<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Upgraded to WordPress 2.3.3 &#8216;Coz of Security Issues, Again!</title>
	<atom:link href="http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/feed/" rel="self" type="application/rss+xml" />
	<link>http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/</link>
	<description>Faith, Technology and Randomness in Life, According to Scott</description>
	<lastBuildDate>Wed, 08 Feb 2012 13:17:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: DreamHost Enters Into Application Hosting &#124; HostingFu</title>
		<link>http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90836</link>
		<dc:creator>DreamHost Enters Into Application Hosting &#124; HostingFu</dc:creator>
		<pubDate>Thu, 07 Feb 2008 01:16:07 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90836</guid>
		<description>[...]  Posted on February 7, 2008 - 10:18am Yesterday on my personal blog, I wrote about WordPress 2.3.3 upgrade due to a security exploit, and one issue I wrote in the comment, is that there are just too many blogs out there installed by [...]</description>
		<content:encoded><![CDATA[<p>[...]  Posted on February 7, 2008 &#8211; 10:18am Yesterday on my personal blog, I wrote about WordPress 2.3.3 upgrade due to a security exploit, and one issue I wrote in the comment, is that there are just too many blogs out there installed by [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mark</title>
		<link>http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90808</link>
		<dc:creator>mark</dc:creator>
		<pubDate>Wed, 06 Feb 2008 06:04:47 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90808</guid>
		<description>not all wordpress sucks, just the diy version ;)

XML-RPC?

unsupported branches?

security issues?

$ svn diff?

2.1/2.2?

&quot;there might be millions of blogs out there that are not patched because they were installed by Fantastico and alike&quot;

holy cow, I wouldn&#039;t wish that stuff on my worst enemy and certainly never recommend it to a non programmer, yet it&#039;s still the one of the most popular blogging solutions? crazy world.</description>
		<content:encoded><![CDATA[<p>not all wordpress sucks, just the diy version ;)</p>
<p>XML-RPC?</p>
<p>unsupported branches?</p>
<p>security issues?</p>
<p>$ svn diff?</p>
<p>2.1/2.2?</p>
<p>&#8220;there might be millions of blogs out there that are not patched because they were installed by Fantastico and alike&#8221;</p>
<p>holy cow, I wouldn&#8217;t wish that stuff on my worst enemy and certainly never recommend it to a non programmer, yet it&#8217;s still the one of the most popular blogging solutions? crazy world.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90804</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 06 Feb 2008 02:44:54 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90804</guid>
		<description>Man it frustrates me too. Hopefully with the update notification added in 2.3 and the one-click upgrades coming in 2.5 we&#039;ll get more people updating when we do a release.

I think you also have a good point that we need to put pressure on the hosts and Fantastico to take responsibility for the blogs that they set up and stay current with releases.</description>
		<content:encoded><![CDATA[<p>Man it frustrates me too. Hopefully with the update notification added in 2.3 and the one-click upgrades coming in 2.5 we&#8217;ll get more people updating when we do a release.</p>
<p>I think you also have a good point that we need to put pressure on the hosts and Fantastico to take responsibility for the blogs that they set up and stay current with releases.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scotty</title>
		<link>http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90803</link>
		<dc:creator>scotty</dc:creator>
		<pubDate>Wed, 06 Feb 2008 02:30:33 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90803</guid>
		<description>Matt,

Thanks for the clarification, especially on how the ticket was updated. No, I am not being angry, but frustrated. It is easy for me to keep up with WordPress development and new releases, but (due to WP&#039;s popularity) there might be millions of blogs out there that are not patched because they were installed by Fantastico and alike. A few days ago I have to report to PodShow that some of their blogs were hacked -- and I thought they are big and tech-savvy enough to know that they need to keep up to date? Not entirely WordPress&#039; fault, but frustrating nevertheless.

Sorry that I did not know the official stable branches are 2.0 and 2.3. I have just checked the code and it appears 2.0/2.1 are not affected but 2.2/2.3.2 are.

Thanks again for the explanation.</description>
		<content:encoded><![CDATA[<p>Matt,</p>
<p>Thanks for the clarification, especially on how the ticket was updated. No, I am not being angry, but frustrated. It is easy for me to keep up with WordPress development and new releases, but (due to WP&#8217;s popularity) there might be millions of blogs out there that are not patched because they were installed by Fantastico and alike. A few days ago I have to report to PodShow that some of their blogs were hacked &#8212; and I thought they are big and tech-savvy enough to know that they need to keep up to date? Not entirely WordPress&#8217; fault, but frustrating nevertheless.</p>
<p>Sorry that I did not know the official stable branches are 2.0 and 2.3. I have just checked the code and it appears 2.0/2.1 are not affected but 2.2/2.3.2 are.</p>
<p>Thanks again for the explanation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90802</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 06 Feb 2008 01:55:55 +0000</pubDate>
		<guid isPermaLink="false">http://scott.yang.id.au/2008/02/upgraded-to-wordpress-233-coz-of-security-issues-again/#comment-90802</guid>
		<description>It&#039;s sounds like you&#039;re pretty angry about this release, and it always sucks to have to do one due to security, but let me clarify two things.

The ticket is a little confusing, even though the issue was opened up 3 months ago there was not enough information to identify the issue and it was closed. The original poster said as much on wp-hackers the other day. When the new issue came to light Lloyd Budd edited the ticket to update it with the new information, and the fix was there within hours, not months later as it may look from the ticket.

The problem doesn&#039;t apply to 2.0 users, which is the stable branch we&#039;ve committed to maintaining through 2010. 2.1/2.2 are both unsupported branches, I don&#039;t think they&#039;re affected by this issue but they probably have others, you should be running either 2.0.latest or 2.3.latest. You could also protect your blog from this and the previous issue you refer to by turning off open registration, which is actually off by default when you install WP.

Do you have any more questions about the release I could answer? I&#039;m happy to try my best to clarify what the situation is and what the thinking was behind issues.</description>
		<content:encoded><![CDATA[<p>It&#8217;s sounds like you&#8217;re pretty angry about this release, and it always sucks to have to do one due to security, but let me clarify two things.</p>
<p>The ticket is a little confusing, even though the issue was opened up 3 months ago there was not enough information to identify the issue and it was closed. The original poster said as much on wp-hackers the other day. When the new issue came to light Lloyd Budd edited the ticket to update it with the new information, and the fix was there within hours, not months later as it may look from the ticket.</p>
<p>The problem doesn&#8217;t apply to 2.0 users, which is the stable branch we&#8217;ve committed to maintaining through 2010. 2.1/2.2 are both unsupported branches, I don&#8217;t think they&#8217;re affected by this issue but they probably have others, you should be running either 2.0.latest or 2.3.latest. You could also protect your blog from this and the previous issue you refer to by turning off open registration, which is actually off by default when you install WP.</p>
<p>Do you have any more questions about the release I could answer? I&#8217;m happy to try my best to clarify what the situation is and what the thinking was behind issues.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

