<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Security alert: WordPress Competition Winning Plugins Vulnerable</title>
	<atom:link href="http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/</link>
	<description>Get Your Daily Byte Of Technology</description>
	<lastBuildDate>Thu, 26 Jan 2012 06:55:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Jan</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1973</link>
		<dc:creator>Jan</dc:creator>
		<pubDate>Mon, 03 Sep 2007 13:03:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1973</guid>
		<description>Mistakes happen? :)</description>
		<content:encoded><![CDATA[<p>Mistakes happen? :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Amy</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1971</link>
		<dc:creator>Amy</dc:creator>
		<pubDate>Thu, 30 Aug 2007 21:32:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1971</guid>
		<description>Personally, I think I would have a few people check my plugin before I went submitting it as a finished product. Then again, I can&#039;t make them so nevermind. :P

Congrats to the winner, but it&#039;s kinda lame that he was the way he was about the hosting prize.</description>
		<content:encoded><![CDATA[<p>Personally, I think I would have a few people check my plugin before I went submitting it as a finished product. Then again, I can&#8217;t make them so nevermind. :P</p>
<p>Congrats to the winner, but it&#8217;s kinda lame that he was the way he was about the hosting prize.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1972</link>
		<dc:creator>David</dc:creator>
		<pubDate>Wed, 29 Aug 2007 22:10:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1972</guid>
		<description>How much damage can be done on a vulnerable plugin? It seems it can be a doorway to attacks?</description>
		<content:encoded><![CDATA[<p>How much damage can be done on a vulnerable plugin? It seems it can be a doorway to attacks?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anirudh</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1961</link>
		<dc:creator>Anirudh</dc:creator>
		<pubDate>Tue, 28 Aug 2007 11:47:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1961</guid>
		<description>There&#039;s no real proof that it can be done and virtually every script is vunerable to csrf and XSS, anyways, this minor problem is fixed. Please read this:
http://anirudhsanjeev.org/on-oneclick-security/

thanks.</description>
		<content:encoded><![CDATA[<p>There&#8217;s no real proof that it can be done and virtually every script is vunerable to csrf and XSS, anyways, this minor problem is fixed. Please read this:<br />
<a href="http://anirudhsanjeev.org/on-oneclick-security/" rel="nofollow">http://anirudhsanjeev.org/on-oneclick-security/</a></p>
<p>thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kirk M</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1962</link>
		<dc:creator>Kirk M</dc:creator>
		<pubDate>Mon, 27 Aug 2007 23:47:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1962</guid>
		<description>Has an email been sent to the author of OneClick with this info? I don&#039;t see an update yet nor an acknowledgment of a comment about this left by David in Spanish of all things. Either way, since I&#039;ve worked with Anirudh on a couple of bugs early on, I&#039;m sending one myself.</description>
		<content:encoded><![CDATA[<p>Has an email been sent to the author of OneClick with this info? I don&#8217;t see an update yet nor an acknowledgment of a comment about this left by David in Spanish of all things. Either way, since I&#8217;ve worked with Anirudh on a couple of bugs early on, I&#8217;m sending one myself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keith Dsouza</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1963</link>
		<dc:creator>Keith Dsouza</dc:creator>
		<pubDate>Mon, 27 Aug 2007 21:41:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1963</guid>
		<description>The said bugs have been fixed and i have released the latest version http://techie-buzz.com/wordpress-plugins/wpau-wins-third-at-weblog-tools-plugin-competition.html

Thanks
Keith</description>
		<content:encoded><![CDATA[<p>The said bugs have been fixed and i have released the latest version <a href="http://techie-buzz.com/wordpress-plugins/wpau-wins-third-at-weblog-tools-plugin-competition.html" rel="nofollow">http://techie-buzz.com/wordpress-plugins/wpau-wins-third-at-weblog-tools-plugin-competition.html</a></p>
<p>Thanks<br />
Keith</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Catch up ! - Online Diary</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1968</link>
		<dc:creator>Catch up ! - Online Diary</dc:creator>
		<pubDate>Mon, 27 Aug 2007 19:37:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1968</guid>
		<description>[...] security flaws in each of these plug-ins. [...]</description>
		<content:encoded><![CDATA[<p>[...] security flaws in each of these plug-ins. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ozh</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1970</link>
		<dc:creator>Ozh</dc:creator>
		<pubDate>Mon, 27 Aug 2007 13:25:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1970</guid>
		<description>The 2 plugins flagged as vulnerable to XSS&amp;CSRF are, I think, just lacking nonce fields in their forms. Which does make them vulnerable to some XSS &amp; CSRF attacks. Which is, IMO, &lt;em&gt;nothing near&lt;/em&gt; a critical vulnerability. There&#039;s no reason not to implement nonces, really, and adding this WP built-in protection in all my plugins has been sitting on my todo-list for quite a while now. I&#039;ve just been too lazy, but there&#039;s no reason why this should go on top of my todo list.

So, unless the smart ass behind this original announcement replies with some details and proves me wrong with more serious issues, I&#039;ll keep this on my todo-list and update some day, for instance when I add features.</description>
		<content:encoded><![CDATA[<p>The 2 plugins flagged as vulnerable to XSS&amp;CSRF are, I think, just lacking nonce fields in their forms. Which does make them vulnerable to some XSS &amp; CSRF attacks. Which is, IMO, <em>nothing near</em> a critical vulnerability. There&#8217;s no reason not to implement nonces, really, and adding this WP built-in protection in all my plugins has been sitting on my todo-list for quite a while now. I&#8217;ve just been too lazy, but there&#8217;s no reason why this should go on top of my todo list.</p>
<p>So, unless the smart ass behind this original announcement replies with some details and proves me wrong with more serious issues, I&#8217;ll keep this on my todo-list and update some day, for instance when I add features.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Barry</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1969</link>
		<dc:creator>Barry</dc:creator>
		<pubDate>Mon, 27 Aug 2007 12:31:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1969</guid>
		<description>@David - Why can&#039;t you let us know the details. You obviously know what they are otherwise you wouldn&#039;t be running around posting that there are vulnerabilities everywhere?
If you haven&#039;t seen them, or know about them, then do you really think you are helping?</description>
		<content:encoded><![CDATA[<p>@David &#8211; Why can&#8217;t you let us know the details. You obviously know what they are otherwise you wouldn&#8217;t be running around posting that there are vulnerabilities everywhere?<br />
If you haven&#8217;t seen them, or know about them, then do you really think you are helping?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Carrero Fdez-Baillo</title>
		<link>http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1965</link>
		<dc:creator>David Carrero Fdez-Baillo</dc:creator>
		<pubDate>Mon, 27 Aug 2007 09:43:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.clazh.com/security-alert-wordpress-competition-winning-plugins-vulnerable/#comment-1965</guid>
		<description>I write alex from buayacorp. I request more information about this bugs for plugin authors.</description>
		<content:encoded><![CDATA[<p>I write alex from buayacorp. I request more information about this bugs for plugin authors.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

