<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SecurityFocus SQL Injection Bogus</title>
	<atom:link href="http://ma.tt/2008/04/securityfocus-sql-injection-bogus/feed/" rel="self" type="application/rss+xml" />
	<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/</link>
	<description>Unlucky in Cards</description>
	<lastBuildDate>Mon, 30 Jan 2012 18:53:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4-alpha-19904</generator>
	<item>
		<title>By: Security and Hacking: The State of WordPress Blogs &#124; The Blog Herald</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-456403</link>
		<dc:creator>Security and Hacking: The State of WordPress Blogs &#124; The Blog Herald</dc:creator>
		<pubDate>Sat, 17 Jan 2009 04:39:59 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-456403</guid>
		<description>[...] &#8220;SecurityFocus SQL Injection Bogus,&#8221; Matt Mullenweg talked about one false report: Online, apparently, it’s fine for someone [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8220;SecurityFocus SQL Injection Bogus,&#8221; Matt Mullenweg talked about one false report: Online, apparently, it’s fine for someone [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nommo</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-448175</link>
		<dc:creator>nommo</dc:creator>
		<pubDate>Thu, 17 Jul 2008 16:03:08 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-448175</guid>
		<description>A corporate blog that I &#039;manage&#039; - running 2.5.1 had it&#039;s entire table dropped last night. Looks like it was via wp-comments-post.php

I spent the day rebuilding.. you know what it&#039;s like, you only find out how crap your backup is when you need to use it. Lessons have been learned.</description>
		<content:encoded><![CDATA[<p>A corporate blog that I &#8216;manage&#8217; &#8211; running 2.5.1 had it&#8217;s entire table dropped last night. Looks like it was via wp-comments-post.php</p>
<p>I spent the day rebuilding.. you know what it&#8217;s like, you only find out how crap your backup is when you need to use it. Lessons have been learned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Guido</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-448057</link>
		<dc:creator>Dan Guido</dc:creator>
		<pubDate>Tue, 15 Jul 2008 15:27:30 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-448057</guid>
		<description>&gt; You can impress your friends by saying whether a security report is valid or not, so it’s a good critical facility to pick up.

Fail.

Don&#039;t knock the bug report on securityfocus, you should be happy some kiddie was kind enough to leak a good bug in Wordpress 2.5. If you took a few minutes to poke around in wp-comments-post.php then you might have found what RoMaNcYxHaCkEr did. Either way, upgrade to WP 2.6 now.</description>
		<content:encoded><![CDATA[<p>&gt; You can impress your friends by saying whether a security report is valid or not, so it’s a good critical facility to pick up.</p>
<p>Fail.</p>
<p>Don&#8217;t knock the bug report on securityfocus, you should be happy some kiddie was kind enough to leak a good bug in WordPress 2.5. If you took a few minutes to poke around in wp-comments-post.php then you might have found what RoMaNcYxHaCkEr did. Either way, upgrade to WP 2.6 now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zero Day mobile edition</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-448041</link>
		<dc:creator>Zero Day mobile edition</dc:creator>
		<pubDate>Tue, 15 Jul 2008 10:55:37 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-448041</guid>
		<description>[...] If you manage a WordPress blog, this should be considered an important update.  You should also pay close attention to Matt Mullenweg&#8217;s security recommendations. [...]</description>
		<content:encoded><![CDATA[<p>[...] If you manage a WordPress blog, this should be considered an important update.  You should also pay close attention to Matt Mullenweg&#8217;s security recommendations. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pattern Recognition &#187; Blog Archive &#187; Interesting WP Spam Hack</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-447952</link>
		<dc:creator>Pattern Recognition &#187; Blog Archive &#187; Interesting WP Spam Hack</dc:creator>
		<pubDate>Mon, 14 Jul 2008 20:17:26 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-447952</guid>
		<description>[...] but Joshua M. Neff told me it happened to him as well. In the comments there was a link to the wordpress developer&#8217;s blog about a similar issue&#8230;but not an identical issue. I don&#8217;t think this is necessarily a [...]</description>
		<content:encoded><![CDATA[<p>[...] but Joshua M. Neff told me it happened to him as well. In the comments there was a link to the wordpress developer&#8217;s blog about a similar issue&#8230;but not an identical issue. I don&#8217;t think this is necessarily a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Security Prevention, Reactions, and Scares &#171; Lorelle on WordPress</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442816</link>
		<dc:creator>WordPress Security Prevention, Reactions, and Scares &#171; Lorelle on WordPress</dc:creator>
		<pubDate>Mon, 28 Apr 2008 11:15:21 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442816</guid>
		<description>[...] Security Prevention, Reactions, and&#160;Scares  Matt Mullenweg spoke out recently on the recent bogus &#8220;SecurityFocus SQL Injection&#8221; fear spreading across the web. There is a huge perception today that WordPress is a security risk. This [...]</description>
		<content:encoded><![CDATA[<p>[...] Security Prevention, Reactions, and&nbsp;Scares  Matt Mullenweg spoke out recently on the recent bogus &#8220;SecurityFocus SQL Injection&#8221; fear spreading across the web. There is a huge perception today that WordPress is a security risk. This [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Wednesday News: WordCamps Everywhere, Webware 100 Again, Plugins to Fix WordPress 2.5, Change Admin Colors, and More : The Blog Herald</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442510</link>
		<dc:creator>WordPress Wednesday News: WordCamps Everywhere, Webware 100 Again, Plugins to Fix WordPress 2.5, Change Admin Colors, and More : The Blog Herald</dc:creator>
		<pubDate>Wed, 23 Apr 2008 23:50:38 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442510</guid>
		<description>[...] Security Prevention and Scares: Matt Mullenweg spoke out recently on the recent bogus &#8220;SecurityFocus SQL Injection&#8221; fear spreading across the web. He also offered some sensible tips and information for those worried [...]</description>
		<content:encoded><![CDATA[<p>[...] Security Prevention and Scares: Matt Mullenweg spoke out recently on the recent bogus &#8220;SecurityFocus SQL Injection&#8221; fear spreading across the web. He also offered some sensible tips and information for those worried [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Don&#8217;t Fall Behind &#171; The Panegyrist</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442224</link>
		<dc:creator>Don&#8217;t Fall Behind &#171; The Panegyrist</dc:creator>
		<pubDate>Tue, 22 Apr 2008 06:30:37 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442224</guid>
		<description>[...] Mullenweg, the creator (or something like that) of WordPress, recently posted about the need to keep your copy of WordPress up-to-date: not to keep up with the latest features, though that&#8217;s certainly a good enough reason for [...]</description>
		<content:encoded><![CDATA[<p>[...] Mullenweg, the creator (or something like that) of WordPress, recently posted about the need to keep your copy of WordPress up-to-date: not to keep up with the latest features, though that&#8217;s certainly a good enough reason for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noticias de Bitacoras.com &#187; Consejos para hacer tu blog más seguro</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442086</link>
		<dc:creator>Noticias de Bitacoras.com &#187; Consejos para hacer tu blog más seguro</dc:creator>
		<pubDate>Mon, 21 Apr 2008 13:03:44 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442086</guid>
		<description>[...] SecurityFocus SQL Injection Bogus [...]</description>
		<content:encoded><![CDATA[<p>[...] SecurityFocus SQL Injection Bogus [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442059</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Mon, 21 Apr 2008 00:33:01 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442059</guid>
		<description>Hone, you basically just described our VIP hosting:

http://wordpress.com/vip-hosting/</description>
		<content:encoded><![CDATA[<p>Hone, you basically just described our VIP hosting:</p>
<p><a href="http://wordpress.com/vip-hosting/" rel="nofollow">http://wordpress.com/vip-hosting/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress and Security &#124; nickbohle.de</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442053</link>
		<dc:creator>WordPress and Security &#124; nickbohle.de</dc:creator>
		<pubDate>Sun, 20 Apr 2008 23:07:32 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442053</guid>
		<description>[...] Don&#039;t hesitate to upgrade WordPress! Matt Mullenweg just wrote a great article about security and upgrading. [...]</description>
		<content:encoded><![CDATA[<p>[...] Don&#8217;t hesitate to upgrade WordPress! Matt Mullenweg just wrote a great article about security and upgrading. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tranpalitu &#187; Blog Archive &#187; Seguridad en WordPress</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442048</link>
		<dc:creator>Tranpalitu &#187; Blog Archive &#187; Seguridad en WordPress</dc:creator>
		<pubDate>Sun, 20 Apr 2008 20:51:38 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442048</guid>
		<description>[...] Las claves de la seguridad en WordPress son seg&#250;n Matthew Mullenweg: [...]</description>
		<content:encoded><![CDATA[<p>[...] Las claves de la seguridad en WordPress son seg&#250;n Matthew Mullenweg: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: .neteffect, April 20, 2008 &#124; BlogWell</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442047</link>
		<dc:creator>.neteffect, April 20, 2008 &#124; BlogWell</dc:creator>
		<pubDate>Sun, 20 Apr 2008 20:10:04 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442047</guid>
		<description>[...] SecurityFocus SQL injection bogus [...]</description>
		<content:encoded><![CDATA[<p>[...] SecurityFocus SQL injection bogus [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trevor Davis &#124; Blog &#124; Weekly Link Round-Up #27</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-442000</link>
		<dc:creator>Trevor Davis &#124; Blog &#124; Weekly Link Round-Up #27</dc:creator>
		<pubDate>Sun, 20 Apr 2008 03:14:22 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-442000</guid>
		<description>[...] SecurityFocus SQL Injection Bogus [...]</description>
		<content:encoded><![CDATA[<p>[...] SecurityFocus SQL Injection Bogus [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cómo hacer tu blog un poco más seguro &#187; blogpocket 7.0</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441998</link>
		<dc:creator>Cómo hacer tu blog un poco más seguro &#187; blogpocket 7.0</dc:creator>
		<pubDate>Sat, 19 Apr 2008 23:19:05 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441998</guid>
		<description>[...] Según cuenta Matthew Mullenweg en su blog, la versión 2.5 de WordPress no contiene vulnerabilidades, al hilo de un posible fallo de seguridad. En cualquier caso, el bueno de Matt nos aconseja adoptar tres medidas básicas para evitar disgustos: [...]</description>
		<content:encoded><![CDATA[<p>[...] Según cuenta Matthew Mullenweg en su blog, la versión 2.5 de WordPress no contiene vulnerabilidades, al hilo de un posible fallo de seguridad. En cualquier caso, el bueno de Matt nos aconseja adoptar tres medidas básicas para evitar disgustos: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ???????????? ?????????</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441996</link>
		<dc:creator>???????????? ?????????</dc:creator>
		<pubDate>Sat, 19 Apr 2008 20:22:03 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441996</guid>
		<description>[...] ??? ?????????? ???????????. ???? ?????, ????????? ?? ?? ?????? ??????????, ?? ??? ??? ??? ??? ???????? ????? ?????????????, ???? [...]</description>
		<content:encoded><![CDATA[<p>[...] ??? ?????????? ???????????. ???? ?????, ????????? ?? ?? ?????? ??????????, ?? ??? ??? ??? ??? ???????? ????? ?????????????, ???? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hone</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441987</link>
		<dc:creator>Hone</dc:creator>
		<pubDate>Sat, 19 Apr 2008 13:54:13 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441987</guid>
		<description>Matt, regarding SQL scalability etc, one service Automattic could offer on Wordpress.com is a $100 - $200 per month paid service which is equivalent to a single dedicated server - then it good go up in price as usage increases.

Lots of folks who are basically publishers have a suck time when they need to move to a dedicated server once their Wordpress blog gets to big.

I&#039;d buy this service even if there was zero support.  All I&#039;d need would be the ability to load my own theme - maybe via svn, and also be in the wordpress.com network so people could easily make comments etc.

It would also be cool if you also offered hosted Mu.  People always have the same problem once there blog gets too big.  They&#039;re smart enough to install it for a small user base but once you need multiple database servers etc it just becomes too much for your average punter.</description>
		<content:encoded><![CDATA[<p>Matt, regarding SQL scalability etc, one service Automattic could offer on WordPress.com is a $100 &#8211; $200 per month paid service which is equivalent to a single dedicated server &#8211; then it good go up in price as usage increases.</p>
<p>Lots of folks who are basically publishers have a suck time when they need to move to a dedicated server once their WordPress blog gets to big.</p>
<p>I&#8217;d buy this service even if there was zero support.  All I&#8217;d need would be the ability to load my own theme &#8211; maybe via svn, and also be in the wordpress.com network so people could easily make comments etc.</p>
<p>It would also be cool if you also offered hosted Mu.  People always have the same problem once there blog gets too big.  They&#8217;re smart enough to install it for a small user base but once you need multiple database servers etc it just becomes too much for your average punter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ::: Manuele Lancia ::: &#187; Blog Archive &#187; Exploit per Wordpress 2.5</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441986</link>
		<dc:creator>::: Manuele Lancia ::: &#187; Blog Archive &#187; Exploit per Wordpress 2.5</dc:creator>
		<pubDate>Sat, 19 Apr 2008 13:33:32 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441986</guid>
		<description>[...] malevolo, rendendo così possibile la modifica del database. Va detto come il bollettino sia stato criticato da Matt Mullenweg per la sua mancanza di informazioni [...]</description>
		<content:encoded><![CDATA[<p>[...] malevolo, rendendo così possibile la modifica del database. Va detto come il bollettino sia stato criticato da Matt Mullenweg per la sua mancanza di informazioni [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bontb</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441966</link>
		<dc:creator>Bontb</dc:creator>
		<pubDate>Fri, 18 Apr 2008 22:12:20 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441966</guid>
		<description>I was one of the victims well not for bontb.com but on hawaiib.com &quot;which i removed now&quot;

Read what I wrote 
http://www.bontb.com/2008/03/wp-content1-trojan-virus-for-wordpress-bloggers/</description>
		<content:encoded><![CDATA[<p>I was one of the victims well not for bontb.com but on hawaiib.com &#8220;which i removed now&#8221;</p>
<p>Read what I wrote<br />
<a href="http://www.bontb.com/2008/03/wp-content1-trojan-virus-for-wordpress-bloggers/" rel="nofollow">http://www.bontb.com/2008/03/wp-content1-trojan-virus-for-wordpress-bloggers/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Usayd</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441964</link>
		<dc:creator>Usayd</dc:creator>
		<pubDate>Fri, 18 Apr 2008 21:07:46 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441964</guid>
		<description>Some good points raised matt, thanks.

I have to admit, it&#039;s pretty hard to maintain a number of WordPress websites simultaneously and keep them up to date. It&#039;s apparent that you guys are aware of this, but the obvious point is that it will take an upgrade to the version where this feature becomes available before one click upgrades will take place :)</description>
		<content:encoded><![CDATA[<p>Some good points raised matt, thanks.</p>
<p>I have to admit, it&#8217;s pretty hard to maintain a number of WordPress websites simultaneously and keep them up to date. It&#8217;s apparent that you guys are aware of this, but the obvious point is that it will take an upgrade to the version where this feature becomes available before one click upgrades will take place <img src='http://s.ma.tt/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441950</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Fri, 18 Apr 2008 15:18:59 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441950</guid>
		<description>Derek, as I mentioned in the post, this is a high priority for us.</description>
		<content:encoded><![CDATA[<p>Derek, as I mentioned in the post, this is a high priority for us.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Derek</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441945</link>
		<dc:creator>Derek</dc:creator>
		<pubDate>Fri, 18 Apr 2008 12:59:03 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441945</guid>
		<description>I believe the best thing that could be done is to make an automatic upgrade function in the core. Just like the plugin page does now...there is a new version available, click to update automatically...why not have that functionality built into the &quot;There is a new version of Wordpress available...&quot; link. Click the link and &quot;blam&quot; you are upgraded!</description>
		<content:encoded><![CDATA[<p>I believe the best thing that could be done is to make an automatic upgrade function in the core. Just like the plugin page does now&#8230;there is a new version available, click to update automatically&#8230;why not have that functionality built into the &#8220;There is a new version of WordPress available&#8230;&#8221; link. Click the link and &#8220;blam&#8221; you are upgraded!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441920</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Fri, 18 Apr 2008 00:40:40 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441920</guid>
		<description>This is very cool and very helpful to WP bloggers. I have doing my best to follow the version upgrade. Also, I think the plugin - WP security scan is a good security enhancement to WP, no matter how perfect it does, but this approach. Thanks.</description>
		<content:encoded><![CDATA[<p>This is very cool and very helpful to WP bloggers. I have doing my best to follow the version upgrade. Also, I think the plugin &#8211; WP security scan is a good security enhancement to WP, no matter how perfect it does, but this approach. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ryan</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441913</link>
		<dc:creator>ryan</dc:creator>
		<pubDate>Thu, 17 Apr 2008 21:58:16 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441913</guid>
		<description>Matt I saw your video from the Word whatever thing in Texas.  Blogger convention basically.  You are a likeable enough chap and well intentioned I&#039;d say so don&#039;t read this as an attack.

I&#039;ve gotta say, it&#039;s almost as if Wordpress is in a competition with phpBB for frequency and sheer number of vulns.  We&#039;ve got this sql injection issue and then we learn the salted passwords work great, but users aren&#039;t being educated enough to change the random phrase.  http://seclists.org/bugtraq/2008/Apr/0164.html

I like the functionality of Wordpress and I like the features but can&#039;t recommend it to non-techies who want a hands off blogging feature.  The problem is the non-techies have their techie friend install it and then never look at it again.

What I&#039;d like to see is a Wordpress.com along the lines of Typepad, where we get a packaged deal that&#039;s not crippled like Wordpress.com is.  You guys could have the fun of patching and keeping a decent number of plugins available and we&#039;d happliy pay money and blog.

Wordpress will have a black eye soon because of all the comment spam and splogs that are built with it.  Much like including the WP logo on prior versions made people associate database connection issues with Wordpress regardless of what the problem is.  I see that went away in 2.5.

People used to complain about splogs on Blogger, there are still some, but most of them that I run across these days are on WP.  Hell, someone sells a tool to make them.

This is a prediction from Matt Cutts in his blog for 2008
&quot;2008 will be the year that hacking and search engine optimization (SEO) collide in a major way. By the end of the year, a nontrivial fraction of blackhat SEO will involve illegally hacking sites for links or landing pages. One webhost will get a significant black eye as hundreds or thousands of customers’ websites are hacked.&quot;

I think this will turn out true, though it might be one product rather than one web host, or maybe the product that gives them the door is Wordpress.

Food for thought.  I&#039;m still running 2.5 for a couple of my blogs.

Sleeping with one eye open,

Ryan</description>
		<content:encoded><![CDATA[<p>Matt I saw your video from the Word whatever thing in Texas.  Blogger convention basically.  You are a likeable enough chap and well intentioned I&#8217;d say so don&#8217;t read this as an attack.</p>
<p>I&#8217;ve gotta say, it&#8217;s almost as if WordPress is in a competition with phpBB for frequency and sheer number of vulns.  We&#8217;ve got this sql injection issue and then we learn the salted passwords work great, but users aren&#8217;t being educated enough to change the random phrase.  <a href="http://seclists.org/bugtraq/2008/Apr/0164.html" rel="nofollow">http://seclists.org/bugtraq/2008/Apr/0164.html</a></p>
<p>I like the functionality of WordPress and I like the features but can&#8217;t recommend it to non-techies who want a hands off blogging feature.  The problem is the non-techies have their techie friend install it and then never look at it again.</p>
<p>What I&#8217;d like to see is a WordPress.com along the lines of Typepad, where we get a packaged deal that&#8217;s not crippled like WordPress.com is.  You guys could have the fun of patching and keeping a decent number of plugins available and we&#8217;d happliy pay money and blog.</p>
<p>WordPress will have a black eye soon because of all the comment spam and splogs that are built with it.  Much like including the WP logo on prior versions made people associate database connection issues with WordPress regardless of what the problem is.  I see that went away in 2.5.</p>
<p>People used to complain about splogs on Blogger, there are still some, but most of them that I run across these days are on WP.  Hell, someone sells a tool to make them.</p>
<p>This is a prediction from Matt Cutts in his blog for 2008<br />
&#8220;2008 will be the year that hacking and search engine optimization (SEO) collide in a major way. By the end of the year, a nontrivial fraction of blackhat SEO will involve illegally hacking sites for links or landing pages. One webhost will get a significant black eye as hundreds or thousands of customers’ websites are hacked.&#8221;</p>
<p>I think this will turn out true, though it might be one product rather than one web host, or maybe the product that gives them the door is WordPress.</p>
<p>Food for thought.  I&#8217;m still running 2.5 for a couple of my blogs.</p>
<p>Sleeping with one eye open,</p>
<p>Ryan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uncle Che</title>
		<link>http://ma.tt/2008/04/securityfocus-sql-injection-bogus/#comment-441885</link>
		<dc:creator>Uncle Che</dc:creator>
		<pubDate>Thu, 17 Apr 2008 12:26:48 +0000</pubDate>
		<guid isPermaLink="false">http://ma.tt/?p=5198#comment-441885</guid>
		<description>I think upgrading wordpress is as easy as we can imagine. I have instructed people who cannot even install a plugin and they have been able to do it. A plugin on wordpress.org named WP Automatic Upgrade has worked on 26 different blogs on 19 diffrent accounts which i have helped friends upgrade free of charge. 

If you find someone who still can&#039;t upgrade and you don&#039;t have enough time to help, please send him/her to me.</description>
		<content:encoded><![CDATA[<p>I think upgrading wordpress is as easy as we can imagine. I have instructed people who cannot even install a plugin and they have been able to do it. A plugin on wordpress.org named WP Automatic Upgrade has worked on 26 different blogs on 19 diffrent accounts which i have helped friends upgrade free of charge. </p>
<p>If you find someone who still can&#8217;t upgrade and you don&#8217;t have enough time to help, please send him/her to me.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

