<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: BIG security issue !</title>
	<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/</link>
	<description>ALEX RABE &#124; learning by doing...</description>
	<pubDate>Tue, 07 Oct 2008 03:39:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: alex.rabe</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-4719</link>
		<dc:creator>alex.rabe</dc:creator>
		<pubDate>Sat, 22 Dec 2007 12:57:13 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-4719</guid>
		<description>This is ongoing since May, also my page receive still 100-200 attemps each day...</description>
		<content:encoded><![CDATA[<p>This is ongoing since May, also my page receive still 100-200 attemps each day&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KC</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-4715</link>
		<dc:creator>KC</dc:creator>
		<pubDate>Sat, 22 Dec 2007 01:47:10 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-4715</guid>
		<description>I'm seeing today in the logs that someone (a botnet?) is guessing that I have this plugin installed (and some others too).  I notice that this happens time to time -- they check on whatever wordpress installations they can find and see if someone hasn't updated.</description>
		<content:encoded><![CDATA[<p>I&#8217;m seeing today in the logs that someone (a botnet?) is guessing that I have this plugin installed (and some others too).  I notice that this happens time to time &#8212; they check on whatever wordpress installations they can find and see if someone hasn&#8217;t updated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Websenat &#187; Beitrag &#187; Websenat reloaded 2 (UPDATE)</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2819</link>
		<dc:creator>Websenat &#187; Beitrag &#187; Websenat reloaded 2 (UPDATE)</dc:creator>
		<pubDate>Sun, 02 Sep 2007 12:09:28 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2819</guid>
		<description>[...] DoS-Attacken gegen einen Brasilianischen Server benutzt. Das betroffene PlugIn war WordTube von Alex Rabe. Anfang Mai wurde auch schon auf einigen Sites und Blogs &#252;ber dieses Problem berichtet. Durch [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] DoS-Attacken gegen einen Brasilianischen Server benutzt. Das betroffene PlugIn war WordTube von Alex Rabe. Anfang Mai wurde auch schon auf einigen Sites und Blogs &#252;ber dieses Problem berichtet. Durch [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fear, WPMU and progress&#8230; at alex.rabe</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2648</link>
		<dc:creator>Fear, WPMU and progress&#8230; at alex.rabe</dc:creator>
		<pubDate>Sat, 25 Aug 2007 09:03:36 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2648</guid>
		<description>[...] but this is also a growing risk that hackers and bad guys review again the code and find another security problem. I fear the day when my plugin is listed on milworm&#8230; I do my best to review my own code, but [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] but this is also a growing risk that hackers and bad guys review again the code and find another security problem. I fear the day when my plugin is listed on milworm&#8230; I do my best to review my own code, but [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wilsen</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2595</link>
		<dc:creator>wilsen</dc:creator>
		<pubDate>Wed, 22 Aug 2007 22:19:20 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2595</guid>
		<description>Hi Alex,

things like that happen! I appreciate that you acted that quick and that you mind your plug-in. But "Hacked of London" is right. Because of that I want to recommend this book:

http://www.amazon.de/PHP-Sicherheit-PHP-MySQL-Webanwendungen-sicher-programmieren/dp/3898644502/ref=cm_taf_title_featured?ie=UTF8&#38;tag=tellafriend-20

This book really kicks ass! And if you don't already know it, it will help you to develop more of these wonderful plug-ins for us ;-)</description>
		<content:encoded><![CDATA[<p>Hi Alex,</p>
<p>things like that happen! I appreciate that you acted that quick and that you mind your plug-in. But &#8220;Hacked of London&#8221; is right. Because of that I want to recommend this book:</p>
<p><a href="http://www.amazon.de/PHP-Sicherheit-PHP-MySQL-Webanwendungen-sicher-programmieren/dp/3898644502/ref=cm_taf_title_featured?ie=UTF8&amp;tag=tellafriend-20" rel="nofollow">http://www.amazon.de/PHP-Sicherheit-PHP-MySQL-Webanwendungen-sicher-programmieren/dp/3898644502/ref=cm_taf_title_featured?ie=UTF8&amp;tag=tellafriend-20</a></p>
<p>This book really kicks ass! And if you don&#8217;t already know it, it will help you to develop more of these wonderful plug-ins for us <img src='http://alexrabe.boelinger.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: site got hacked today!</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2434</link>
		<dc:creator>site got hacked today!</dc:creator>
		<pubDate>Mon, 13 Aug 2007 16:09:37 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2434</guid>
		<description>[...] seems like one file of the wordtube plugin was open to GET exploits. i removed the file now, changed all passwords (ftp, sql, wordpress, mint) and hope that i won&#8217;t recieve another suspicious email. if you use the same plugin, do so as well (instructions are here). [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] seems like one file of the wordtube plugin was open to GET exploits. i removed the file now, changed all passwords (ftp, sql, wordpress, mint) and hope that i won&#8217;t recieve another suspicious email. if you use the same plugin, do so as well (instructions are here). [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Downtime am Wochenende</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2123</link>
		<dc:creator>Downtime am Wochenende</dc:creator>
		<pubDate>Thu, 26 Jul 2007 09:36:59 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2123</guid>
		<description>[...] Ich m&#246;chte es so sagen: stellt bitte sicher, dass die Plugins eurer Wordpress-Installationen auf dem neusten Stand sind. Sofern ihr sie &#252;berhaupt benutzt. Aber auch sonst, denn sonst passieren doofe Dinge&#8230; [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Ich m&#246;chte es so sagen: stellt bitte sicher, dass die Plugins eurer Wordpress-Installationen auf dem neusten Stand sind. Sofern ihr sie &#252;berhaupt benutzt. Aber auch sonst, denn sonst passieren doofe Dinge&#8230; [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: boris</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2122</link>
		<dc:creator>boris</dc:creator>
		<pubDate>Thu, 26 Jul 2007 09:19:58 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2122</guid>
		<description>hab das sicherheitsproblem am eigenen leib.. ehm, server erfahren und wollte etwas zum thema erzählen.. aber ich sehe ja: das problem ist bekannt und gelöst. bestens :)</description>
		<content:encoded><![CDATA[<p>hab das sicherheitsproblem am eigenen leib.. ehm, server erfahren und wollte etwas zum thema erzählen.. aber ich sehe ja: das problem ist bekannt und gelöst. bestens <img src='http://alexrabe.boelinger.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: alex.rabe</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2052</link>
		<dc:creator>alex.rabe</dc:creator>
		<pubDate>Mon, 16 Jul 2007 17:02:53 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2052</guid>
		<description>&lt;p&gt;See my motto... learning by doing&lt;/p&gt;
You can trust me , this happend not a second time :-)</description>
		<content:encoded><![CDATA[<p>See my motto&#8230; learning by doing</p>
<p>You can trust me , this happend not a second time <img src='http://alexrabe.boelinger.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacked of London</title>
		<link>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2050</link>
		<dc:creator>Hacked of London</dc:creator>
		<pubDate>Mon, 16 Jul 2007 10:55:13 +0000</pubDate>
		<guid>http://alexrabe.boelinger.com/2007/05/01/big-security-issue/#comment-2050</guid>
		<description>These are really basic XSS attacks. Maybe you should learn to program before you release stuff in future.</description>
		<content:encoded><![CDATA[<p>These are really basic XSS attacks. Maybe you should learn to program before you release stuff in future.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
