<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: The WordPress Security Update</title>
	<atom:link href="http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/</link>
	<description>News, opinion, and fresh thinking for web developers and designers. The official podcast of sitepoint.com.</description>
	<pubDate>Tue, 02 Dec 2008 07:47:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: itlitjacgg</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-191421</link>
		<dc:creator>itlitjacgg</dc:creator>
		<pubDate>Thu, 01 Mar 2007 08:34:43 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-191421</guid>
		<description>&lt;a href="http://vtxtqvl.com" rel="nofollow"&gt;jitcplm&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://vtxtqvl.com" rel="nofollow">jitcplm</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: wvrvvspovp</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-190964</link>
		<dc:creator>wvrvvspovp</dc:creator>
		<pubDate>Wed, 28 Feb 2007 15:31:18 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-190964</guid>
		<description>Hi! Very nice site! Thanks you very much! tivwxiewjipe</description>
		<content:encoded><![CDATA[<p>Hi! Very nice site! Thanks you very much! tivwxiewjipe</p>]]></content:encoded>
	</item>
	<item>
		<title>By: JiggyWittit</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-15144</link>
		<dc:creator>JiggyWittit</dc:creator>
		<pubDate>Mon, 06 Mar 2006 13:54:24 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-15144</guid>
		<description>Kewl blog you got goin on up here.
Peace, JiggyWittit</description>
		<content:encoded><![CDATA[<p>Kewl blog you got goin on up here.<br />
Peace, JiggyWittit</p>]]></content:encoded>
	</item>
	<item>
		<title>By: TreeFrog</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-14283</link>
		<dc:creator>TreeFrog</dc:creator>
		<pubDate>Wed, 22 Feb 2006 03:41:58 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-14283</guid>
		<description>Terrific Blog you have. Peace Out.
TreeFrog</description>
		<content:encoded><![CDATA[<p>Terrific Blog you have. Peace Out.<br />
TreeFrog</p>]]></content:encoded>
	</item>
	<item>
		<title>By: DDDSoft</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-13913</link>
		<dc:creator>DDDSoft</dc:creator>
		<pubDate>Mon, 13 Feb 2006 13:27:19 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-13913</guid>
		<description>Thx, This a good site!

http://dddsoft.com</description>
		<content:encoded><![CDATA[<p>Thx, This a good site!</p>
<p><a href="http://dddsoft.com" rel="nofollow">http://dddsoft.com</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress - XOOPS CHINA</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-9870</link>
		<dc:creator>WordPress - XOOPS CHINA</dc:creator>
		<pubDate>Thu, 13 Oct 2005 03:44:25 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-9870</guid>
		<description>[...] 好久没上SitePoint的网站，今天在调试一个程序时用到它的rss，偶然发现它居然不知从什么时候换成了WordPress，偷偷摸摸的，就像The WordPress Security Update里所争论的 [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] 好久没上SitePoint的网站，今天在调试一个程序时用到它的rss，偶然发现它居然不知从什么时候换成了WordPress，偷偷摸摸的，就像The WordPress Security Update里所争论的 [&#8230;]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: ce</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-8139</link>
		<dc:creator>ce</dc:creator>
		<pubDate>Fri, 19 Aug 2005 08:36:45 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-8139</guid>
		<description>about the PHP :-)
a) mentioned on the download site!!! the right place is the front page!!! I will never check the download page if there is no new version. now I have a file called php-5.0.4.tar.bz2 I should check EVRY TIME if it is the correct file (I still have somewhere this buggy file)
b) lacking files from PEAR ok, not a security problem, but still a bug
c) you never say never :-)

P.S. I don't know wordpress at all (haven't heart of it until now), I am just disapointed by PHP from their style of development the last few months/years, and I am pressed to try alternatives thats all (just a fit of nerves) peace! :-))</description>
		<content:encoded><![CDATA[<p>about the PHP :-)<br />
a) mentioned on the download site!!! the right place is the front page!!! I will never check the download page if there is no new version. now I have a file called php-5.0.4.tar.bz2 I should check EVRY TIME if it is the correct file (I still have somewhere this buggy file)<br />
b) lacking files from PEAR ok, not a security problem, but still a bug<br />
c) you never say never :-)</p>
<p>P.S. I don&#8217;t know wordpress at all (haven&#8217;t heart of it until now), I am just disapointed by PHP from their style of development the last few months/years, and I am pressed to try alternatives thats all (just a fit of nerves) peace! :-))</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-2418</link>
		<dc:creator>Stefan</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2418</guid>
		<description>&lt;p&gt;Just a "little" correction. &lt;/p&gt;

&lt;p&gt;"Dougall admits that the first downloadable archive to be posted on wordpress.org didn't contain all the security fixes they intended to include..."&lt;/p&gt;

&lt;p&gt;This sounds as if they only forgot to put a fix into the release, but this is simply not true, because I downloaded the 1.5.2 release tarball to check if they had really fixed the SQL holes that I had reported. I realised that those were fixed and so I checked how they fixed the remote code execution. It turned out, that this fix was worth nothing because it was easy bypassable and so I sent them a patch to fix it. (7 hours before the replacement)&lt;/p&gt;

&lt;p&gt;And there are enough timestamps in the subversion tree, the release tarball and the blog posting, to prove, that the announcement was made ATLEAST 4 hours and 45 minutes before the tarball was replaced, and that the original tarball was created 9 hours before the replaced one.&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>Just a &#8220;little&#8221; correction. </p>
<p>&#8220;Dougall admits that the first downloadable archive to be posted on wordpress.org didn&#8217;t contain all the security fixes they intended to include&#8230;&#8221;</p>
<p>This sounds as if they only forgot to put a fix into the release, but this is simply not true, because I downloaded the 1.5.2 release tarball to check if they had really fixed the SQL holes that I had reported. I realised that those were fixed and so I checked how they fixed the remote code execution. It turned out, that this fix was worth nothing because it was easy bypassable and so I sent them a patch to fix it. (7 hours before the replacement)</p>
<p>And there are enough timestamps in the subversion tree, the release tarball and the blog posting, to prove, that the announcement was made ATLEAST 4 hours and 45 minutes before the tarball was replaced, and that the original tarball was created 9 hours before the replaced one.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-2419</link>
		<dc:creator>Stefan</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2419</guid>
		<description>&lt;p&gt;"Amusingly, it appears that hours after the blog post went live, Stefan renamed the post's title to 'WordPress - irresponsible silent tarball update' without notice."&lt;/p&gt;

&lt;p&gt;So the term "Update:" is no notice of changes? And you really compare a changed blog entry title with a silently fixed remote code execution hole? And btw. the blog title was changed only minutes and not hours after the Post. &lt;/p&gt;

&lt;p&gt;It was bad luck that planet-php and other aggregators were fast enough to get the explicit title. However it underlines that even in a very very short timewindow downloads are possible.&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>&#8220;Amusingly, it appears that hours after the blog post went live, Stefan renamed the post&#8217;s title to &#8216;WordPress - irresponsible silent tarball update&#8217; without notice.&#8221;</p>
<p>So the term &#8220;Update:&#8221; is no notice of changes? And you really compare a changed blog entry title with a silently fixed remote code execution hole? And btw. the blog title was changed only minutes and not hours after the Post. </p>
<p>It was bad luck that planet-php and other aggregators were fast enough to get the explicit title. However it underlines that even in a very very short timewindow downloads are possible.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/#comment-2420</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 31 Dec 1969 19:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2420</guid>
		<description>&lt;p&gt;PHP itself did such a thing with 5.0.4 or 5.0.3 (I don't remember exactly) and it is quite a stupid thing for a mature project :-(&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>PHP itself did such a thing with 5.0.4 or 5.0.3 (I don&#8217;t remember exactly) and it is quite a stupid thing for a mature project :-(</p>]]></content:encoded>
	</item>
</channel>
</rss>
