<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Powered By &#187; risk</title>
	<atom:link href="http://www.powered-by.org/tag/risk/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.powered-by.org</link>
	<description>Content Management System News and Updates</description>
	<lastBuildDate>Wed, 22 Dec 2010 03:49:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Simple Machines Forum</title>
		<link>http://www.powered-by.org/simple-machines-forum/</link>
		<comments>http://www.powered-by.org/simple-machines-forum/#comments</comments>
		<pubDate>Sun, 19 Apr 2009 08:38:02 +0000</pubDate>
		<dc:creator>powered-by.org</dc:creator>
				<category><![CDATA[CMS Index]]></category>
		<category><![CDATA[Forum]]></category>
		<category><![CDATA[Open Source Web CMS]]></category>
		<category><![CDATA[SMF]]></category>
		<category><![CDATA[beta]]></category>
		<category><![CDATA[Free]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[mysql database]]></category>
		<category><![CDATA[opera]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Simple Machines Forum]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/cms/forum/simple-machines-forum/</guid>
		<description><![CDATA[Simple Machines Forum (abbreviated as SMF) is a freeware Internet forum application. The software is written in PHP and uses a MySQL database backend, although multi-database support is being developed for version 2.0. SMF is developed by the Simple Machines development team. SMF was created to replace the forum software YaBB SE, which at the [...]]]></description>
			<content:encoded><![CDATA[<p><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; margin-left: 0px; border-left-width: 0px; margin-right: 0px" title="smf" border="0" alt="smf" align="right" src="http://www.powered-by.org/wp-content/uploads/2009/04/smf.jpg" width="150" height="150" /> Simple Machines Forum (abbreviated as SMF) is a freeware Internet forum application. The software is written in PHP and uses a MySQL database backend, although multi-database support is being developed for version 2.0. SMF is developed by the Simple Machines development team.</p>
<p>SMF was created to replace the forum software YaBB SE, which at the time was gaining a bad reputation because of problems with its Perl-based ancestor software YaBB[citation needed]. At the time, YaBB was attributed to causing resource allocation problems on many systems. YaBB SE was written as a rough PHP port of YaBB, and had many of the same resource and security problems of the older YaBB versions. Joseph Fung and Jeff Lewis of Lewis Media Inc., the owners of YaBB SE and the original owners of SMF, made the decision to convert to a new brand and name.</p>
<p> <span id="more-500"></span><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; margin-left: 0px; border-left-width: 0px; margin-right: 0px" title="smf_web" border="0" alt="smf_web" align="right" src="http://www.powered-by.org/wp-content/uploads/2009/04/smf-web.jpg" width="300" height="401" /> SMF started as a small project by username &quot;[Unknown]&quot; (one of the YaBB SE developers) and its main intent was to add more advanced templating to YaBB SE. The project then slowly grew to address common feature requests, efficiency problems, and security concerns. A rehaul of YaBB SE had been in development for several years, but was superseded by this then competing project. Popular interest in the new YaBB SE fork sparked a complete rewrite of the code, with security and performance in mind. This eventually became today&#8217;s Simple Machines Forum.. The first SMF release was SMF 1.0 Beta 1a, released on 30 September 2003 to Charter Members only.
</p>
<p>On the 23rd of October 2006, Simple Machines LLC was registered in the state of Arizona, and the transfer of copyrights from Lewis Media to Simple Machines LLC was completed on the 24th of November 2006 during a three-day retreat in Tucson, AZ. This was done for the &quot;[solidification of] the team’s commitment to continuously providing free software, without the perceived risks of corporate influence&quot;</p>
<h3>Future</h3>
<p>On 8 April 2007, Simple Machines announced the introduction of their next version, SMF 2.0 [8]. SMF 2.0 has been in development alongside SMF 1.1 since December 2005. This version will have many new features, including:</p>
<ul>
<li>Database abstraction &#8211; with support for PostgreSQL and SQLite planned alongside that of MySQL. </li>
<li>Automatic installation of packages into themes other than just the default. </li>
<li>Email templates to simplify customization of forum emails. </li>
<li>Moderation center including post, topic and attachment moderation &#8211; to allow approving of user content before it is made public. </li>
<li>User warning system. </li>
<li>Additional group functionally including group moderators and requestable/free assignable groups. </li>
<li>WYSIWYG editor to provide an intuitive user interface to those users not familiar with BBCode. </li>
<li>Permission improvements such as group inheritance and permission profiles to further reduce the complexity of the permissions system. </li>
<li>File based caching for a performance increase on all forums regardless of whether an accelerator is installed. </li>
<li>Mail queuing system to stagger the sending of emails to improve performance on large forums. </li>
<li>Advanced signature settings to allow the administrator of a forum to more tightly control the contents of users signatures. </li>
<li>Personal messaging improvements including ability to automatically sort incoming messages and a variety of display options. </li>
<li>Improved upgrade script with better timeout protection and simpler user interface. </li>
<li>Custom profile fields to enable administrators to add additional member fields from the administration center. </li>
<li>Use of OpenID. </li>
</ul>
<p>The first public beta of SMF 2.0 was released on Monday, March 17 2008.</p>
<h3>Localization</h3>
<p>SMF is available in over 38 languages[9], including Albanian, Arabic, Bulgarian, Catalan, Chinese, Czech, Danish, Dutch, English, Finnish, French, German, Greek, Hebrew, Hungarian, Italian, Japanese, Norwegian, Persian, Polish, Portuguese, Romanian, Russian, Spanish, Swedish, Thai, Turkish and Ukrainian. It can be translated to other languages by volunteers. UTF-8 and non-UTF-8 encodings are available for all.</p>
<h3>Modifications</h3>
<p>SMF has a modification base repository for free modification hosting and tracking via the Simple Machines main site. Many modifications, or &quot;mods&quot; as they are usually called, have been created and distributed free of charge, including an arcade, profile additions, gallery, RPG system, spam filter, various SEO features, and many more. Before being listed on the SMF Mods site, the mod is validated by the SMF Team, to ensure that it complies with the SMF Coding Guidelines.</p>
<p>The Package Manager included in SMF is one of the flagship features. It allows an administrator to install modifications and updates to SMF without having to modify the code of the script, usually with only a few mouse clicks.</p>
<h3>The SMF team</h3>
<p>The Simple Machines team includes graphics, documentation, customization, localization, marketing, and management divisions. The SMF support staff and users also provide free support on the official community forums. Their duties include helping forum owners with troubleshooting and optimization.</p>
<h3>Charter Members</h3>
<p>People who wish to support Simple Machines with a donation of 50 USD yearly are rewarded with a Charter Membership. This grants access to a hidden section on the forum and advanced beta versions to test before they go public. Advanced support for SMF including installation and upgrades by the staff are also provided. Charter Members also get access to a private Helpdesk staffed by the Simple Machines Support Team where Charter Members can receive one-on-one support outside of the public forum.</p>
<h3>SMF and free software</h3>
<p>SMF is occasionally criticized for not being available under a free software license; the developers acknowledge this. Redistribution of the software, even unmodified, is not allowed without written permission. The source code is not redistributable either, although it is allowed to distribute instructions on how to modify it.</p>
<h3>Minimum System Requirement</h3>
<p>To run SMF, the webserver you&#8217;re hosted on must meet a few simple requirements. These are not terribly high, and as such most hosts meet them.</p>
<ul>
<li>Any webserver that properly supports PHP, such as Apache or Internet Information Services (IIS). </li>
<li>PHP 4.1.0 or higher. The following directives are required to be set correctly in php.ini:
<ul>
<li>the engine directive must be On. </li>
<li>the magic_quotes_sybase directive must be set to Off. </li>
<li>the session.save_path directive must be set to a valid directory. </li>
<li>the file_uploads directive must be On. </li>
<li>the upload_tmp_dir must be set to a valid directory. </li>
</ul>
</li>
<li>MySQL 3.23.4 or higher. </li>
<li>at least 512 kilobytes of storage space in the database, although more is highly recommended. </li>
<li>about two and a half megabytes of storage space on the web server, although more is recommended. </li>
</ul>
<h3>Recommended System Requirements</h3>
<p>However, for best performance and use, a bit more is suggested. This includes the following:</p>
<ul>
<li>Linux or another Unix based operating system. </li>
<li>The GNU Aspell and its dictionaries for spell checking support. </li>
<li>Apache with AcceptPathInfo set to On (Apache 2 and later only) for queryless URL support. </li>
<li>PHP 4.3.0 or higher, with the following set in php.ini:
<ul>
<li>the max_input_time directive is set to a value of at least 30. </li>
<li>the post_max_size and upload_max_filesize directives are set to the size of the largest attachments you wish to be able to upload. </li>
<li>the session.use_trans_sid directive set to Off. </li>
<li>the memory_limit directive is set to at least 8M. </li>
<li>the max_execution_time directive is set to at least 15. </li>
<li>the register_globals directive is set to Off. </li>
</ul>
</li>
<li>MySQL 4.0.15 or higher with query caching enabled. </li>
<li>GD Graphics Library 2.0 or higher. </li>
</ul>
<h3>Links</h3>
<ul>
<li><a target="_blank" href="http://www.simplemachines.org/" target="_blank">Official Website</a> </li>
<li><a target="_blank" href="http://download.simplemachines.org/index.php" target="_blank">Download SMF</a> </li>
<li><a target="_blank" href="http://custom.simplemachines.org/mods/" target="_blank">SMF Mods</a> </li>
<li><a target="_blank" href="http://custom.simplemachines.org/themes/" target="_blank">SMf Themes</a> </li>
<li><a href="http://www.powered-by.org/references/cms-index/simple-machines-forum/" target="_blank">SMf – Powered-by</a></li>
</ul>
<p><a href="http://www.powered-by.org/cms/forum/simple-machines-forum/" target="_blank"></a></p>
<h4>Incoming search terms:</h4><ul><li>powered by smf</li><li>bowser simple machine forum</li><li>grenade powered by smf</li><li>ones smf</li><li>Simple Machines Forum</li><li>tube inurl:/forums/</li><li>change use simple machines llc</li><li>simple machines required information applicants</li><li>duties yabb</li><li>daffodils simple machine forum</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/simple-machines-forum/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>WordPress 2.6.3 released after vulnerability in the Snoopy library was discovered</title>
		<link>http://www.powered-by.org/wordpress-263-released-after-vulnerability-in-the-snoopy-library-was-discovered/</link>
		<comments>http://www.powered-by.org/wordpress-263-released-after-vulnerability-in-the-snoopy-library-was-discovered/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 03:31:37 +0000</pubDate>
		<dc:creator>CMS News</dc:creator>
				<category><![CDATA[New Release]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[snoopy]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/?p=68</guid>
		<description><![CDATA[Snoopy is a PHP class that simulates a web browser. It automates the task of retrieving web page content and posting forms. A vulnerability in the Snoopy library was announced today. WordPress uses Snoopy to fetch the feeds shown in the Dashboard. Although this seems to be a low risk vulnerability for WordPress users, we [...]]]></description>
			<content:encoded><![CDATA[<p>Snoopy is a PHP class that simulates a web browser. It automates the task of retrieving web page content and posting forms.<span id="more-70"></span></p>
<blockquote><p>A vulnerability in the Snoopy library was announced today.  WordPress uses Snoopy to fetch the feeds shown in the Dashboard.   Although this seems to be a low risk vulnerability for WordPress users, we wanted to get an update out immediately.  2.6.3 is available for download right now.  If you don’t want to download the whole release to get the security fix, you can download the following two files and copy them over your 2.6.2 installation.</p></blockquote>
<p>File affetec:ted</p>
<ol>
<li><a target="_blank" href="http://trac.wordpress.org/export/9310/tags/2.6.3/wp-includes/class-snoopy.php">wp-includes/class-snoopy.php</a></li>
<li><a target="_blank" href="http://trac.wordpress.org/export/9310/tags/2.6.3/wp-includes/version.php">wp-includes/version.php</a></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/wordpress-263-released-after-vulnerability-in-the-snoopy-library-was-discovered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress shuts door on new PHP attack vector</title>
		<link>http://www.powered-by.org/wordpress-shuts-door-on-new-php-attack-vector/</link>
		<comments>http://www.powered-by.org/wordpress-shuts-door-on-new-php-attack-vector/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 17:53:25 +0000</pubDate>
		<dc:creator>powered-by.org</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[Blogs]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Patch]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.powered-by.org/news/security/wordpress-shuts-door-on-new-php-attack-vector/</guid>
		<description><![CDATA[According to an advisory from maintainers of the open-source blog software, WordPress 2.6.2 was released on September 8 to mitigate a new attack vector discovered by PHP security guru Stefan Esser. From the announcement: Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand(). With his help we [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_6" class="wp-caption alignright" style="width: 288px"><a href="http://www.powered-by.org/wp-content/uploads/2008/09/wordpress-logo.png"><img class="size-medium wp-image-6" title="wordpress-logo" src="http://www.powered-by.org/wp-content/uploads/2008/09/wordpress-logo.png" alt="Wordpress" width="278" height="117" /></a><p class="wp-caption-text">Wordpress</p></div>
<p>According to an advisory from maintainers of the open-source blog software, WordPress 2.6.2 was released on September 8 to mitigate a new attack vector discovered by PHP security guru Stefan Esser.</p>
<p><span id="more-32"></span></p>
<p>From the announcement:</p>
<blockquote><p>Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.</p></blockquote>
<p>WordPress developers said the attack is difficult to accomplish but, because of the associated risk, the patch is being released.</p>
<p>It’s important to note that other PHP applications are vulnerable to this class of attack.</p>
<p><a target="_blank" href="http://blogs.zdnet.com/security/?p=1868">WordPress shuts door on new PHP attack vector | Zero Day | ZDNet.com</a></p>
<h4>Incoming search terms:</h4><ul><li>inurl:Powered by WordPress 2 6 1</li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.powered-by.org/wordpress-shuts-door-on-new-php-attack-vector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

