<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Followup on Wordpress Security Issue</title>
	<atom:link href="http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/</link>
	<description>Chemically-enhanced neural rewiring, on a semi-regular basis...</description>
	<lastBuildDate>Tue, 16 Mar 2010 14:26:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: http://localhost</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-86658</link>
		<dc:creator>http://localhost</dc:creator>
		<pubDate>Tue, 16 Mar 2010 22:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-86658</guid>
		<description>&lt;strong&gt;facilitating hack a vulnerability ?&lt;/strong&gt;

Ok.. So finally Kim did post about my exploit&#8230;. (our communication on the subject has been via email so far). I&#8217;m not too sure if it should be termed a &#8220;hack&#8221; though, just because if the intention was to hack, I could have very ...</description>
		<content:encoded><![CDATA[<p><strong>facilitating hack a vulnerability ?</strong></p>
<p>Ok.. So finally Kim did post about my exploit&#8230;. (our communication on the subject has been via email so far). I&#8217;m not too sure if it should be termed a &#8220;hack&#8221; though, just because if the intention was to hack, I could have very &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blog.babytux.de &#187; Wordpress 2.0.4</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-82593</link>
		<dc:creator>blog.babytux.de &#187; Wordpress 2.0.4</dc:creator>
		<pubDate>Tue, 16 Mar 2010 14:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-82593</guid>
		<description>[...] Technikecke, Wordpress     Tags: Blog, WordpressSchon am 29. Juli veröffentlichte das Wordpress-Team eine neue Version der Blog-Software. Heute findet sich dies auch auf Heise als Newsmeldung wieder. Grund dafür ist, daß mit der aktuellen Version auch ein kritisches Sicherheitsloch behoben worden sein soll: Angreifer könnten sich durch die Lücke in verwundbare Systeme hacken, weitere Details sind bislang jedoch nicht bekannt. Vergangene Woche warnte der ehemalige WordPress-Entwickler mit dem Pseudonym &#8220;Dr Dave&#8221; in seinem Blog vor der Schwachstelle und riet WordPress-Nutzern, die Benutzerregistrierung für Gäste zu deaktivieren. Allerdings gibt auch er keine Details zu dem Fehler bekannt, nicht einmal in einem F.A.Q. zu seiner Warnung. Auf eine Anfrage von heise Security bezüglich des Fehlers antwortete der Hauptentwickler Matt Mullenweg bislang nicht. Quelle: Heise Online [...]</description>
		<content:encoded><![CDATA[<p>[...] Technikecke, Wordpress     Tags: Blog, WordpressSchon am 29. Juli veröffentlichte das Wordpress-Team eine neue Version der Blog-Software. Heute findet sich dies auch auf Heise als Newsmeldung wieder. Grund dafür ist, daß mit der aktuellen Version auch ein kritisches Sicherheitsloch behoben worden sein soll: Angreifer könnten sich durch die Lücke in verwundbare Systeme hacken, weitere Details sind bislang jedoch nicht bekannt. Vergangene Woche warnte der ehemalige WordPress-Entwickler mit dem Pseudonym &#8220;Dr Dave&#8221; in seinem Blog vor der Schwachstelle und riet WordPress-Nutzern, die Benutzerregistrierung für Gäste zu deaktivieren. Allerdings gibt auch er keine Details zu dem Fehler bekannt, nicht einmal in einem F.A.Q. zu seiner Warnung. Auf eine Anfrage von heise Security bezüglich des Fehlers antwortete der Hauptentwickler Matt Mullenweg bislang nicht. Quelle: Heise Online [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hosting Lmi - Alojamiento web &#187; Bug cr</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79652</link>
		<dc:creator>Hosting Lmi - Alojamiento web &#187; Bug cr</dc:creator>
		<pubDate>Tue, 16 Mar 2010 09:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79652</guid>
		<description>[...] Dr Dave Foolowup on WordPress Security Issue [...]</description>
		<content:encoded><![CDATA[<p>[...] Dr Dave Foolowup on WordPress Security Issue [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Actualiza tu WordPress de forma urgente - Fernando Gomez</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79556</link>
		<dc:creator>Actualiza tu WordPress de forma urgente - Fernando Gomez</dc:creator>
		<pubDate>Tue, 16 Mar 2010 00:12:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79556</guid>
		<description>[...] Su utilizasÂ WordPress, te vendrÃ­a bien saber que ya estÃ¡ disponible la WordPress 2.0.4 y es que se han encontrado mÃ¡s de 50 bugs, pero sobre todo uno de ellos parece ser terriblemente crÃ­tico. Tanto que sus autores no han querido desvelar exactamente de que se trata, pero instan a correr la voz y a que actualices de forma urgente tu Blog. [...]</description>
		<content:encoded><![CDATA[<p>[...] Su utilizasÂ WordPress, te vendrÃ­a bien saber que ya estÃ¡ disponible la WordPress 2.0.4 y es que se han encontrado mÃ¡s de 50 bugs, pero sobre todo uno de ellos parece ser terriblemente crÃ­tico. Tanto que sus autores no han querido desvelar exactamente de que se trata, pero instan a correr la voz y a que actualices de forma urgente tu Blog. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Squio.blog &#187; Wordpress 2.0.4 security update</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79475</link>
		<dc:creator>Squio.blog &#187; Wordpress 2.0.4 security update</dc:creator>
		<pubDate>Tue, 16 Mar 2010 16:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79475</guid>
		<description>[...] Speaking of which, the discussion around security issues always seems to trigger some hefty debates. Whether to reveal every problem immediately, or to keep it under the hood until a solution exists, or even don&#8217;t mention security at all, just make the fixed version available with some vague improvement promises. Well, read this one for yourself here: Dr Dave Â» Followup on Wordpress Security Issue. [...]</description>
		<content:encoded><![CDATA[<p>[...] Speaking of which, the discussion around security issues always seems to trigger some hefty debates. Whether to reveal every problem immediately, or to keep it under the hood until a solution exists, or even don&#8217;t mention security at all, just make the fixed version available with some vague improvement promises. Well, read this one for yourself here: Dr Dave Â» Followup on Wordpress Security Issue. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kutitots &#187; Blog Archive &#187; WP version 2.0.4 released</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79440</link>
		<dc:creator>Kutitots &#187; Blog Archive &#187; WP version 2.0.4 released</dc:creator>
		<pubDate>Tue, 16 Mar 2010 13:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79440</guid>
		<description>[...] For WP users who don&#8217;t read the WP announcements on their Dashboards (or have customized their admin home page entirely like I did for SheeroMedia), you might want to head over the WordPress download section for an update. I don&#8217;t normally blog about things like this, but Dr. Dave&#8217;s blog post about it made me a bit concerned.    Kutitots, Kutitots.Com &#169; 2004-2006 by Gail Dela Cruz. All rights reserved. HAVE SOME SHAME.Don&#039;t copy my flea and layout.  Looking for something in particular? [...]</description>
		<content:encoded><![CDATA[<p>[...] For WP users who don&#8217;t read the WP announcements on their Dashboards (or have customized their admin home page entirely like I did for SheeroMedia), you might want to head over the WordPress download section for an update. I don&#8217;t normally blog about things like this, but Dr. Dave&#8217;s blog post about it made me a bit concerned.    Kutitots, Kutitots.Com &copy; 2004-2006 by Gail Dela Cruz. All rights reserved. HAVE SOME SHAME.Don&#8217;t copy my flea and layout.  Looking for something in particular? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blogging reloaded &#187; Wordpress 2.0.4</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79439</link>
		<dc:creator>Blogging reloaded &#187; Wordpress 2.0.4</dc:creator>
		<pubDate>Tue, 16 Mar 2010 13:53:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79439</guid>
		<description>[...] Followup on Wordpress Security Issue [...]</description>
		<content:encoded><![CDATA[<p>[...] Followup on Wordpress Security Issue [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rootsvr.de Blog</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79434</link>
		<dc:creator>rootsvr.de Blog</dc:creator>
		<pubDate>Tue, 16 Mar 2010 13:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79434</guid>
		<description>&lt;strong&gt;Wordpress Update auf 2.0.4 Sicherheitsfix&lt;/strong&gt;

Bei der beliebten Blogsoftware Wordpress gibt es mit der Version 2.0.4 diverse kritische LÃ¼cken gestopft und insgesamt 50 Bugs behoben. Das Update sollte so schnell wie mÃ¶glich eingespielt werden.

...</description>
		<content:encoded><![CDATA[<p><strong>Wordpress Update auf 2.0.4 Sicherheitsfix</strong></p>
<p>Bei der beliebten Blogsoftware Wordpress gibt es mit der Version 2.0.4 diverse kritische LÃ¼cken gestopft und insgesamt 50 Bugs behoben. Das Update sollte so schnell wie mÃ¶glich eingespielt werden.</p>
<p>&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rootsvr.de Blog &#187; Blog Archiv &#187; Wordpress Update auf 2.0.4 Sicherheitsfix</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79433</link>
		<dc:creator>rootsvr.de Blog &#187; Blog Archiv &#187; Wordpress Update auf 2.0.4 Sicherheitsfix</dc:creator>
		<pubDate>Tue, 16 Mar 2010 13:21:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79433</guid>
		<description>[...] Wordpress schliesst mit dem Update auf 2.0.4 diverse SicherheitslÃ¼cken. Dr Dave hat in seinem Blog auf die SicherheitslÃ¼cken aufmerksam gemacht, als workaround sollte man GÃ¤sten das registrieren verbieten, besser aber 2.0.4 installieren: runterladen, drÃ¼berkopieren - fertig! [...]</description>
		<content:encoded><![CDATA[<p>[...] Wordpress schliesst mit dem Update auf 2.0.4 diverse SicherheitslÃ¼cken. Dr Dave hat in seinem Blog auf die SicherheitslÃ¼cken aufmerksam gemacht, als workaround sollte man GÃ¤sten das registrieren verbieten, besser aber 2.0.4 installieren: runterladen, drÃ¼berkopieren &#8211; fertig! [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79422</link>
		<dc:creator>Will</dc:creator>
		<pubDate>Tue, 16 Mar 2010 11:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79422</guid>
		<description>Well, here are all the changes between WP 2.0.3 and WP 2.0.4:

http://trac.wordpress.org/log/branches/2.0?action=stop_on_copy&amp;rev=4066&amp;stop_rev=3826&amp;mode=stop_on_copy

Does NOT include the security fix though does it? I would guess no way!! ???</description>
		<content:encoded><![CDATA[<p>Well, here are all the changes between WP 2.0.3 and WP 2.0.4:</p>
<p><a href="http://trac.wordpress.org/log/branches/2.0?action=stop_on_copy&amp;rev=4066&amp;stop_rev=3826&amp;mode=stop_on_copy" rel="nofollow">http://trac.wordpress.org/log/branches/2.0?action=stop_on_copy&amp;rev=4066&amp;stop_rev=3826&amp;mode=stop_on_copy</a></p>
<p>Does NOT include the security fix though does it? I would guess no way!! ???</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress Registration Vulnerability an Injection Attack? at FEWL.NET</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79274</link>
		<dc:creator>Wordpress Registration Vulnerability an Injection Attack? at FEWL.NET</dc:creator>
		<pubDate>Tue, 16 Mar 2010 21:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79274</guid>
		<description>[...] This might be a slight follow up to Dr. Dave&#8217;s Followup on Wordpress Security Issue. I just woke up after a long flight from Virginia to Tokyo and got to this link via Jem&#8217;s site. Details on the vulnerability are sketchy so I thought I&#8217;d take a look for myself. The followup post said that the issue is corrected with the Wordpress 2.0.4 upgrade. So I downloaded the newest version and compared it to my current install. I haven&#8217;t been looking long, but here&#8217;s what I found so far. [...]</description>
		<content:encoded><![CDATA[<p>[...] This might be a slight follow up to Dr. Dave&#8217;s Followup on Wordpress Security Issue. I just woke up after a long flight from Virginia to Tokyo and got to this link via Jem&#8217;s site. Details on the vulnerability are sketchy so I thought I&#8217;d take a look for myself. The followup post said that the issue is corrected with the Wordpress 2.0.4 upgrade. So I downloaded the newest version and compared it to my current install. I haven&#8217;t been looking long, but here&#8217;s what I found so far. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scaturan</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79196</link>
		<dc:creator>scaturan</dc:creator>
		<pubDate>Tue, 16 Mar 2010 15:30:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79196</guid>
		<description>thanks Dave!</description>
		<content:encoded><![CDATA[<p>thanks Dave!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Webrocker &#187; Upgrade auf WP 2.0.4</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-79119</link>
		<dc:creator>Webrocker &#187; Upgrade auf WP 2.0.4</dc:creator>
		<pubDate>Tue, 16 Mar 2010 10:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-79119</guid>
		<description>[...] halten, was die Kommentare angeht. Man kann aber auch selbst einen Kommentar verfassen, oder ein Trackback von der eigenen Seite ausmachen. [...]</description>
		<content:encoded><![CDATA[<p>[...] halten, was die Kommentare angeht. Man kann aber auch selbst einen Kommentar verfassen, oder ein Trackback von der eigenen Seite ausmachen. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dead Reckoning &#187; Archive &#187; WordPress Announcements</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78832</link>
		<dc:creator>Dead Reckoning &#187; Archive &#187; WordPress Announcements</dc:creator>
		<pubDate>Tue, 16 Mar 2010 21:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78832</guid>
		<description>[...] This advice comes courtesy of Dr. Dave. He has posted a detailed follow-up to his initial warning which may also be of interest. [...]</description>
		<content:encoded><![CDATA[<p>[...] This advice comes courtesy of Dr. Dave. He has posted a detailed follow-up to his initial warning which may also be of interest. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dr Dave</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78763</link>
		<dc:creator>dr Dave</dc:creator>
		<pubDate>Tue, 16 Mar 2010 15:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78763</guid>
		<description>Regarding people still running 1.5:

Trust me, I am the first one annoyed by this (considering how some of my blogs still happily run 1.5 with little will to upgrade), but it is now time to seriously consider upgrading. 

I wished there was a better way, especially considering WP 2.0 comes with its own bunch of issues, bugs and security issues, but it will become increasingly tedious to keep up with all the security fixes and provides 1.5-compatible patches for them. Chiefly thanks to the aforementioned level of transparency and communication around these flaws: it takes skills worthy of a 70&#039;s Eastern European spy to manage and extort clear information from the Powers That Be on every single security flaw that may affect each version of Wordpress.

I for one, will keep user reg disabled on my 1.5 blogs, quickly tweak the most critical bits and look into upgrading to an easier-to-maintain platform (be it WP or other) soon enough. I advise you do the same or your life will be a kafkaesque hell of muddy bug report decrypting and patch maintenance.</description>
		<content:encoded><![CDATA[<p>Regarding people still running 1.5:</p>
<p>Trust me, I am the first one annoyed by this (considering how some of my blogs still happily run 1.5 with little will to upgrade), but it is now time to seriously consider upgrading. </p>
<p>I wished there was a better way, especially considering WP 2.0 comes with its own bunch of issues, bugs and security issues, but it will become increasingly tedious to keep up with all the security fixes and provides 1.5-compatible patches for them. Chiefly thanks to the aforementioned level of transparency and communication around these flaws: it takes skills worthy of a 70&#8217;s Eastern European spy to manage and extort clear information from the Powers That Be on every single security flaw that may affect each version of Wordpress.</p>
<p>I for one, will keep user reg disabled on my 1.5 blogs, quickly tweak the most critical bits and look into upgrading to an easier-to-maintain platform (be it WP or other) soon enough. I advise you do the same or your life will be a kafkaesque hell of muddy bug report decrypting and patch maintenance.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: T. Longren &#187; WordPress 2.0.4 Released</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78760</link>
		<dc:creator>T. Longren &#187; WordPress 2.0.4 Released</dc:creator>
		<pubDate>Tue, 16 Mar 2010 15:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78760</guid>
		<description>[...] I can&#8217;t find any documentation stating the user registration vulnerability has been fixed, but Kelson is reporting it has been taken care of in WordPress 2.0.4. I believe this WordPress release was pushed out quickly due to some information revealed by Dr. Dave earlier in the week. [...]</description>
		<content:encoded><![CDATA[<p>[...] I can&#8217;t find any documentation stating the user registration vulnerability has been fixed, but Kelson is reporting it has been taken care of in WordPress 2.0.4. I believe this WordPress release was pushed out quickly due to some information revealed by Dr. Dave earlier in the week. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dr Dave</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78759</link>
		<dc:creator>dr Dave</dc:creator>
		<pubDate>Tue, 16 Mar 2010 15:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78759</guid>
		<description>&lt;strong&gt;Update on the security flaw&lt;/strong&gt;

The exploit has been, &lt;em&gt;as far as I can tell&lt;/em&gt;(*), fixed by the latest 2.0.4 release. You are therefore strongly recommended to (read: you MUST) upgrade to this version.

As for the &quot;users can register&quot; option: enabling it back should be OK. 
I personally will leave it off on my blogs, as I just don&#039;t feel like entrusting strangers with access to wp-admin in the current state of the code (I insist that the aforementioned exploit &lt;em&gt;has been&lt;/em&gt; fixed now, I am only being paranoid here).

(*) Note that this is only my own very superficial testing of the code released: in no way the word of any official developer. You should all be aware that I have barely any more official knowledge of this than you do, considering Matt&#039;s fondness for the stealth&amp;ignore school of crisis management (basically, if i doesn&#039;t make it on Slashdot, you can bet you&#039;ll never read about it on his blog). As you may have noticed, he has been marvellously low-key about the whole thing (you know, don&#039;t want &lt;s&gt;investors&lt;/s&gt; users to &quot;panic&quot; or, god forbid, start suspecting that WP might sometimes have security flaws in it). It also bears pointing out that he has neither contacted me nor replied to my emails in any way other than  posting his very helpful comment above. 

And just to definitely close that chapter of WP&#039;s Incredible Security Adventures by saying I have no regrets whatsoever about releasing this warning, given the way it was otherwise handled by WP officials: 1) deny 2) minimize 3) somewhat acknowledge 4) keep shut 5) release an upgrade that likely won&#039;t be installed by more than 50% of the general public with for only communication a tiny confusing &quot;upgrade announcement&quot; message in the dashboard feed, wedged between two inconsequential WP marketoid news.</description>
		<content:encoded><![CDATA[<p><strong>Update on the security flaw</strong></p>
<p>The exploit has been, <em>as far as I can tell</em>(*), fixed by the latest 2.0.4 release. You are therefore strongly recommended to (read: you MUST) upgrade to this version.</p>
<p>As for the &#8220;users can register&#8221; option: enabling it back should be OK.<br />
I personally will leave it off on my blogs, as I just don&#8217;t feel like entrusting strangers with access to wp-admin in the current state of the code (I insist that the aforementioned exploit <em>has been</em> fixed now, I am only being paranoid here).</p>
<p>(*) Note that this is only my own very superficial testing of the code released: in no way the word of any official developer. You should all be aware that I have barely any more official knowledge of this than you do, considering Matt&#8217;s fondness for the stealth&amp;ignore school of crisis management (basically, if i doesn&#8217;t make it on Slashdot, you can bet you&#8217;ll never read about it on his blog). As you may have noticed, he has been marvellously low-key about the whole thing (you know, don&#8217;t want <s>investors</s> users to &#8220;panic&#8221; or, god forbid, start suspecting that WP might sometimes have security flaws in it). It also bears pointing out that he has neither contacted me nor replied to my emails in any way other than  posting his very helpful comment above. </p>
<p>And just to definitely close that chapter of WP&#8217;s Incredible Security Adventures by saying I have no regrets whatsoever about releasing this warning, given the way it was otherwise handled by WP officials: 1) deny 2) minimize 3) somewhat acknowledge 4) keep shut 5) release an upgrade that likely won&#8217;t be installed by more than 50% of the general public with for only communication a tiny confusing &#8220;upgrade announcement&#8221; message in the dashboard feed, wedged between two inconsequential WP marketoid news.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uncle Che</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78757</link>
		<dc:creator>Uncle Che</dc:creator>
		<pubDate>Tue, 16 Mar 2010 15:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78757</guid>
		<description>Yeah, inquiring minds want to know, does 2.0.4 fix the issue? I had several of my older sites still on 2.0.1 and 2.0.2 so I took the initiative today to upgrade every one of my sites to 2.0.4.</description>
		<content:encoded><![CDATA[<p>Yeah, inquiring minds want to know, does 2.0.4 fix the issue? I had several of my older sites still on 2.0.1 and 2.0.2 so I took the initiative today to upgrade every one of my sites to 2.0.4.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Soccer Dad</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78748</link>
		<dc:creator>Soccer Dad</dc:creator>
		<pubDate>Tue, 16 Mar 2010 14:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78748</guid>
		<description>If it was, I don&#039;t see it: http://trac.wordpress.org/query?status=closed&amp;milestone=2.0.4

But obviously only Dr D can say for sure. None of those security fixes seemed like a non priv user exploit. My guess is it was not since 2.0.4 was hitting beta just as Dr D sent his announcement. Just a guess.</description>
		<content:encoded><![CDATA[<p>If it was, I don&#8217;t see it: <a href="http://trac.wordpress.org/query?status=closed&amp;milestone=2.0.4" rel="nofollow">http://trac.wordpress.org/query?status=closed&amp;milestone=2.0.4</a></p>
<p>But obviously only Dr D can say for sure. None of those security fixes seemed like a non priv user exploit. My guess is it was not since 2.0.4 was hitting beta just as Dr D sent his announcement. Just a guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SicherheitslÃ¼cke in WordPress und 2.0.4 Beta Download &#8212; Software Guide</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78694</link>
		<dc:creator>SicherheitslÃ¼cke in WordPress und 2.0.4 Beta Download &#8212; Software Guide</dc:creator>
		<pubDate>Tue, 16 Mar 2010 10:54:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78694</guid>
		<description>[...] Mehr Infos gibt es im Wordpress.de-Forum, beim S-O-S SEO Blog und im Folgebeitrag von Dr. Dave. [...]</description>
		<content:encoded><![CDATA[<p>[...] Mehr Infos gibt es im Wordpress.de-Forum, beim S-O-S SEO Blog und im Folgebeitrag von Dr. Dave. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fh</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78693</link>
		<dc:creator>fh</dc:creator>
		<pubDate>Tue, 16 Mar 2010 10:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78693</guid>
		<description>Dear Dr. Dave, thanks for the announcement - but please, can you clarify if the issue has been fixed in 2.0.4?</description>
		<content:encoded><![CDATA[<p>Dear Dr. Dave, thanks for the announcement &#8211; but please, can you clarify if the issue has been fixed in 2.0.4?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blog.deobald.org &#187; Blog Archive &#187; Wordpress Security Warning</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78447</link>
		<dc:creator>blog.deobald.org &#187; Blog Archive &#187; Wordpress Security Warning</dc:creator>
		<pubDate>Tue, 16 Mar 2010 18:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78447</guid>
		<description>[...] siehe Dr. Dave (Teil 2). [...]</description>
		<content:encoded><![CDATA[<p>[...] siehe Dr. Dave (Teil 2). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IgnacioMarcos</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78405</link>
		<dc:creator>IgnacioMarcos</dc:creator>
		<pubDate>Tue, 16 Mar 2010 15:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78405</guid>
		<description>Dave, 

thanks for the advise!

Have you tried to submit this issue to SECURITYFOCUS or any other CERT? Probably that will propagate it much faster and better.

Ignacio.</description>
		<content:encoded><![CDATA[<p>Dave, </p>
<p>thanks for the advise!</p>
<p>Have you tried to submit this issue to SECURITYFOCUS or any other CERT? Probably that will propagate it much faster and better.</p>
<p>Ignacio.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: T. Longren</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78404</link>
		<dc:creator>T. Longren</dc:creator>
		<pubDate>Tue, 16 Mar 2010 15:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78404</guid>
		<description>&lt;strong&gt;WordPress Security Issue&lt;/strong&gt;

Dr. Dave, the dude behind Spam Karma, has issued a warning to all WordPress users.  A message popped up on my Spam Karma 2 dashboard warning of a potential security vulnerability in WordPress.  Here&#8217;s part of the warning:
If you are running Wordp...</description>
		<content:encoded><![CDATA[<p><strong>WordPress Security Issue</strong></p>
<p>Dr. Dave, the dude behind Spam Karma, has issued a warning to all WordPress users.  A message popped up on my Spam Karma 2 dashboard warning of a potential security vulnerability in WordPress.  Here&#8217;s part of the warning:<br />
If you are running Wordp&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MP:Blog - Mediaprojekte</title>
		<link>http://unknowngenius.com/blog/archives/2006/07/27/followup-on-wordpress/comment-page-1/#comment-78394</link>
		<dc:creator>MP:Blog - Mediaprojekte</dc:creator>
		<pubDate>Tue, 16 Mar 2010 14:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://unknowngenius.com/blog/?p=1414#comment-78394</guid>
		<description>&lt;strong&gt;Wordpress Sicherheit - User Registrieren dringend abschalten&lt;/strong&gt;

	Laut Dr. Dave und anderen kann es in allen WordPress Versionen ein Sicherheitsproblem geben, wenn Benutzern das Registrieren erlaubt ist.
	Es wird dringend empfohlen das Registrieren f&#252;r G&#228;ste abzuschalten und s&#228;mtliche unbekannte Gast-...</description>
		<content:encoded><![CDATA[<p><strong>Wordpress Sicherheit &#8211; User Registrieren dringend abschalten</strong></p>
<p>	Laut Dr. Dave und anderen kann es in allen WordPress Versionen ein Sicherheitsproblem geben, wenn Benutzern das Registrieren erlaubt ist.<br />
	Es wird dringend empfohlen das Registrieren f&uuml;r G&auml;ste abzuschalten und s&auml;mtliche unbekannte Gast-&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
