<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>BlogSecurity</title>
	
	<link>http://blogsecurity.net</link>
	<description>Always something worth reading...</description>
	<lastBuildDate>Mon, 22 Feb 2010 21:41:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/BlogSecurity" /><feedburner:info uri="blogsecurity" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><image><link>http://blogsecurity.net</link><url>http://blogsecurity.net/wp-content/themes/div_caton2/images/bs-logo.png</url></image><feedburner:emailServiceId>BlogSecurity</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/BlogSecurity" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FBlogSecurity" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:browserFriendly>Always something worth reading...</feedburner:browserFriendly><item>
		<title>WordPress Thrashing Authorisation Bypass</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/G45bqg90l8g/wordpress-thrashing-authorisation-bypass</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-thrashing-authorisation-bypass#comments</comments>
		<pubDate>Mon, 22 Feb 2010 21:41:28 +0000</pubDate>
		<dc:creator>Philipp</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=607</guid>
		<description>Thomas Mackenzie has reported a vulnerability affecting Wordpress &amp;#62;= 2.9. Versions before 2.9 are not vulnerable.
tmacuk quote:
Since version 2.9 a new feature was implemented so that users were able to retrieve posts that they may have deleted by accident. This new feature was labelled ‘trash’. Any posts that are placed within the trash are only viewable [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=G45bqg90l8g:LrCRPGjlkTo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=G45bqg90l8g:LrCRPGjlkTo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=G45bqg90l8g:LrCRPGjlkTo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=G45bqg90l8g:LrCRPGjlkTo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=G45bqg90l8g:LrCRPGjlkTo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=G45bqg90l8g:LrCRPGjlkTo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=G45bqg90l8g:LrCRPGjlkTo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=G45bqg90l8g:LrCRPGjlkTo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=G45bqg90l8g:LrCRPGjlkTo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/G45bqg90l8g" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-thrashing-authorisation-bypass/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-thrashing-authorisation-bypass</feedburner:origLink></item>
		<item>
		<title>WordPress Trackback &lt; 2.8.5 Denial of Service</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/b0nMEPl4ikw/wordpress-trackback-2-8-5-denial-of-service</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-trackback-2-8-5-denial-of-service#comments</comments>
		<pubDate>Tue, 12 Jan 2010 22:00:03 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=603</guid>
		<description>If you are running WordPress &amp;#60; 2.8.5 and finding your blog inaccessible at times this post may be for you.
A denial of vulnerability was released back in Oct 2009 that affects &amp;#60; WordPress 2.8.5. 
The exploit sends a continuous stream of POST requests with overly large blog titles to wp-trackback.php. This could result in the [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=b0nMEPl4ikw:gxAB0_fddPc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=b0nMEPl4ikw:gxAB0_fddPc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=b0nMEPl4ikw:gxAB0_fddPc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=b0nMEPl4ikw:gxAB0_fddPc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=b0nMEPl4ikw:gxAB0_fddPc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=b0nMEPl4ikw:gxAB0_fddPc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=b0nMEPl4ikw:gxAB0_fddPc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=b0nMEPl4ikw:gxAB0_fddPc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=b0nMEPl4ikw:gxAB0_fddPc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/b0nMEPl4ikw" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-trackback-2-8-5-denial-of-service/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-trackback-2-8-5-denial-of-service</feedburner:origLink></item>
		<item>
		<title>Distributed WordPress Password Guessing</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/fS4Tds3ATV4/distributed-wordpress-password-guessing</link>
		<comments>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing#comments</comments>
		<pubDate>Tue, 08 Dec 2009 23:00:22 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Articles]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=589</guid>
		<description>One of The Internet Storm Center readers recently discovered a malicious WordPress hacking script.
The script is nothing more then a password guessing tool. However, what makes it unique &amp;#8212; as pointed out by ISC, is the fact that it uses a MySQL database backend to store password attempts. This means the script could be executed [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=fS4Tds3ATV4:kCl2tcduENk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=fS4Tds3ATV4:kCl2tcduENk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=fS4Tds3ATV4:kCl2tcduENk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=fS4Tds3ATV4:kCl2tcduENk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=fS4Tds3ATV4:kCl2tcduENk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=fS4Tds3ATV4:kCl2tcduENk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=fS4Tds3ATV4:kCl2tcduENk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=fS4Tds3ATV4:kCl2tcduENk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=fS4Tds3ATV4:kCl2tcduENk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/fS4Tds3ATV4" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing/feed</wfw:commentRss>
		<slash:comments>14</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/wordpress/distributed-wordpress-password-guessing</feedburner:origLink></item>
		<item>
		<title>BlogSecurity Upgrade and Move</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/u35iW8dkq2o/blogsecurity-upgrade-and-move</link>
		<comments>http://blogsecurity.net/news/blogsecurity-upgrade-and-move#comments</comments>
		<pubDate>Tue, 08 Dec 2009 22:32:29 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=587</guid>
		<description>Hey guys, we had loads of emails recently regarding wp-scanner just not working. Unfortunately, our old hosting company performed an upgrade which broke our DNS and configurations. To add insult to injury we were also in the process of moving to a new server at a new provider so things have been an utter a [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=u35iW8dkq2o:mmG_jtIdeGU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=u35iW8dkq2o:mmG_jtIdeGU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=u35iW8dkq2o:mmG_jtIdeGU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=u35iW8dkq2o:mmG_jtIdeGU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=u35iW8dkq2o:mmG_jtIdeGU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=u35iW8dkq2o:mmG_jtIdeGU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=u35iW8dkq2o:mmG_jtIdeGU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=u35iW8dkq2o:mmG_jtIdeGU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=u35iW8dkq2o:mmG_jtIdeGU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/u35iW8dkq2o" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/news/blogsecurity-upgrade-and-move/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/news/blogsecurity-upgrade-and-move</feedburner:origLink></item>
		<item>
		<title>WordPress </title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/wEe8UNvOzc0/wordpress-2-8-3-reset-admin-password-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-2-8-3-reset-admin-password-vulnerability#comments</comments>
		<pubDate>Tue, 11 Aug 2009 15:02:50 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=578</guid>
		<description>An exploit has been released for all current versions of WordPress including WordPress&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=wEe8UNvOzc0:9iWuI0Wk_CM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=wEe8UNvOzc0:9iWuI0Wk_CM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=wEe8UNvOzc0:9iWuI0Wk_CM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=wEe8UNvOzc0:9iWuI0Wk_CM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=wEe8UNvOzc0:9iWuI0Wk_CM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=wEe8UNvOzc0:9iWuI0Wk_CM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=wEe8UNvOzc0:9iWuI0Wk_CM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=wEe8UNvOzc0:9iWuI0Wk_CM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=wEe8UNvOzc0:9iWuI0Wk_CM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/wEe8UNvOzc0" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-2-8-3-reset-admin-password-vulnerability/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-2-8-3-reset-admin-password-vulnerability</feedburner:origLink></item>
		<item>
		<title>Critical IPhone SMS Vulnerability</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/7ylBvAlRD60/critical-iphone-sms-vulnerability</link>
		<comments>http://blogsecurity.net/alerts/critical-iphone-sms-vulnerability#comments</comments>
		<pubDate>Tue, 11 Aug 2009 14:48:05 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=576</guid>
		<description>Apple is releasing a critical patch on Saturday to address a recent vulnerability that was demonstrated at the infamous Blackhat hacking conference.

Charlie Miller, a consultant with Independent Security Evaluators, and Collin Mulliner, a PhD student at the Technical University of Berlin, presented the details of the vulnerability at the Black Hat Security Conference in Las [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=7ylBvAlRD60:_C292aAQ48c:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=7ylBvAlRD60:_C292aAQ48c:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=7ylBvAlRD60:_C292aAQ48c:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=7ylBvAlRD60:_C292aAQ48c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=7ylBvAlRD60:_C292aAQ48c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=7ylBvAlRD60:_C292aAQ48c:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=7ylBvAlRD60:_C292aAQ48c:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=7ylBvAlRD60:_C292aAQ48c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=7ylBvAlRD60:_C292aAQ48c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/7ylBvAlRD60" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/alerts/critical-iphone-sms-vulnerability/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/alerts/critical-iphone-sms-vulnerability</feedburner:origLink></item>
		<item>
		<title>WordPress 2.8.3 Fixes Security Holes</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/CmtFLgc_peg/wordpress-2-8-3-fixes-security-holes</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-2-8-3-fixes-security-holes#comments</comments>
		<pubDate>Tue, 04 Aug 2009 21:43:40 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=571</guid>
		<description>If you haven&amp;#8217;t already done so, we&amp;#8217;d stongly recommend upgrading to WordPress 2.8.3. Also, the WordPress 2.0.x branches are now deprecated (a bit earlier then expected) and will therefore no longer be maintained. [Link]
Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1.  Luckily, the entire WordPress community has our backs. [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=CmtFLgc_peg:FJeaAjNSdrY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=CmtFLgc_peg:FJeaAjNSdrY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=CmtFLgc_peg:FJeaAjNSdrY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=CmtFLgc_peg:FJeaAjNSdrY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=CmtFLgc_peg:FJeaAjNSdrY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=CmtFLgc_peg:FJeaAjNSdrY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=CmtFLgc_peg:FJeaAjNSdrY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=CmtFLgc_peg:FJeaAjNSdrY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=CmtFLgc_peg:FJeaAjNSdrY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/CmtFLgc_peg" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-2-8-3-fixes-security-holes/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-2-8-3-fixes-security-holes</feedburner:origLink></item>
		<item>
		<title>WordPress Plugin DM Albums 1.9.2 vulnerabilities</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/247nU9uI-Vw/wordpress-plugin-dm-albums-192-vulnerabilities</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:33:37 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=559</guid>
		<description>DM Albums™ is an inline photo album/gallery plugin that displays high quality images and thumbnails perfectly sized to your blog.
Two vulnerabilities have been made public:
1. Stack released  a &amp;#8220;remote file disclosure vulnerability&amp;#8221; (Low-Medium Risk Level)
2. Septemb0x released a &amp;#8220;remote file include vulnerability&amp;#8221; (Critical Risk Level)
An attacker could use these vulnerabilities to potentially gain full access [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=247nU9uI-Vw:9C_eJwMuBnA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=247nU9uI-Vw:9C_eJwMuBnA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=247nU9uI-Vw:9C_eJwMuBnA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=247nU9uI-Vw:9C_eJwMuBnA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/247nU9uI-Vw" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-plugin-dm-albums-192-vulnerabilities</feedburner:origLink></item>
		<item>
		<title>WordPress Plugin Related Sites 2.1 Blind SQL Injection Vulnerability</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/iBQFl-UNtUM/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability</link>
		<comments>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability#comments</comments>
		<pubDate>Wed, 01 Jul 2009 13:26:07 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=555</guid>
		<description>A critical vulnerability has been discovered in the WordPress Plugin Related Sites plugin. An exploit is available in the wild and available on Milw0rm, making this attack easier to exploit.
Although, the vulnerability says that version 2.1 is vulnerable. You should assume previous versions are vulnerable as well.
BlogSec have confirmed that the current version (at the [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=iBQFl-UNtUM:hYR61CngZ2g:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=iBQFl-UNtUM:hYR61CngZ2g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=iBQFl-UNtUM:hYR61CngZ2g:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=iBQFl-UNtUM:hYR61CngZ2g:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/iBQFl-UNtUM" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/wordpress/wordpress-plugin-related-sites-21-blind-sql-injection-vulnerability</feedburner:origLink></item>
		<item>
		<title>Critical phpMyAdmin Vulnerabilities Discovered</title>
		<link>http://feedproxy.google.com/~r/BlogSecurity/~3/kdAeYGwBzxc/critical-phpmyadmin-vulnerabilities-discovered</link>
		<comments>http://blogsecurity.net/news/critical-phpmyadmin-vulnerabilities-discovered#comments</comments>
		<pubDate>Wed, 10 Jun 2009 20:49:48 +0000</pubDate>
		<dc:creator>DK</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Tips]]></category>
		<category><![CDATA[phpmyadmin]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blogsecurity.net/?p=547</guid>
		<description>A number of bloggers and web site owners use phpMyAdmin for easy database administration. Two critical vulnerabilities have been discovered that could be used to gain full access to the affected server.
Exploits have already been made publicly available, see GNUCITIZEN for an example:

http://172.16.211.10/phpMyAdmin-3.0.1.1//config/
config.inc.php?p=phpinfo();


Description
Setup script used to generate configuration can be fooled using a crafted POST [...]&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=kdAeYGwBzxc:kCvGMEC-SSs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=kdAeYGwBzxc:kCvGMEC-SSs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?i=kdAeYGwBzxc:kCvGMEC-SSs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/BlogSecurity?a=kdAeYGwBzxc:kCvGMEC-SSs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/BlogSecurity?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/BlogSecurity/~4/kdAeYGwBzxc" height="1" width="1"/&gt;</description>
		<wfw:commentRss>http://blogsecurity.net/news/critical-phpmyadmin-vulnerabilities-discovered/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://blogsecurity.net/news/critical-phpmyadmin-vulnerabilities-discovered</feedburner:origLink></item>
	</channel>
</rss>

