<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>BlogSecurity</title>
	
	<link>http://blogsecurity.net</link>
	<description>Always something worth reading...</description>
	<pubDate>Wed, 01 Jul 2009 13:33:37 +0000</pubDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<image><link>http://blogsecurity.net</link><url>http://blogsecurity.net/wp-content/themes/div_caton2/images/bs-logo.png</url></image><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/BlogSecurity" type="application/rss+xml" /><feedburner:emailServiceId>BlogSecurity</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/BlogSecurity" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:browserFriendly>Always something worth reading...</feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>WordPress Plugin DM Albums 1.9.2 vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/247nU9uI-Vw/wordpress-plugin-dm-albums-192-vulnerabilities</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:33:37 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Advisories]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=559</guid>
		<description>DM Albums™ is an inline photo album/gallery plugin that displays high quality images and thumbnails perfectly sized to your blog.
Two vulnerabilities have been made public:
1. Stack released  a &amp;#8220;remote file disclosure vulnerability&amp;#8221; (Low-Medium Risk Level)
2. Septemb0x released a &amp;#8220;remote file include vulnerability&amp;#8221; (Critical Risk Level)
An attacker could use these vulnerabilities to potentially gain full access [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=247nU9uI-Vw:9C_eJwMuBnA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=247nU9uI-Vw:9C_eJwMuBnA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=247nU9uI-Vw:9C_eJwMuBnA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/247nU9uI-Vw" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities</feedburner:origLink></item>
		<item>
		<title>WordPress Plugin Related Sites 2.1 Blind SQL Injection Vulnerability</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/iBQFl-UNtUM/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:26:07 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Advisories]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=555</guid>
		<description>A critical vulnerability has been discovered in the WordPress Plugin Related Sites plugin. An exploit is available in the wild and available on Milw0rm, making this attack easier to exploit.
Although, the vulnerability says that version 2.1 is vulnerable. You should assume previous versions are vulnerable as well.
BlogSec have confirmed that the current version (at the [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=iBQFl-UNtUM:hYR61CngZ2g:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=iBQFl-UNtUM:hYR61CngZ2g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=iBQFl-UNtUM:hYR61CngZ2g:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/iBQFl-UNtUM" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability</feedburner:origLink></item>
		<item>
		<title>Critical phpMyAdmin Vulnerabilities Discovered</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/kdAeYGwBzxc/critical-phpmyadmin-vulnerabilities-discovered</link>
		<comments>http://blogsecurity.net/news/critical-phpmyadmin-vulnerabilities-discovered#comments</comments>
		<pubDate>Wed, 10 Jun 2009 20:49:48 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Security Tips]]></category>

		<category><![CDATA[phpmyadmin]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=547</guid>
		<description>A number of bloggers and web site owners use phpMyAdmin for easy database administration. Two critical vulnerabilities have been discovered that could be used to gain full access to the affected server.
Exploits have already been made publicly available, see GNUCITIZEN for an example:

http://172.16.211.10/phpMyAdmin-3.0.1.1//config/
config.inc.php?p=phpinfo();


Description
Setup script used to generate configuration can be fooled using a crafted POST [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=kdAeYGwBzxc:kCvGMEC-SSs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=kdAeYGwBzxc:kCvGMEC-SSs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=kdAeYGwBzxc:kCvGMEC-SSs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/kdAeYGwBzxc" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/news/critical-phpmyadmin-vulnerabilities-discovered/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/news/critical-phpmyadmin-vulnerabilities-discovered</feedburner:origLink></item>
		<item>
		<title>Blogs and tweets in a moving business trend part1</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/E4_-2pN_Vn8/blogs-and-tweets-in-a-moving-business-trend-part1</link>
		<comments>http://blogsecurity.net/news/blogs-and-tweets-in-a-moving-business-trend-part1#comments</comments>
		<pubDate>Wed, 10 Jun 2009 13:13:39 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[blog]]></category>

		<category><![CDATA[social networks]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=536</guid>
		<description>Avoid popularity if you would have peace &amp;#8211; Abraham Lincoln
Mozilla started a blog back in 2008, after breaking the  guiness world records for the most downloads in 24 hours.
Can anyone guess what blogging platform they are using? Yes you probably guessed it if you read the title of this post.
Mozilla stands out with a few [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=E4_-2pN_Vn8:68qicc9j4bo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=E4_-2pN_Vn8:68qicc9j4bo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=E4_-2pN_Vn8:68qicc9j4bo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=E4_-2pN_Vn8:68qicc9j4bo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=E4_-2pN_Vn8:68qicc9j4bo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=E4_-2pN_Vn8:68qicc9j4bo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=E4_-2pN_Vn8:68qicc9j4bo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=E4_-2pN_Vn8:68qicc9j4bo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=E4_-2pN_Vn8:68qicc9j4bo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/E4_-2pN_Vn8" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/news/blogs-and-tweets-in-a-moving-business-trend-part1/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/news/blogs-and-tweets-in-a-moving-business-trend-part1</feedburner:origLink></item>
		<item>
		<title>Tiananmen Square continues to bleed hope for freedom of speech</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/04vAL7GE8ak/tiananmen-square-continues-to-bleed-hope-for-freedom-of-speech</link>
		<comments>http://blogsecurity.net/news/tiananmen-square-continues-to-bleed-hope-for-freedom-of-speech#comments</comments>
		<pubDate>Fri, 05 Jun 2009 20:13:12 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[News]]></category>

		<category><![CDATA[Social-Networking]]></category>

		<category><![CDATA[blogs]]></category>

		<category><![CDATA[Freedom of Speech]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=518</guid>
		<description>“internet interprets censorship as damage and routes around it.” - EFF co-founder John Gilmore
2005, Yahoo provides information that helped Chinese officials convict a journalist accused of leaking state secrets. Apparently, Shi Tao, a 37-year-old writer for the Dangdai Shang Bao, released a &amp;#8220;state secret&amp;#8221; which contained a message to Shi&amp;#8217;s newspaper warning journalists of the [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=04vAL7GE8ak:3-afxHOR9gQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=04vAL7GE8ak:3-afxHOR9gQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=04vAL7GE8ak:3-afxHOR9gQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=04vAL7GE8ak:3-afxHOR9gQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=04vAL7GE8ak:3-afxHOR9gQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=04vAL7GE8ak:3-afxHOR9gQ:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=04vAL7GE8ak:3-afxHOR9gQ:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=04vAL7GE8ak:3-afxHOR9gQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=04vAL7GE8ak:3-afxHOR9gQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/04vAL7GE8ak" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/news/tiananmen-square-continues-to-bleed-hope-for-freedom-of-speech/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/news/tiananmen-square-continues-to-bleed-hope-for-freedom-of-speech</feedburner:origLink></item>
		<item>
		<title>WordPress Install Files Security Risk</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/xfEu5MM9CEc/wordpress-install-files-security-risk</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-install-files-security-risk#comments</comments>
		<pubDate>Fri, 08 May 2009 13:35:32 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[blog]]></category>

		<category><![CDATA[blogs]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=512</guid>
		<description>Jeff Starr over at Perishable Press has discovered a way to hack a WordPress blog in rare cases where the installation files have been left behind and the database is in accessible:

The other day, my server crashed and Perishable Press was unable to connect to the MySQL database. Normally, when WordPress encounters a database error&amp;#8230;
The [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=xfEu5MM9CEc:7fWrmYm31UU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=xfEu5MM9CEc:7fWrmYm31UU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=xfEu5MM9CEc:7fWrmYm31UU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=xfEu5MM9CEc:7fWrmYm31UU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=xfEu5MM9CEc:7fWrmYm31UU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=xfEu5MM9CEc:7fWrmYm31UU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=xfEu5MM9CEc:7fWrmYm31UU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=xfEu5MM9CEc:7fWrmYm31UU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=xfEu5MM9CEc:7fWrmYm31UU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/xfEu5MM9CEc" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-install-files-security-risk/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-install-files-security-risk</feedburner:origLink></item>
		<item>
		<title>Twitter Web Worm Causes Havoc</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/OvYVCn0Bg7Q/twitter-web-worm-causes-havoc</link>
		<comments>http://blogsecurity.net/social-networking/twitter-web-worm-causes-havoc#comments</comments>
		<pubDate>Tue, 14 Apr 2009 15:33:20 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Social-Networking]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=504</guid>
		<description>Update: Apparently a bunch of variant worms are doing the rounds that circumvent Twitter&amp;#8217;s recent patch to fix the problem. I&amp;#8217;d be cautious using Twitter over the next couple weeks, see protection guidelines below or at this link.
Teen exploits Twitter
A 17 year-old has claimed credit for releasing a Cross Site Scripting worm that infected hundreds [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=OvYVCn0Bg7Q:ZNSjM61nQ1Q:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=OvYVCn0Bg7Q:ZNSjM61nQ1Q:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=OvYVCn0Bg7Q:ZNSjM61nQ1Q:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=OvYVCn0Bg7Q:ZNSjM61nQ1Q:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=OvYVCn0Bg7Q:ZNSjM61nQ1Q:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=OvYVCn0Bg7Q:ZNSjM61nQ1Q:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=OvYVCn0Bg7Q:ZNSjM61nQ1Q:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=OvYVCn0Bg7Q:ZNSjM61nQ1Q:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=OvYVCn0Bg7Q:ZNSjM61nQ1Q:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/OvYVCn0Bg7Q" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/social-networking/twitter-web-worm-causes-havoc/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/social-networking/twitter-web-worm-causes-havoc</feedburner:origLink></item>
		<item>
		<title>Facebook Faces Big Brother Monitoring</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/w74IsJ7SEWM/facebook-faces-big-brother-monitoring</link>
		<comments>http://blogsecurity.net/social-networking/facebook-faces-big-brother-monitoring#comments</comments>
		<pubDate>Wed, 25 Mar 2009 09:02:04 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[News]]></category>

		<category><![CDATA[Social-Networking]]></category>

		<category><![CDATA[facebook]]></category>

		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=493</guid>
		<description>Millions of Britons who use social networking sites could be  having their accounts &amp;#8220;secretly&amp;#8221; monitored in the near future.

Kelly was responding to a speech made by Home Office security minister Vernon Coaker on 18 March at a meeting of the House of Commons Fourth Delegated Legislation Committee. Coaker said the EU Data Retention Directive, which [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=w74IsJ7SEWM:9DC_f2LfD_I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=w74IsJ7SEWM:9DC_f2LfD_I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=w74IsJ7SEWM:9DC_f2LfD_I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=w74IsJ7SEWM:9DC_f2LfD_I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=w74IsJ7SEWM:9DC_f2LfD_I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=w74IsJ7SEWM:9DC_f2LfD_I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=w74IsJ7SEWM:9DC_f2LfD_I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=w74IsJ7SEWM:9DC_f2LfD_I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=w74IsJ7SEWM:9DC_f2LfD_I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/w74IsJ7SEWM" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/social-networking/facebook-faces-big-brother-monitoring/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/social-networking/facebook-faces-big-brother-monitoring</feedburner:origLink></item>
		<item>
		<title>WordPress MU &lt; 2.7 Cross Site Scripting Vulnerability</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/BdNGY7a_5Po/wordpress-mu-27-cross-site-scripting-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability#comments</comments>
		<pubDate>Thu, 19 Mar 2009 08:32:08 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Advisories]]></category>

		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=488</guid>
		<description>Cross Site Scripting Vulnerability
Juan Galiana Lara has released details regarding a vulnerability that affects WordPress MU versions &amp;#60; 2.7.
Version 2.7 is NOT affected according to the advisory. So if you have upgraded to 2.7 you can ignore this advisory.
Vulnerability Details
WordPress MU prior to version 2.7 fails to sanitize the Host header correctly in choose_primary_blog function [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=BdNGY7a_5Po:YNskVvhYHIc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=BdNGY7a_5Po:YNskVvhYHIc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=BdNGY7a_5Po:YNskVvhYHIc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=BdNGY7a_5Po:YNskVvhYHIc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=BdNGY7a_5Po:YNskVvhYHIc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=BdNGY7a_5Po:YNskVvhYHIc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=BdNGY7a_5Po:YNskVvhYHIc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=BdNGY7a_5Po:YNskVvhYHIc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=BdNGY7a_5Po:YNskVvhYHIc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/BdNGY7a_5Po" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-mu-27-cross-site-scripting-vulnerability</feedburner:origLink></item>
		<item>
		<title>How to Firewall Your WordPress Blog</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/ugfkBOolkzs/how-to-firewall-your-wordpress-blog</link>
		<comments>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog#comments</comments>
		<pubDate>Thu, 05 Mar 2009 10:22:56 +0000</pubDate>
		<dc:creator>DK</dc:creator>
		
		<category><![CDATA[Articles]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[blog security]]></category>

		<category><![CDATA[wordpress security]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=471</guid>
		<description>You already know to use a decent password for your blog, but brute-force or dictionary attacks aren&amp;#8217;t the only attacks used against bloggers.  It&amp;#8217;s much cheaper and faster to exploit software flaws, and that the hackers do.  A programmer&amp;#8217;s oversight may allow a hacker to gain access to your blog to insert spyware, [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=ugfkBOolkzs:8jKVn9KsEt4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=ugfkBOolkzs:8jKVn9KsEt4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=ugfkBOolkzs:8jKVn9KsEt4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=ugfkBOolkzs:8jKVn9KsEt4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=ugfkBOolkzs:8jKVn9KsEt4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=ugfkBOolkzs:8jKVn9KsEt4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=ugfkBOolkzs:8jKVn9KsEt4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=ugfkBOolkzs:8jKVn9KsEt4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=ugfkBOolkzs:8jKVn9KsEt4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/ugfkBOolkzs" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog/feed</wfw:commentRss>
		<feedburner:origLink>http://blogsecurity.net/wordpress/how-to-firewall-your-wordpress-blog</feedburner:origLink></item>
	</channel>
</rss>
