<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AWSOM.org = Artist Website Setup Options Markup &#187; Security</title>
	<atom:link href="http://www.awsom.org/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.awsom.org</link>
	<description>Get your website up and running in an AWSOM fashion</description>
	<lastBuildDate>Wed, 16 Jun 2010 17:26:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Wordpress 2.5.1 released, major security fix required</title>
		<link>http://www.awsom.org/2008/wordpress-251-released-major-security-fix-required/</link>
		<comments>http://www.awsom.org/2008/wordpress-251-released-major-security-fix-required/#comments</comments>
		<pubDate>Sat, 26 Apr 2008 12:44:34 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[AWSOM News]]></category>
		<category><![CDATA[Critical!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/?p=254</guid>
		<description><![CDATA[WordPress 2.5.1 has been released, and all 2.5 users should immediately upgrade to the new version. There is apparently some kind of security vulnerability fix in the new version, so this is a critical upgrade for all users. I suspect it&#8217;s probably related to the ongoing series of issues that are causing spam attacks on [...]]]></description>
			<content:encoded><![CDATA[<p>WordPress 2.5.1 has been released, and all 2.5 users should immediately upgrade to the new version. There is apparently some kind of security vulnerability fix in the new version, so this is a critical upgrade for all users. I suspect it&#8217;s probably related to the ongoing series of issues that are causing spam attacks on older versions of WordPress, so this is a pretty big reason to be constantly on the lookout for irregular things occurring on your sites and make sure you always have the most updated versions of plugins and such installed.</p>
<p>So far it looks like all of the AWSOM plugins are unaffected by the upgrade and still work properly. If you encounter any issues though please let me know.</p>
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=254&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_254" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2008/wordpress-251-released-major-security-fix-required/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam Hack in Progress across Wordpress sites</title>
		<link>http://www.awsom.org/2008/spam-hack-in-progress-across-wordpress-sites/</link>
		<comments>http://www.awsom.org/2008/spam-hack-in-progress-across-wordpress-sites/#comments</comments>
		<pubDate>Tue, 15 Apr 2008 15:54:23 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[AWSOM News]]></category>
		<category><![CDATA[Critical!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/?p=251</guid>
		<description><![CDATA[There is currently a large scale spam attack on Wordpress sites that is ongoing and affects primarily Wordpress versions 2.1.x and 2.2.x (it&#8217;s not clear if 2.3.x or 2.0.x are affected, but it seems likely they aren&#8217;t). The attack results in a large number of spam listings injected into either posts or theme files which [...]]]></description>
			<content:encoded><![CDATA[<p>There is currently a large scale spam attack on Wordpress sites that is ongoing and affects primarily Wordpress versions 2.1.x and 2.2.x (it&#8217;s not clear if 2.3.x or 2.0.x are affected, but it seems likely they aren&#8217;t). The attack results in a large number of spam listings injected into either posts or theme files which are then set to be hidden through css. Your will typically find that you&#8217;ve been affected when Google contacts you to say you are being de-listed due to a high number of spam links on your site. It is also typical for the attackers to delete all of your pages from your site for some reason, so if you load your site and all of your pages are gone you may have been hacked.</p>
<p>It&#8217;s not entirely clear what method the hackers are using to get admin access to the affected sites, but from my observation it may be a privilege escalation attack using the comment system. In some cases a random user account was created right before the attack. It was also noted that the comments.php theme file was altered to add in a console access applet which allowed for low level server access. If you get hacked make sure you check every theme file to make sure no malicious code was added&#8211;or better yet, reload your theme files from a backed up or fresh copy, and delete out any suspect user registrations.</p>
<p>Wordpress 2.5 is apparently not affected by this problem, so an upgrade should help. I have upgraded my sites to 2.5 and have managed to mostly get things working (though my archive page on this site is currently non-functional). It looks like this is the unfortunate little push that will force most people to upgrade, though I strongly suggest making sure first that there are updated plugins that work with 2.5.</p>
<p>
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=251&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_251" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2008/spam-hack-in-progress-across-wordpress-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On the Same Track as Last Post</title>
		<link>http://www.awsom.org/2008/on-the-same-track-as-last-post/</link>
		<comments>http://www.awsom.org/2008/on-the-same-track-as-last-post/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 17:12:08 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[Critical!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/2008/on-the-same-track-as-last-post/</guid>
		<description><![CDATA[While it is always more convenient to place as many functions into one centralized site as possible, it is also generally more insecure and prone to problems. Case in point: Forum plugins for Wordpress. While I know the desire to have one centralized administration area for a forum and your blog site might seem like [...]]]></description>
			<content:encoded><![CDATA[<p>While it is always more convenient to place as many functions into one centralized site as possible, it is also generally more insecure and prone to problems. Case in point: Forum plugins for Wordpress. While I know the desire to have one centralized administration area for a forum and your blog site might seem like a good idea, it is not always in your best interest to have this as your set up. Apparently there is a <a href="http://weblogtoolscollection.com/archives/2008/01/21/wp-forum-plugin-security-bulletin/">bug in the current version of the WP-Forum plugin</a> that allows malicious users to access your database information. Whenever you have a situation where you allow users to add content to your site, you create a potentially vulnerable area for someone to exploit. In the case of a forum, this can be especially difficult to program in a manner that eliminates this risk. (note how often most forums have security updates, it&#8217;s a lot). So you end up with a case where you now have 2 different site concepts taken out by the most vulnerable element. I almost exclusively suggest that people simply run 2 different sites with 2 different databases and simply match them using a common looking theme. It&#8217;s simply more secure to do things that way.
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=229&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_229" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2008/on-the-same-track-as-last-post/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Urgent Security Issue, Upgrade Wordpress to 2.3.3 Now!</title>
		<link>http://www.awsom.org/2008/urgent-security-issue-upgrade-wordpress-to-233-now/</link>
		<comments>http://www.awsom.org/2008/urgent-security-issue-upgrade-wordpress-to-233-now/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 17:03:48 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[Critical!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/2008/urgent-security-issue-upgrade-wordpress-to-233-now/</guid>
		<description><![CDATA[There has been an unscheduled Wordpress Security release that upgrades Wordpress to version 2.3.3. This is a critical update that closes a vulnerability that would allow registered users to edit the posts of other users if they sent a specially formatted request. It is strongly suggested that all users on the 2.3.x branch upgrade their [...]]]></description>
			<content:encoded><![CDATA[<p>There has been an unscheduled <a href="http://wordpress.org/download/">Wordpress Security release</a> that upgrades Wordpress to version 2.3.3. This is a critical update that closes a vulnerability that would allow registered users to edit the posts of other users if they sent a specially formatted request. It is strongly suggested that all users on the 2.3.x branch upgrade their version as soon as possible.
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=228&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_228" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2008/urgent-security-issue-upgrade-wordpress-to-233-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security a focus as Wordpress Matures</title>
		<link>http://www.awsom.org/2008/security-a-focus-as-wordpress-matures/</link>
		<comments>http://www.awsom.org/2008/security-a-focus-as-wordpress-matures/#comments</comments>
		<pubDate>Thu, 24 Jan 2008 14:26:19 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[Other Web Resources]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Website Administration]]></category>
		<category><![CDATA[Wordpress Plugins]]></category>

		<guid isPermaLink="false">http://www.awsom.org/2008/security-a-focus-as-wordpress-matures/</guid>
		<description><![CDATA[The typical scenario of any software project is &#8220;get it working first, we&#8217;ll secure it later&#8221;. This is particularly true of Web packages, since it&#8217;s not easy in advance to know all of the possible issues you may run into across all of the possible server instances that exist. Wordpress has now become enough established [...]]]></description>
			<content:encoded><![CDATA[<p>The typical scenario of any software project is &#8220;get it working first, we&#8217;ll secure it later&#8221;. This is particularly true of Web packages, since it&#8217;s not easy in advance to know all of the possible issues you may run into across all of the possible server instances that exist. Wordpress has now become enough established that the idea of &#8220;hardening&#8221; it against attack is starting to become a major focus. One of the easiest ways to start doing this is to eliminate the known database table structure, so it&#8217;s harder for hackers to try to inject password searches or other methods of gaining higher privileges on your server or Wordpress. In my <a href="http://www.awsom.org/tutorials/2-config-file-setup/">tutorial on setting up Wordpress</a> I try to stress that you should always change the generic database prefix &#8220;wp_&#8221; to something completely random to help accomplish this. Unfortunately many people missed this step, or set up their Wordpress using an installer program that does not allow this change.</p>
<p>All is not lost though. I have recently discovered a plugin that might help. The folks over at <a href="http://blogsecurity.net/">BlogSecurity.net</a> have developed a plugin for Wordpress that is designed to alter this prefix. <a href="http://blogsecurity.net/wordpress/tool-130707/">WP Prefix Table Changer</a> gets activated like a regular plugin but will alter things so that you have this vulnerability fixed. </p>
<p>This is a very minor thing to do, but every little security step you can take enhances your overall stability and makes you less of a target.</p>
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=222&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_222" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2008/security-a-focus-as-wordpress-matures/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.3.2 released, Critical Update!</title>
		<link>http://www.awsom.org/2007/wordpress-232-released-critical-update/</link>
		<comments>http://www.awsom.org/2007/wordpress-232-released-critical-update/#comments</comments>
		<pubDate>Sun, 30 Dec 2007 15:22:21 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[Critical!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/2007/wordpress-232-released-critical-update/</guid>
		<description><![CDATA[Wordpress 2.3.2 has just been released, and it contains critical updates that fix some vulnerabilities in how Wordpress creates Draft entries. Anyone using the Wordpress 2.3.x line should immediately go to Wordpress.org and download the new version. Unless you&#8217;ve done something strange to your core files all you need to do is overwrite your current [...]]]></description>
			<content:encoded><![CDATA[<p>Wordpress 2.3.2 has just been released, and it contains <strong>critical updates</strong> that fix some vulnerabilities in how Wordpress creates Draft entries. Anyone using the Wordpress 2.3.x line should immediately go to <a href="http://wordpress.org/download/">Wordpress.org and download the new version</a>. Unless you&#8217;ve done something strange to your core files all you need to do is overwrite your current install with the new version to successfully upgrade&#8211;then go to wp-admin/upgrade.php in your web browser to finalize the database update.
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=205&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_205" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2007/wordpress-232-released-critical-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.3.1 now available</title>
		<link>http://www.awsom.org/2007/wordpress-231-now-available/</link>
		<comments>http://www.awsom.org/2007/wordpress-231-now-available/#comments</comments>
		<pubDate>Mon, 29 Oct 2007 16:26:43 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/2007/wordpress-231-now-available/</guid>
		<description><![CDATA[Wordpress 2.3.1 is now available for download from the Wordpress.org website. This release fixes a number of bugs and security issues. I would strongly suggest all current 2.3 version users download and update their version of Wordpress.
Advertisement:  Check Out My Online Store 
ShareThis
]]></description>
			<content:encoded><![CDATA[<p>Wordpress 2.3.1 is now available for <a href="http://wordpress.org/download/">download</a> from the Wordpress.org website. This release fixes a number of bugs and security issues. I would strongly suggest all current 2.3 version users download and update their version of Wordpress.
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=176&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_176" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2007/wordpress-231-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First Wordpress 2.3 vulnerability found, same for earlier versions</title>
		<link>http://www.awsom.org/2007/first-wordpress-23-vulnerability-found-same-for-earlier-versions/</link>
		<comments>http://www.awsom.org/2007/first-wordpress-23-vulnerability-found-same-for-earlier-versions/#comments</comments>
		<pubDate>Wed, 24 Oct 2007 12:45:22 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[Critical!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/2007/first-wordpress-23-vulnerability-found-same-for-earlier-versions/</guid>
		<description><![CDATA[The first Wordpress 2.3 security issue has been found. It is in regard to the blogroll function in Wordpress and results in unlimited spam entries being injected into your blogroll. This vulnerability is already being exploited by spammers. An explanation and a fixed file can be found here until a new point release of Wordpress [...]]]></description>
			<content:encoded><![CDATA[<p>The first Wordpress 2.3 security issue has been found. It is in regard to the blogroll function in Wordpress and results in unlimited spam entries being injected into your blogroll. This vulnerability is already being exploited by spammers. An explanation and a fixed file can be found <a href="http://blogsecurity.net/wordpress/first-wp-23-dexter-vulnerability/">here</a> until a new point release of Wordpress is available. This issue apparently also affects older versions of Wordpress as well as the newest version, so pretty much anyone using the blogroll on their site should immediately address this issue.
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=173&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_173" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2007/first-wordpress-23-vulnerability-found-same-for-earlier-versions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.2.3 released, Security update</title>
		<link>http://www.awsom.org/2007/wordpress-223-released-security-update/</link>
		<comments>http://www.awsom.org/2007/wordpress-223-released-security-update/#comments</comments>
		<pubDate>Mon, 10 Sep 2007 12:58:49 +0000</pubDate>
		<dc:creator>harknell</dc:creator>
				<category><![CDATA[Critical!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Website Administration]]></category>

		<guid isPermaLink="false">http://www.awsom.org/2007/wordpress-223-released-security-update/</guid>
		<description><![CDATA[Wordpress 2.2.3 has been released and contains some small bug fixes and security updates. Anyone using the 2.2.x branch should update to this new version. (Please note: 2.2.3 is NOT 2.3 and is not the version of Wordpress that will break many older plugins&#8211;this is just an update to the existing 2.2 branch&#8211;so don&#8217;t be [...]]]></description>
			<content:encoded><![CDATA[<p>Wordpress 2.2.3 has been released and contains some small bug fixes and security updates. Anyone using the 2.2.x branch should update to this new version. (Please note: 2.2.3 is NOT 2.3 and is not the version of Wordpress that will break many older plugins&#8211;this is just an update to the existing 2.2 branch&#8211;so don&#8217;t be afraid to update to this version).
<p><strong><em>Advertisement</em></strong>:  <a href="http://www.onezumistudios.com">Check Out My Online Store</a><em> </em></p>
<p class="akst_link"><a href="http://www.awsom.org/?p=152&amp;akst_action=share-this"  title="Email, post to del.icio.us, etc." id="akst_link_152" class="akst_share_link" rel="noindex nofollow">ShareThis</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://www.awsom.org/2007/wordpress-223-released-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
