<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The WordPress Security Update</title>
	<atom:link href="http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/</link>
	<description>News, opinion, and fresh thinking for web developers and designers. The official podcast of sitepoint.com.</description>
	<lastBuildDate>Fri, 12 Mar 2010 18:32:11 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: itlitjacgg</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-191421</link>
		<dc:creator>itlitjacgg</dc:creator>
		<pubDate>Thu, 01 Mar 2007 08:34:43 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-191421</guid>
		<description>&lt;a href=&quot;http://vtxtqvl.com&quot; rel=&quot;nofollow&quot;&gt;jitcplm&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://vtxtqvl.com" rel="nofollow">jitcplm</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: wvrvvspovp</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-190964</link>
		<dc:creator>wvrvvspovp</dc:creator>
		<pubDate>Wed, 28 Feb 2007 15:31:18 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-190964</guid>
		<description>Hi! Very nice site! Thanks you very much! tivwxiewjipe</description>
		<content:encoded><![CDATA[<p>Hi! Very nice site! Thanks you very much! tivwxiewjipe</p>]]></content:encoded>
	</item>
	<item>
		<title>By: JiggyWittit</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-15144</link>
		<dc:creator>JiggyWittit</dc:creator>
		<pubDate>Mon, 06 Mar 2006 13:54:24 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-15144</guid>
		<description>Kewl blog you got goin on up here.
Peace, JiggyWittit</description>
		<content:encoded><![CDATA[<p>Kewl blog you got goin on up here.<br />
Peace, JiggyWittit</p>]]></content:encoded>
	</item>
	<item>
		<title>By: TreeFrog</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-14283</link>
		<dc:creator>TreeFrog</dc:creator>
		<pubDate>Wed, 22 Feb 2006 03:41:58 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-14283</guid>
		<description>Terrific Blog you have. Peace Out.
TreeFrog</description>
		<content:encoded><![CDATA[<p>Terrific Blog you have. Peace Out.<br />
TreeFrog</p>]]></content:encoded>
	</item>
	<item>
		<title>By: DDDSoft</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-13913</link>
		<dc:creator>DDDSoft</dc:creator>
		<pubDate>Mon, 13 Feb 2006 13:27:19 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-13913</guid>
		<description>Thx, This a good site!

http://dddsoft.com</description>
		<content:encoded><![CDATA[<p>Thx, This a good site!</p>
<p><a href="http://dddsoft.com" rel="nofollow">http://dddsoft.com</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress - XOOPS CHINA</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-9870</link>
		<dc:creator>WordPress - XOOPS CHINA</dc:creator>
		<pubDate>Thu, 13 Oct 2005 03:44:25 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-9870</guid>
		<description></description>
		<content:encoded><![CDATA[<p>[...] 好久没上SitePoint的网站，今天在调试一个程序时用到它的rss，偶然发现它居然不知从什么时候换成了WordPress，偷偷摸摸的，就像The WordPress Security Update里所争论的 [...]</p>]]></content:encoded>
	</item>
	<item>
		<title>By: ce</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-8139</link>
		<dc:creator>ce</dc:creator>
		<pubDate>Fri, 19 Aug 2005 08:36:45 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-8139</guid>
		<description>about the PHP :-)
a) mentioned on the download site!!! the right place is the front page!!! I will never check the download page if there is no new version. now I have a file called php-5.0.4.tar.bz2 I should check EVRY TIME if it is the correct file (I still have somewhere this buggy file)
b) lacking files from PEAR ok, not a security problem, but still a bug
c) you never say never :-)

P.S. I don&#039;t know wordpress at all (haven&#039;t heart of it until now), I am just disapointed by PHP from their style of development the last few months/years, and I am pressed to try alternatives thats all (just a fit of nerves) peace! :-))</description>
		<content:encoded><![CDATA[<p>about the PHP :-)<br />
a) mentioned on the download site!!! the right place is the front page!!! I will never check the download page if there is no new version. now I have a file called php-5.0.4.tar.bz2 I should check EVRY TIME if it is the correct file (I still have somewhere this buggy file)<br />
b) lacking files from PEAR ok, not a security problem, but still a bug<br />
c) you never say never :-)</p>
<p>P.S. I don&#8217;t know wordpress at all (haven&#8217;t heart of it until now), I am just disapointed by PHP from their style of development the last few months/years, and I am pressed to try alternatives thats all (just a fit of nerves) peace! :-))</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-2418</link>
		<dc:creator>Stefan</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2418</guid>
		<description>&lt;p&gt;Just a &quot;little&quot; correction. &lt;/p&gt;

&lt;p&gt;&quot;Dougall admits that the first downloadable archive to be posted on wordpress.org didn&#039;t contain all the security fixes they intended to include...&quot;&lt;/p&gt;

&lt;p&gt;This sounds as if they only forgot to put a fix into the release, but this is simply not true, because I downloaded the 1.5.2 release tarball to check if they had really fixed the SQL holes that I had reported. I realised that those were fixed and so I checked how they fixed the remote code execution. It turned out, that this fix was worth nothing because it was easy bypassable and so I sent them a patch to fix it. (7 hours before the replacement)&lt;/p&gt;

&lt;p&gt;And there are enough timestamps in the subversion tree, the release tarball and the blog posting, to prove, that the announcement was made ATLEAST 4 hours and 45 minutes before the tarball was replaced, and that the original tarball was created 9 hours before the replaced one.&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>Just a &#8220;little&#8221; correction. </p>
<p>&#8220;Dougall admits that the first downloadable archive to be posted on wordpress.org didn&#8217;t contain all the security fixes they intended to include&#8230;&#8221;</p>
<p>This sounds as if they only forgot to put a fix into the release, but this is simply not true, because I downloaded the 1.5.2 release tarball to check if they had really fixed the SQL holes that I had reported. I realised that those were fixed and so I checked how they fixed the remote code execution. It turned out, that this fix was worth nothing because it was easy bypassable and so I sent them a patch to fix it. (7 hours before the replacement)</p>
<p>And there are enough timestamps in the subversion tree, the release tarball and the blog posting, to prove, that the announcement was made ATLEAST 4 hours and 45 minutes before the tarball was replaced, and that the original tarball was created 9 hours before the replaced one.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-2419</link>
		<dc:creator>Stefan</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2419</guid>
		<description>&lt;p&gt;&quot;Amusingly, it appears that hours after the blog post went live, Stefan renamed the post&#039;s title to &#039;WordPress - irresponsible silent tarball update&#039; without notice.&quot;&lt;/p&gt;

&lt;p&gt;So the term &quot;Update:&quot; is no notice of changes? And you really compare a changed blog entry title with a silently fixed remote code execution hole? And btw. the blog title was changed only minutes and not hours after the Post. &lt;/p&gt;

&lt;p&gt;It was bad luck that planet-php and other aggregators were fast enough to get the explicit title. However it underlines that even in a very very short timewindow downloads are possible.&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>&#8220;Amusingly, it appears that hours after the blog post went live, Stefan renamed the post&#8217;s title to &#8216;WordPress &#8211; irresponsible silent tarball update&#8217; without notice.&#8221;</p>
<p>So the term &#8220;Update:&#8221; is no notice of changes? And you really compare a changed blog entry title with a silently fixed remote code execution hole? And btw. the blog title was changed only minutes and not hours after the Post. </p>
<p>It was bad luck that planet-php and other aggregators were fast enough to get the explicit title. However it underlines that even in a very very short timewindow downloads are possible.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-2420</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2420</guid>
		<description>&lt;p&gt;PHP itself did such a thing with 5.0.4 or 5.0.3 (I don&#039;t remember exactly) and it is quite a stupid thing for a mature project :-(&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>PHP itself did such a thing with 5.0.4 or 5.0.3 (I don&#8217;t remember exactly) and it is quite a stupid thing for a mature project :-(</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Stefan</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-2421</link>
		<dc:creator>Stefan</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2421</guid>
		<description>&lt;p&gt;Mr. Anonymous, this is partly right. It is true that PHP 5.0.4 was rereleased. But a) it was mentioned on the download site and not done silently and b) this was because the original tarball was lacking files, it was broken. c) PHP would never change a tarball afterwards to silently fix a security problem.&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>Mr. Anonymous, this is partly right. It is true that PHP 5.0.4 was rereleased. But a) it was mentioned on the download site and not done silently and b) this was because the original tarball was lacking files, it was broken. c) PHP would never change a tarball afterwards to silently fix a security problem.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Pierrick</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-2422</link>
		<dc:creator>Pierrick</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2422</guid>
		<description>&lt;p&gt;I thought this behaviour (rerelease silently) was proprietary software editors property! (I work in such a company and this is what we do everyday :-/)&lt;/p&gt;

&lt;p&gt;I can&#039;t understand why Wordpress developers did this!&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>I thought this behaviour (rerelease silently) was proprietary software editors property! (I work in such a company and this is what we do everyday :-/)</p>
<p>I can&#8217;t understand why Wordpress developers did this!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: z0s0</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-2423</link>
		<dc:creator>z0s0</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2423</guid>
		<description>&lt;p&gt;And.. now announcing the new SitePoint blogs... powered by Wordpress!&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p>And.. now announcing the new SitePoint blogs&#8230; powered by Wordpress!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: ChiliJ</title>
		<link>http://www.sitepoint.com/blogs/2005/08/18/the-wordpress-security-update/comment-page-1/#comment-2424</link>
		<dc:creator>ChiliJ</dc:creator>
		<pubDate>Tue, 30 Nov 1999 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">927626957#comment-2424</guid>
		<description>&lt;p&gt;&lt;i&gt;I thought this behaviour (rerelease silently) was proprietary software editors property!&lt;/i&gt;&lt;/p&gt;

&lt;p&gt;Perhaps wordpress is going proprietary.. lol&lt;/p&gt;

</description>
		<content:encoded><![CDATA[<p><i>I thought this behaviour (rerelease silently) was proprietary software editors property!</i></p>
<p>Perhaps wordpress is going proprietary.. lol</p>]]></content:encoded>
	</item>
</channel>
</rss>
