<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: XML-RPC Vulnerability</title>
	<atom:link href="http://ma.tt/2005/07/xml-rpc-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://ma.tt/2005/07/xml-rpc-vulnerability/</link>
	<description>Unlucky in Cards</description>
	<lastBuildDate>Sat, 26 May 2012 13:00:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-beta4-20941</generator>
	<item>
		<title>By: StreetComputing &#187; WordPress comments and numeric entity codes</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-25677</link>
		<dc:creator>StreetComputing &#187; WordPress comments and numeric entity codes</dc:creator>
		<pubDate>Thu, 15 Sep 2005 08:42:13 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-25677</guid>
		<description>[...] In fact, the only near-official word I could find on the matter was this comment on Matt Mullenweg&#8217;s (WP lead developer) weblog, in which he states: I do block comments with numeric entities lower than a certain number. [...]</description>
		<content:encoded><![CDATA[<p>[...] In fact, the only near-official word I could find on the matter was this comment on Matt Mullenweg&#8217;s (WP lead developer) weblog, in which he states: I do block comments with numeric entities lower than a certain number. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Verpoorten</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22172</link>
		<dc:creator>Tim Verpoorten</dc:creator>
		<pubDate>Thu, 07 Jul 2005 04:22:29 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22172</guid>
		<description>Matt.
I believe you, now can you please talk to the folks over at blogsome.com that are running your Wordpress groupware and let them know it&#039;s safe? They just stopped all access to xlmrpc.php by third party apps like jetblog, and marsedit, etc... just manual blog entries. Maybe you can set them straight over there?
Thanks
Tim</description>
		<content:encoded><![CDATA[<p>Matt.<br />
I believe you, now can you please talk to the folks over at blogsome.com that are running your WordPress groupware and let them know it&#8217;s safe? They just stopped all access to xlmrpc.php by third party apps like jetblog, and marsedit, etc&#8230; just manual blog entries. Maybe you can set them straight over there?<br />
Thanks<br />
Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ionic</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22167</link>
		<dc:creator>ionic</dc:creator>
		<pubDate>Wed, 06 Jul 2005 20:09:49 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22167</guid>
		<description>Nahh forget it... it seems that you do something like striptags and when I wrote Wordpress &lt; with a real &lt; char the rest was truncated. (strip_tags)

When I write &amp;ampl;lt; i get a nice &lt; instead....

So you need to write htmlentities ;)</description>
		<content:encoded><![CDATA[<p>Nahh forget it&#8230; it seems that you do something like striptags and when I wrote WordPress &lt; with a real &lt; char the rest was truncated. (strip_tags)</p>
<p>When I write &ampl;lt; i get a nice &lt; instead&#8230;.</p>
<p>So you need to write htmlentities <img src='http://s.ma.tt/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22166</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 06 Jul 2005 20:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22166</guid>
		<description>I bet the HTML cleaner (KSES) thought your comment after &quot;WordPress&quot; was one giant invalid HTML tag and stripped it.</description>
		<content:encoded><![CDATA[<p>I bet the HTML cleaner (KSES) thought your comment after &#8220;WordPress&#8221; was one giant invalid HTML tag and stripped it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22165</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 06 Jul 2005 20:07:23 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22165</guid>
		<description>Ionic, for some reason the comment came through as just &quot;Wordpress&quot; with no other text, I assumed it was a mistake and deleted it. I do block comments with numeric entities lower than a certain number. If you want to email me your original comment I&#039;ll be happy to make sure it gets posted.</description>
		<content:encoded><![CDATA[<p>Ionic, for some reason the comment came through as just &#8220;WordPress&#8221; with no other text, I assumed it was a mistake and deleted it. I do block comments with numeric entities lower than a certain number. If you want to email me your original comment I&#8217;ll be happy to make sure it gets posted.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ionic</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22164</link>
		<dc:creator>ionic</dc:creator>
		<pubDate>Wed, 06 Jul 2005 20:02:56 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22164</guid>
		<description>Ohh I just see... When you write comments here you must fluently speak htmlentities...</description>
		<content:encoded><![CDATA[<p>Ohh I just see&#8230; When you write comments here you must fluently speak htmlentities&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ionic</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22162</link>
		<dc:creator>ionic</dc:creator>
		<pubDate>Wed, 06 Jul 2005 20:01:03 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22162</guid>
		<description>It is not a nice act to remove my comment and replace it with a GulfTech one. I commented on this issue first.

Unfortunately this crappy blog, does strange things if you write somethint like

Wordpress &lt; 1.5  - if you replace &lt; with the lower than character...</description>
		<content:encoded><![CDATA[<p>It is not a nice act to remove my comment and replace it with a GulfTech one. I commented on this issue first.</p>
<p>Unfortunately this crappy blog, does strange things if you write somethint like</p>
<p>WordPress &lt; 1.5  &#8211; if you replace &lt; with the lower than character&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22160</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 06 Jul 2005 17:17:36 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22160</guid>
		<description>I think we switched when 1.5 was released.</description>
		<content:encoded><![CDATA[<p>I think we switched when 1.5 was released.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GulfTech</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22159</link>
		<dc:creator>GulfTech</dc:creator>
		<pubDate>Wed, 06 Jul 2005 17:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22159</guid>
		<description>The recently published XML-RPC vulns will not work on current versions of WordPress, but it seems that WordPress did use PHPXMLRPC at one time, and I think that is where the confusion comes in to play. Maybe the developers could tell us when they quit using PHPXMLRPC in favor of their own XML-RPC?</description>
		<content:encoded><![CDATA[<p>The recently published XML-RPC vulns will not work on current versions of WordPress, but it seems that WordPress did use PHPXMLRPC at one time, and I think that is where the confusion comes in to play. Maybe the developers could tell us when they quit using PHPXMLRPC in favor of their own XML-RPC?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Xavier</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22153</link>
		<dc:creator>Xavier</dc:creator>
		<pubDate>Wed, 06 Jul 2005 08:42:11 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22153</guid>
		<description>Does it really fix everything XML-RPC ? I read some files where released afterwards. Or were there added in 1.5.1.3 during an update of the archive (should we then re-install 1.5.1.3) ?</description>
		<content:encoded><![CDATA[<p>Does it really fix everything XML-RPC ? I read some files where released afterwards. Or were there added in 1.5.1.3 during an update of the archive (should we then re-install 1.5.1.3) ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tyler</title>
		<link>http://ma.tt/2005/07/xml-rpc-vulnerability/#comment-22142</link>
		<dc:creator>tyler</dc:creator>
		<pubDate>Tue, 05 Jul 2005 20:58:23 +0000</pubDate>
		<guid isPermaLink="false">http://photomatt.net/2005/07/05/xml-rpc-vulnerability/#comment-22142</guid>
		<description>Thanks for the confirmation Matt.  I was pretty sure 1.5.1.3 addressed that.  The Hardened-PHP patch keeps all my apps safe from that bug though.</description>
		<content:encoded><![CDATA[<p>Thanks for the confirmation Matt.  I was pretty sure 1.5.1.3 addressed that.  The Hardened-PHP patch keeps all my apps safe from that bug though.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

