<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>archGFX &#187; security</title>
	<atom:link href="http://archgfx.net/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://archgfx.net</link>
	<description>Austin web designer - Adam Freetly</description>
	<lastBuildDate>Thu, 19 Apr 2012 18:01:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>WordPress 2.3.3 Spam Exploit</title>
		<link>http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit</link>
		<comments>http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit#comments</comments>
		<pubDate>Thu, 27 Mar 2008 16:24:56 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit</guid>
		<description><![CDATA[If you run a wordpress blog, you should be reading Blogsecurity. This is the feed I use, that only includes the wordpress advisories. I think it's a damn shame that this feed isn't included in the wordpress planet that's syndicated across everyone's dashboard. Security is far more important than wordcamp. I'm only bringing this up [...]]]></description>
			<content:encoded><![CDATA[<p>If you run a wordpress blog, you should be reading <a href="http://blogsecurity.net/">Blogsecurity</a>.  <a href="http://blogsecurity.net/category/wordpress/feed/">This is the feed I use</a>, that only includes the wordpress advisories. I think it's a damn shame that this feed isn't included in the <a href="http://planet.wordpress.org/">wordpress planet</a> that's syndicated across everyone's dashboard.  Security is far more important than wordcamp.</p>
<p>I'm only bringing this up because there's a <a href="http://smackdown.blogsblogsblogs.com/2008/03/23/new-wordpress-233-exploitvulnerability-adds-spam-directory-wp-content1/">new WordPress 2.3.3 exploit</a> that's as-yet unpatched. So far it seems to only affect blogs with open registration, but no one's yet sure what exploit is being  targetted.   So far the only stopgap solution is to create a directory in <code>wp-content/</code> called <code>1/</code>, and set the permissions to <code>000</code>, using an FTP program:</p>
<p><img src="http://archgfx.net/wp-content/uploads/2008/03/000.JPG" class="center" alt="000" /></p>
<p>While you're in there, you should also make sure your <code>wp-content/</code> directory is set to <code>755</code>, and you should set <code>wp-content/index.php</code> to <code>444</code>, since the exploit seems to replace that file as well.</p>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2008/geek/blogging/wordpress-233-spam-exploit/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Shame on me</title>
		<link>http://archgfx.net/blog/2007/geek/shame-on-me</link>
		<comments>http://archgfx.net/blog/2007/geek/shame-on-me#comments</comments>
		<pubDate>Mon, 12 Nov 2007 13:59:25 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[geekery]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2007/geek/shame-on-me</guid>
		<description><![CDATA[I've been lax in my personal security. Until last week, I only had 5 or so passwords. 1 for bank-grade security sites that required a strong password, 1 for physical computers, a few old ones, and the kicker, 1 for everything on the internet. Evidently I either signed up for something not so safe, or [...]]]></description>
			<content:encoded><![CDATA[<p>I've been lax in my personal security.  Until last week, I only had 5 or so passwords.  1 for bank-grade security sites that required a strong password, 1 for physical computers, a few old ones, and the kicker, 1 for everything on the internet.  Evidently I either signed up for something not so safe, or authenticated in plain text somewhere unsafe.  Or my "everything password" wasn't that secure.</p>
<p>Either way, someone guessed, stole, or cracked their way to my paypal account, and bought a couple hundred dollars worth of shareware via SWReg.org.  The funds came from a savings account so my first warning actually came from paypal, who placed restrictions on my account after the first couple login attempts failed.</p>
<p>I called up to report the fraudulent charges, and while the woman did helpfully explain that I could have done this all without taking my fingers off the keyboard, it was a good thing.  Besides being incredibly nice to someone asking questions from the <acronym title='Frequently Asked Questions'><span class='caps'>FAQ</span></acronym>, She also gave me a little shpiel about their new security keys, and offered to send me one.  Given my love of 1) free shit 2) security (present idiocy notwithstanding) 3) gadgets, I think you can guess my answer.</p>
<p><a href="http://paypal.com/securitykey"><img src="http://archgfx.net/wp-content/uploads/2007/11/spot_ppsecuritykeyfront_240x134.gif" alt="VIP token" /></a></p>
<p>It's a <a href="http://www.verisign.com/products-services/security-services/identity-protection/index.html">VIP token</a>, a pretty badass little toy.  You push a button and it generates a 6-digit number that's good for 30 seconds or so, which you use when you sign into your paypal + ebay accounts.  Not only that, but since it's made by verisign, you can add it to your <a href="http://pip.verisignlabs.com/">PIP openID</a> as well.  Now, in addition to having changed all my internet passwords, I've got ridiculously strong security on anything that I sign into with OpenID.  I'm using it for this site with <a href="http://wordpress.org/extend/plugins/openid/">openID+</a> v2.0(<a href="http://willnorris.com/2007/11/wp-openid-20-released">released friday</a>), although the previous versions have <a href="http://archgfx.net/blog/2007/geek/blogging/thirtieth#comment-22959">been glitchy</a>.</p>
<p>Unfortunately, I still haven't finished with paypal yet.  I have a premier account, which at some point required a land line.  I no longer have a home phone, so they have to <em>physically mail me something</em>, to restore my account.  That's just for the restrictions, though. They've already refunded the fraudulent charges.</p>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2007/geek/shame-on-me/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Link Spam in WP2.3</title>
		<link>http://archgfx.net/blog/2007/geek/link-spam-in-wp23</link>
		<comments>http://archgfx.net/blog/2007/geek/link-spam-in-wp23#comments</comments>
		<pubDate>Sat, 20 Oct 2007 12:26:47 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[geekery]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2007/geek/link-spam-in-wp23</guid>
		<description><![CDATA[Anyone running wordpress 2.3 with the "Anyone can register" checkbox on, should go grab WordPress 2.3.1 Beta 1, as there's an exploit1 in the wild. Meaning spammers are already using it  to insert any link they please into your blogroll.  Another solution is to close registration and delete any users you don't know. h/t Root [...]]]></description>
			<content:encoded><![CDATA[<p>Anyone running wordpress 2.3 with the "<strong>Anyone can register</strong>" checkbox on, should go grab <a href="http://boren.nu/archives/2007/10/17/wordpress-231-beta-1/">WordPress 2.3.1 Beta 1</a>, as there's an exploit<a href="#footnote-1-1224" id="footnote-link-1-1224" title="See the footnote.">1</a> <a href="http://wordpress.org/support/topic/138934?replies=15">in the wild</a>. Meaning spammers are already using it  to insert any link they please into your blogroll.   Another solution is to close registration and delete any users you don't know.</p>
<p><cite>h/t <a href="http://more404.com/article/49/wordpress-security-patch-7864">Root</a></cite></p>
<br /><ol class="footnotes"><li id="footnote-1-1224">not traditionally an exploit, there is no user privilege escalation, but users are allowed to access to a feature that should be restricted  <a href="#footnote-link-1-1224"></a></li></ol>]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2007/geek/link-spam-in-wp23/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Buckshot, Ep. 3</title>
		<link>http://archgfx.net/blog/2007/geek/buckshot-ep-3</link>
		<comments>http://archgfx.net/blog/2007/geek/buckshot-ep-3#comments</comments>
		<pubDate>Fri, 25 May 2007 16:16:50 +0000</pubDate>
		<dc:creator>adam</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[geekery]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[2.0]]></category>
		<category><![CDATA[buckshot]]></category>
		<category><![CDATA[downhill battle]]></category>
		<category><![CDATA[jesus]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[upgrade]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://archgfx.net/blog/2007/asides/buckshot-ep-3</guid>
		<description><![CDATA[If Paul was gay, I would hate christianity less. Then again, without the misogyny and homophobia, would it even have survived this long? No wonder people steal music: So... I guess as a reward for being a "true fan" you get ripped off. I love Trent Reznor. Although i have to say, the EURO max [...]]]></description>
			<content:encoded><![CDATA[<ul>
<li>If <a href="http://byzantium.wordpress.com/2007/02/13/paul-was-queer/">Paul was gay</a>, I would hate christianity less.  Then again, without the <a href="http://en.wikipedia.org/wiki/Pauline_Christianity">misogyny and homophobia</a>, would it even have survived this long?</li>
<li><a href="http://nin.com/tr/">No wonder people steal music</a>:<br />
<blockquote cite="http://nin.com/tr/"><p>So... I guess as a reward for being a "true fan" you get ripped off.</p></blockquote>
<p>I love Trent Reznor.  Although i have to say, the EURO max single is one of those things that people seem to <em>like</em> getting abused over.</li>
<li>WordPress 2.0 was so numbered to go along with the Web 2.0 buzz, <a href="http://dougal.gunters.org/blog/2007/04/19/wp-tags-perhaps-i-spoke-too-soon">but it lacked tags</a>, which were the hallmark of web 2.0.  it will be greatly amusing when the version that includes tags <a href="http://groups.google.com/group/wp-hackers/browse_thread/thread/7cee0af2ab019b8d/21d4d2e6667490b8?#21d4d2e6667490b8">bumps the version number to 3.0</a>.  Web 3.0, of course, is <a href="http://evolvingtrends.wordpress.com/2006/06/26/wikipedia-30-the-end-of-google/">supposed to be the semantic web</a>.  Surely, then, wordpress 4.0 will <a href="http://archgfx.net/wordpress/wp-content/themes/sandbox/readme.html#microformats" title="the sandbox, of course">give us the semantics</a> which will be dated by then?</li>
<li><a href="http://technosailor.com/98-of-wordpress-blogs-vulnerable/">98% of wordpress blogs are vulnerable</a>.  50 is a small sample size, but there's no doubt in my mind that the figure is accurate.  If <a href="http://lorelle.wordpress.com/2007/05/25/comment-spammers-never-stop-even-when-your-blog-is-down/">upgrading weren't such a <acronym title='Pain In The Ass'><span class='caps'>PITA</span></acronym></a>, mightn't the number be lower, though?</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://archgfx.net/blog/2007/geek/buckshot-ep-3/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

