<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Critical Announcement affecting ALL Wordpress users</title>
	<atom:link href="http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/feed/" rel="self" type="application/rss+xml" />
	<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/</link>
	<description>Chemically-enhanced neural rewiring, on a semi-regular basis...</description>
	<lastBuildDate>Sun, 07 Mar 2010 16:40:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Innovative Discussions &#187; Blog Archive &#187; abcd post to remove</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-150207</link>
		<dc:creator>Innovative Discussions &#187; Blog Archive &#187; abcd post to remove</dc:creator>
		<pubDate>Wed, 10 Mar 2010 21:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-150207</guid>
		<description>[...] Notre bon docteur Dave, entre autres choses responsables de l’excellent et indispensable plug-in Spam Karma (que votre serviteur préfère à Akismet, en passant) signale une faille de sécurité assez importante pour toutes les versions de WordPress. [...]</description>
		<content:encoded><![CDATA[<p>[...] Notre bon docteur Dave, entre autres choses responsables de l’excellent et indispensable plug-in Spam Karma (que votre serviteur préfère à Akismet, en passant) signale une faille de sécurité assez importante pour toutes les versions de WordPress. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Easy Does It University &#187; WordPress has drama</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-105782</link>
		<dc:creator>Easy Does It University &#187; WordPress has drama</dc:creator>
		<pubDate>Wed, 10 Mar 2010 09:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-105782</guid>
		<description>[...] Authors of popular plugins for WordPress such as Dr. Dave (Spam Karma) are discontinuing their association with WordPress because of some baby mama drama jamma damma. I didn&#8217;t really read through everyones blogs to see what everyones points of views were (the main WordPress developers vs. outside WordPress developers) but it seemed basically like the outside people were not liking the way Matt (co-creator and owner of WP) was handling things or maybe it&#8217;s because WP might be doing some evil stuff on the side. I guess everyone has their share of drama - even the nerds.    Posted by Eric on Saturday, September 23, 2006 12:50 am    (Possibly) Related Posts: [...]</description>
		<content:encoded><![CDATA[<p>[...] Authors of popular plugins for WordPress such as Dr. Dave (Spam Karma) are discontinuing their association with WordPress because of some baby mama drama jamma damma. I didn&#8217;t really read through everyones blogs to see what everyones points of views were (the main WordPress developers vs. outside WordPress developers) but it seemed basically like the outside people were not liking the way Matt (co-creator and owner of WP) was handling things or maybe it&#8217;s because WP might be doing some evil stuff on the side. I guess everyone has their share of drama &#8211; even the nerds.    Posted by Eric on Saturday, September 23, 2006 12:50 am    (Possibly) Related Posts: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maria Langer, the Official Web Site* &#187; WordPress Security Alert!</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-102558</link>
		<dc:creator>Maria Langer, the Official Web Site* &#187; WordPress Security Alert!</dc:creator>
		<pubDate>Wed, 10 Mar 2010 03:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-102558</guid>
		<description>[...] Dr Dave, developer of the must-have spam prevention tool, Spam Karma, sent out the following alert message to all Spam Karma users as an announcement in the Spam Karma administration panel: MAJOR SECURITY ANNOUNCEMENT Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable &#8216;guest user registration&#8217; on your blog if it&#8217;s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke. [...]</description>
		<content:encoded><![CDATA[<p>[...] Dr Dave, developer of the must-have spam prevention tool, Spam Karma, sent out the following alert message to all Spam Karma users as an announcement in the Spam Karma administration panel: MAJOR SECURITY ANNOUNCEMENT Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable &#8216;guest user registration&#8217; on your blog if it&#8217;s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Visual QuickStart Guide &#187; Security Alert!</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-100786</link>
		<dc:creator>WordPress Visual QuickStart Guide &#187; Security Alert!</dc:creator>
		<pubDate>Wed, 10 Mar 2010 04:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-100786</guid>
		<description>[...] Security Alert!   Filed under: General Info, Tips &amp; Tricks by Maria on July 26, 2006  Dr Dave, developer of the must-have spam prevention tool, Spam Karma, sent out the following alert message to all Spam Karma users as an announcement in the Spam Karma administration panel: MAJOR SECURITY ANNOUNCEMENT Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable &#8216;guest user registration&#8217; on your blog if it&#8217;s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke. [...]</description>
		<content:encoded><![CDATA[<p>[...] Security Alert!   Filed under: General Info, Tips &amp; Tricks by Maria on July 26, 2006  Dr Dave, developer of the must-have spam prevention tool, Spam Karma, sent out the following alert message to all Spam Karma users as an announcement in the Spam Karma administration panel: MAJOR SECURITY ANNOUNCEMENT Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable &#8216;guest user registration&#8217; on your blog if it&#8217;s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: http://localhost</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-86657</link>
		<dc:creator>http://localhost</dc:creator>
		<pubDate>Wed, 10 Mar 2010 22:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-86657</guid>
		<description>&lt;strong&gt;facilitating hack a vulnerability ?&lt;/strong&gt;

Ok.. So finally Kim did post about my exploit&#8230;. (our communication on the subject has been via email so far). I&#8217;m not too sure if it should be termed a &#8220;hack&#8221; though, just because if the intention was to hack, I could have very ...</description>
		<content:encoded><![CDATA[<p><strong>facilitating hack a vulnerability ?</strong></p>
<p>Ok.. So finally Kim did post about my exploit&#8230;. (our communication on the subject has been via email so far). I&#8217;m not too sure if it should be termed a &#8220;hack&#8221; though, just because if the intention was to hack, I could have very &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kim Cameron&#8217;s Identity Weblog &#187; Wordpress vulnerability at identityblog</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-86380</link>
		<dc:creator>Kim Cameron&#8217;s Identity Weblog &#187; Wordpress vulnerability at identityblog</dc:creator>
		<pubDate>Wed, 10 Mar 2010 03:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-86380</guid>
		<description>[...] The exploit used was described about three weeks ago (July 27th, 2006) when Dr. Dave published his &#8220;Critical Announcement affecting ALL Wordpress Users.&#8221;  All in all, it was a fairly stern warning.  I would have upgraded to a newer version of Wordpress but couldn&#8217;t because I was travelling: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin &gt;&gt; options: make sure “Anyone can register” is not checked). [...]</description>
		<content:encoded><![CDATA[<p>[...] The exploit used was described about three weeks ago (July 27th, 2006) when Dr. Dave published his &#8220;Critical Announcement affecting ALL Wordpress Users.&#8221;  All in all, it was a fairly stern warning.  I would have upgraded to a newer version of Wordpress but couldn&#8217;t because I was travelling: If you are running Wordpress as your blogging platform and if you have been trusting enough to leave User registration enabled for guests, DISABLE IT IMMEDIATELY (in wp-admin &gt;&gt; options: make sure “Anyone can register” is not checked). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Blog That Boredom Built</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-84987</link>
		<dc:creator>The Blog That Boredom Built</dc:creator>
		<pubDate>Wed, 10 Mar 2010 12:35:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-84987</guid>
		<description>[...] Just passing along some news about WordPress: Critical Announcement to All WordPress Users. I think it only affects users who have open user registration activated. I don&#8217;t. Anyway, check it out. [...]</description>
		<content:encoded><![CDATA[<p>[...] Just passing along some news about WordPress: Critical Announcement to All WordPress Users. I think it only affects users who have open user registration activated. I don&#8217;t. Anyway, check it out. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Project Syndicate &#187; Blog Archive &#187; Lockdown Friday</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-83286</link>
		<dc:creator>Project Syndicate &#187; Blog Archive &#187; Lockdown Friday</dc:creator>
		<pubDate>Wed, 10 Mar 2010 14:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-83286</guid>
		<description>[...] I&#8217;ve been noodling around with the idea of a Free For All Friday on Slacker Manager, just to see what would show up. I was gonna do it tomorrow, but then I noticed that maybe it&#8217;s not such a good idea. Guess we&#8217;ll stay on lockdown around here for now. You can still comment, though. [...]</description>
		<content:encoded><![CDATA[<p>[...] I&#8217;ve been noodling around with the idea of a Free For All Friday on Slacker Manager, just to see what would show up. I was gonna do it tomorrow, but then I noticed that maybe it&#8217;s not such a good idea. Guess we&#8217;ll stay on lockdown around here for now. You can still comment, though. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Xen Blog &#187; Blog Archive &#187; Wordpress Vulnerability</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-82036</link>
		<dc:creator>Xen Blog &#187; Blog Archive &#187; Wordpress Vulnerability</dc:creator>
		<pubDate>Wed, 10 Mar 2010 02:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-82036</guid>
		<description>[...] Critical Announcement affecting ALL Wordpress users [...]</description>
		<content:encoded><![CDATA[<p>[...] Critical Announcement affecting ALL Wordpress users [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Залата на Планинския Крал</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-80928</link>
		<dc:creator>Залата на Планинския Крал</dc:creator>
		<pubDate>Wed, 10 Mar 2010 07:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-80928</guid>
		<description>[...] Източник
Малко повече информация по въпроса [...]</description>
		<content:encoded><![CDATA[<p>[...] Източник<br />
Малко повече информация по въпроса [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wolfgang.lonien.de &#187; Blog Archive &#187; Wordpress vulnerability?</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-80633</link>
		<dc:creator>wolfgang.lonien.de &#187; Blog Archive &#187; Wordpress vulnerability?</dc:creator>
		<pubDate>Wed, 10 Mar 2010 12:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-80633</guid>
		<description>[...] There could be a vulnerability in Wordpress. First I read about it here (via Planet Debian), then on the OP (original poster)&#8217;s blog. [...]</description>
		<content:encoded><![CDATA[<p>[...] There could be a vulnerability in Wordpress. First I read about it here (via Planet Debian), then on the OP (original poster)&#8217;s blog. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: INSIDE PCIJ &#187; Blog advisory</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-80497</link>
		<dc:creator>INSIDE PCIJ &#187; Blog advisory</dc:creator>
		<pubDate>Wed, 10 Mar 2010 05:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-80497</guid>
		<description>[...] WE have reactivated user registration after upgrading to WordPress version 2.0.4 last week. We had to temporarily disable the feature after Dr. Dave, Spam Karma creator, alerted bloggers using WordPress to a potential security issue. The recent upgrade has patched this bug. [...]</description>
		<content:encoded><![CDATA[<p>[...] WE have reactivated user registration after upgrading to WordPress version 2.0.4 last week. We had to temporarily disable the feature after Dr. Dave, Spam Karma creator, alerted bloggers using WordPress to a potential security issue. The recent upgrade has patched this bug. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: [zu frueh] pensioniert &#187; Kritische Sicherheitsl&#252;cke bei Wordpress</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-80078</link>
		<dc:creator>[zu frueh] pensioniert &#187; Kritische Sicherheitsl&#252;cke bei Wordpress</dc:creator>
		<pubDate>Wed, 10 Mar 2010 17:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-80078</guid>
		<description>[...] Worum es sich genau handelt will der Entdecker der L&#252;cke mit dem Pseudonym &#8220;Dr Dave&#8221; noch nicht verraten, allerdings gibt er zumindest einen Hinweis: Wer nicht gleich aktualisieren kann, sollte zumindest f&#252;rs Erste die Benutzerregistrierung f&#252;r G&#228;stInnen deaktivieren. [...]</description>
		<content:encoded><![CDATA[<p>[...] Worum es sich genau handelt will der Entdecker der L&uuml;cke mit dem Pseudonym &#8220;Dr Dave&#8221; noch nicht verraten, allerdings gibt er zumindest einen Hinweis: Wer nicht gleich aktualisieren kann, sollte zumindest f&uuml;rs Erste die Benutzerregistrierung f&uuml;r G&auml;stInnen deaktivieren. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dry the Rain &#187; Blog Archive &#187; Wordpress Security Flaw?</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79986</link>
		<dc:creator>Dry the Rain &#187; Blog Archive &#187; Wordpress Security Flaw?</dc:creator>
		<pubDate>Wed, 10 Mar 2010 12:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79986</guid>
		<description>[...] Allegedly there is some kind of problem with open registration on Wordpress blogs. Better safe than sorry - make sure you&#8217;ve turned off the anyone can register option. [...]</description>
		<content:encoded><![CDATA[<p>[...] Allegedly there is some kind of problem with open registration on Wordpress blogs. Better safe than sorry &#8211; make sure you&#8217;ve turned off the anyone can register option. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: p e k o l a . n e t &#187; SPAM-hyÃ¶kkÃ¤ys</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79966</link>
		<dc:creator>p e k o l a . n e t &#187; SPAM-hyÃ¶kkÃ¤ys</dc:creator>
		<pubDate>Wed, 10 Mar 2010 10:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79966</guid>
		<description>[...] Pekola.net toimii Wordpress julkaisualustalla ja WordpressistÃ¤ lÃ¶ytyy Akismet spam-suodin, joka poistaa automaattisesti kaikki spam-kommentit ja -viitteet. KÃ¤vin Ã¤sken katsomassa filtterin aikaansaannoksia ja tÃ¤nÃ¤ aamuna Akismet on poistanut satoja kommentteja eli aika massiivinen hyÃ¶kkÃ¤ys. Spam-kommenttien sisÃ¤ltÃ¶ on samaa roskaa, kuin spam-emailienkin eli online kasino-, viagra- ja muita mainoksia. Kai noihin joku aina haksahtaa, koska eihÃ¤n spammin lÃ¤hettÃ¤minen muuten kannattaisi. PÃ¤ivitin pari pÃ¤ivÃ¤Ã¤ sitten Wordpressin uusimpaan 2.0.4 versioon ja tuo pÃ¤ivitys kannattaa kaikkien Wp:n kÃ¤yttÃ¤jien tehdÃ¤ tietoturva-aukon vuoksi. [...]</description>
		<content:encoded><![CDATA[<p>[...] Pekola.net toimii Wordpress julkaisualustalla ja WordpressistÃ¤ lÃ¶ytyy Akismet spam-suodin, joka poistaa automaattisesti kaikki spam-kommentit ja -viitteet. KÃ¤vin Ã¤sken katsomassa filtterin aikaansaannoksia ja tÃ¤nÃ¤ aamuna Akismet on poistanut satoja kommentteja eli aika massiivinen hyÃ¶kkÃ¤ys. Spam-kommenttien sisÃ¤ltÃ¶ on samaa roskaa, kuin spam-emailienkin eli online kasino-, viagra- ja muita mainoksia. Kai noihin joku aina haksahtaa, koska eihÃ¤n spammin lÃ¤hettÃ¤minen muuten kannattaisi. PÃ¤ivitin pari pÃ¤ivÃ¤Ã¤ sitten Wordpressin uusimpaan 2.0.4 versioon ja tuo pÃ¤ivitys kannattaa kaikkien Wp:n kÃ¤yttÃ¤jien tehdÃ¤ tietoturva-aukon vuoksi. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rarmknecht.com &#8250; Having Some Fun</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79600</link>
		<dc:creator>rarmknecht.com &#8250; Having Some Fun</dc:creator>
		<pubDate>Wed, 10 Mar 2010 04:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79600</guid>
		<description>[...] Updated to the latest Wordpress (v2.0.4) to take care of some security issues and various other bugs. I figured that with the update of code I&#8217;d try to freshen up the site with a new theme. Being me, it doesn&#8217;t work completely proper with the initial install and is going to require some tweeking. I&#8217;ll be working on that over the next couple days. Also, IE7 Beta3 likes to throwup when trying to connect to the site claiming there&#8217;s a DNS error even though Firefox works just fine.  Yay beta! [...]</description>
		<content:encoded><![CDATA[<p>[...] Updated to the latest Wordpress (v2.0.4) to take care of some security issues and various other bugs. I figured that with the update of code I&#8217;d try to freshen up the site with a new theme. Being me, it doesn&#8217;t work completely proper with the initial install and is going to require some tweeking. I&#8217;ll be working on that over the next couple days. Also, IE7 Beta3 likes to throwup when trying to connect to the site claiming there&#8217;s a DNS error even though Firefox works just fine.  Yay beta! [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress 2.0.4 Released &#124; My Webmaster Experience</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79593</link>
		<dc:creator>WordPress 2.0.4 Released &#124; My Webmaster Experience</dc:creator>
		<pubDate>Wed, 10 Mar 2010 03:44:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79593</guid>
		<description>[...] WordPress 2.0.4, the latest stable release their series, is available for download. This release contains several important security fixes, including the unspecified security issue from Dr. Dave of Spam Karma. [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress 2.0.4, the latest stable release their series, is available for download. This release contains several important security fixes, including the unspecified security issue from Dr. Dave of Spam Karma. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: De IT y cosas peores &#187; Registro de usuarios deshabilitado</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79502</link>
		<dc:creator>De IT y cosas peores &#187; Registro de usuarios deshabilitado</dc:creator>
		<pubDate>Wed, 10 Mar 2010 19:03:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79502</guid>
		<description>[...] Se ha deshabilitado temporalmente el registro de usuarios nuevos, hasta que se actualize la instalación de Wordpress. Esto debido a un bug en versiones anteriores del propio Wordpress. [...]</description>
		<content:encoded><![CDATA[<p>[...] Se ha deshabilitado temporalmente el registro de usuarios nuevos, hasta que se actualize la instalación de Wordpress. Esto debido a un bug en versiones anteriores del propio Wordpress. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Das Voynich-Blog &#187; Blog Archiv &#187; Registrierung momentan nicht mÃ¶glich</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79479</link>
		<dc:creator>Das Voynich-Blog &#187; Blog Archiv &#187; Registrierung momentan nicht mÃ¶glich</dc:creator>
		<pubDate>Wed, 10 Mar 2010 17:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79479</guid>
		<description>[...] Wegen eines kritischen Sicherheitsproblems mit der hier verwendeten Blogsoftware habe ich die M&#246;glichkeit zur offenen Registrierung vorr&#252;bergehend abgeschaltet. Da ich im Moment aus verschiedenen Gr&#252;nden nicht dazu komme, eine neue Version der Software auf dem Server hochzuladen, kann dieser Zustand noch einige Tage bestehen bleiben. Ich werde hier eine kurze Meldung geben, wenn die Registrierung wieder offen ist. [...]</description>
		<content:encoded><![CDATA[<p>[...] Wegen eines kritischen Sicherheitsproblems mit der hier verwendeten Blogsoftware habe ich die M&#246;glichkeit zur offenen Registrierung vorr&#252;bergehend abgeschaltet. Da ich im Moment aus verschiedenen Gr&#252;nden nicht dazu komme, eine neue Version der Software auf dem Server hochzuladen, kann dieser Zustand noch einige Tage bestehen bleiben. Ich werde hier eine kurze Meldung geben, wenn die Registrierung wieder offen ist. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Valwit&#8217;s &#187; Blog Archive &#187; Huh?!</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79464</link>
		<dc:creator>Valwit&#8217;s &#187; Blog Archive &#187; Huh?!</dc:creator>
		<pubDate>Wed, 10 Mar 2010 15:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79464</guid>
		<description>[...] Najwyrazniej jakis paskudny bug w&#160;kodzie: http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/ Nawet nie uzywajac trzeba uwazac. Skandal. [...]</description>
		<content:encoded><![CDATA[<p>[...] Najwyrazniej jakis paskudny bug w&nbsp;kodzie: <a href="http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/" rel="nofollow">http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/</a> Nawet nie uzywajac trzeba uwazac. Skandal. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blog.babytux.de &#187; Wordpress 2.0.4</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79430</link>
		<dc:creator>blog.babytux.de &#187; Wordpress 2.0.4</dc:creator>
		<pubDate>Wed, 10 Mar 2010 12:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79430</guid>
		<description>[...] Technikecke     Tags: Blog, WordpressSchon am 29. Juli veröffentlichte das Wordpress-Team eine neue Version der Blog-Software. Heute findet sich dies auch auf Heise als Newsmeldung wieder. Grund dafür ist, daß mit der aktuellen Version auch ein kritisches Sicherheitsloch behoben worden sein soll: Angreifer könnten sich durch die Lücke in verwundbare Systeme hacken, weitere Details sind bislang jedoch nicht bekannt. Vergangene Woche warnte der ehemalige WordPress-Entwickler mit dem Pseudonym &#8220;Dr Dave&#8221; in seinem Blog vor der Schwachstelle und riet WordPress-Nutzern, die Benutzerregistrierung für Gäste zu deaktivieren. Allerdings gibt auch er keine Details zu dem Fehler bekannt, nicht einmal in einem F.A.Q. zu seiner Warnung. Auf eine Anfrage von heise Security bezüglich des Fehlers antwortete der Hauptentwickler Matt Mullenweg bislang nicht. Quelle: Heise Online [...]</description>
		<content:encoded><![CDATA[<p>[...] Technikecke     Tags: Blog, WordpressSchon am 29. Juli veröffentlichte das Wordpress-Team eine neue Version der Blog-Software. Heute findet sich dies auch auf Heise als Newsmeldung wieder. Grund dafür ist, daß mit der aktuellen Version auch ein kritisches Sicherheitsloch behoben worden sein soll: Angreifer könnten sich durch die Lücke in verwundbare Systeme hacken, weitere Details sind bislang jedoch nicht bekannt. Vergangene Woche warnte der ehemalige WordPress-Entwickler mit dem Pseudonym &#8220;Dr Dave&#8221; in seinem Blog vor der Schwachstelle und riet WordPress-Nutzern, die Benutzerregistrierung für Gäste zu deaktivieren. Allerdings gibt auch er keine Details zu dem Fehler bekannt, nicht einmal in einem F.A.Q. zu seiner Warnung. Auf eine Anfrage von heise Security bezüglich des Fehlers antwortete der Hauptentwickler Matt Mullenweg bislang nicht. Quelle: Heise Online [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress se actualiza a 2.0.4 at blooG</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-79225</link>
		<dc:creator>Wordpress se actualiza a 2.0.4 at blooG</dc:creator>
		<pubDate>Wed, 10 Mar 2010 18:03:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-79225</guid>
		<description>[...] Una nueva versiÃ³n de Wordpress ha salido para poder ser descargada, en esta versiÃ³n se corrigen mÃ¡s de 50 bugs de la versiÃ³n anterior, incluyendo un grave problema de seguridad anunciado hace pocos dÃ­as. [...]</description>
		<content:encoded><![CDATA[<p>[...] Una nueva versiÃ³n de Wordpress ha salido para poder ser descargada, en esta versiÃ³n se corrigen mÃ¡s de 50 bugs de la versiÃ³n anterior, incluyendo un grave problema de seguridad anunciado hace pocos dÃ­as. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dead Reckoning &#187; Archive &#187; WordPress Announcements</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-78831</link>
		<dc:creator>Dead Reckoning &#187; Archive &#187; WordPress Announcements</dc:creator>
		<pubDate>Wed, 10 Mar 2010 21:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-78831</guid>
		<description>[...] Here&#8217;s the deal: unless you are currently running version 2.0.4 it is recommended that you take the following action without delay: [...]</description>
		<content:encoded><![CDATA[<p>[...] Here&#8217;s the deal: unless you are currently running version 2.0.4 it is recommended that you take the following action without delay: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dr Dave</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-78758</link>
		<dc:creator>dr Dave</dc:creator>
		<pubDate>Wed, 10 Mar 2010 15:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-78758</guid>
		<description>&lt;strong&gt;Update on the security flaw&lt;/strong&gt;

The exploit has been, &lt;em&gt;as far as I can tell&lt;/em&gt;(*), fixed by the latest 2.0.4 release. You are therefore strongly recommended to (read: you MUST) upgrade to this version.

As for the &quot;users can register&quot; option: enabling it back should be OK. 
I personally will leave it off on my blogs, as I just don&#039;t feel like entrusting strangers with access to wp-admin in the current state of the code (I insist that the aforementioned exploit &lt;em&gt;has been&lt;/em&gt; fixed now, I am only being paranoid here).

(*) Note that this is only my own very superficial testing of the code released: in no way the word of any official developer. You should all be aware that I have barely any more official knowledge of this than you do, considering Matt&#039;s fondness for the stealth&amp;ignore school of crisis management (basically, if i doesn&#039;t make it on Slashdot, you can bet you&#039;ll never read about it on his blog). As you may have noticed, he has been marvellously low-key about the whole thing (you know, don&#039;t want &lt;s&gt;investors&lt;/s&gt; users to &quot;panic&quot; or, god forbid, start suspecting that WP might sometimes have security flaws in it). It also bears pointing out that he has neither contacted me nor replied to my emails in any way other than  posting his very helpful comment above. 

And just to definitely close that chapter of WP&#039;s Incredible Security Adventures by saying I have no regrets whatsoever about releasing this warning, given the way it was otherwise handled by WP officials: 1) deny 2) minimize 3) somewhat acknowledge 4) keep shut 5) release an upgrade that likely won&#039;t be installed by more than 50% of the general public with for only communication a tiny confusing &quot;upgrade announcement&quot; message in the dashboard feed, wedged between two inconsequential WP marketoid news.</description>
		<content:encoded><![CDATA[<p><strong>Update on the security flaw</strong></p>
<p>The exploit has been, <em>as far as I can tell</em>(*), fixed by the latest 2.0.4 release. You are therefore strongly recommended to (read: you MUST) upgrade to this version.</p>
<p>As for the &#8220;users can register&#8221; option: enabling it back should be OK.<br />
I personally will leave it off on my blogs, as I just don&#8217;t feel like entrusting strangers with access to wp-admin in the current state of the code (I insist that the aforementioned exploit <em>has been</em> fixed now, I am only being paranoid here).</p>
<p>(*) Note that this is only my own very superficial testing of the code released: in no way the word of any official developer. You should all be aware that I have barely any more official knowledge of this than you do, considering Matt&#8217;s fondness for the stealth&amp;ignore school of crisis management (basically, if i doesn&#8217;t make it on Slashdot, you can bet you&#8217;ll never read about it on his blog). As you may have noticed, he has been marvellously low-key about the whole thing (you know, don&#8217;t want <s>investors</s> users to &#8220;panic&#8221; or, god forbid, start suspecting that WP might sometimes have security flaws in it). It also bears pointing out that he has neither contacted me nor replied to my emails in any way other than  posting his very helpful comment above. </p>
<p>And just to definitely close that chapter of WP&#8217;s Incredible Security Adventures by saying I have no regrets whatsoever about releasing this warning, given the way it was otherwise handled by WP officials: 1) deny 2) minimize 3) somewhat acknowledge 4) keep shut 5) release an upgrade that likely won&#8217;t be installed by more than 50% of the general public with for only communication a tiny confusing &#8220;upgrade announcement&#8221; message in the dashboard feed, wedged between two inconsequential WP marketoid news.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: T. Longren &#187; WordPress 2.0.4 Released</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/26/critical-announcement-to-all-wordpress-users/comment-page-3/#comment-78755</link>
		<dc:creator>T. Longren &#187; WordPress 2.0.4 Released</dc:creator>
		<pubDate>Wed, 10 Mar 2010 15:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1413#comment-78755</guid>
		<description>[...] I can&#8217;t find any documentation stating the user registration vulnerability has been fixed, but Kelson is reporting it has been taken care of in WordPress 2.0.4. I believe this WordPress release was pushed out quickly due to some information revealed by Dr. Dave earlier in the week. [...]</description>
		<content:encoded><![CDATA[<p>[...] I can&#8217;t find any documentation stating the user registration vulnerability has been fixed, but Kelson is reporting it has been taken care of in WordPress 2.0.4. I believe this WordPress release was pushed out quickly due to some information revealed by Dr. Dave earlier in the week. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
