<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Technosailor - Latest Comments in 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.disqus.com/</link><description></description><atom:link href="https://technosailor.disqus.com/98_of_wordpress_blogs_vulnerable/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Sat, 16 Feb 2008 14:54:27 -0000</lastBuildDate><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702307</link><description>&lt;p&gt;It crashed when I tried to update from an earlier version to latest one. Didn't work.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ness</dc:creator><pubDate>Sat, 16 Feb 2008 14:54:27 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702305</link><description>&lt;p&gt;Er make that "Subscribe" to Comments. I need my coffee.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Zatz</dc:creator><pubDate>Sat, 09 Jun 2007 12:53:21 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702303</link><description>&lt;p&gt;2.2 broke my Respond to Comments plugin. Wonder if B5's new talent knows anything about that. ;)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Zatz</dc:creator><pubDate>Sat, 09 Jun 2007 12:52:13 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702302</link><description>&lt;p&gt;yeah I must upgrade, thanks the timely reminder..&lt;/p&gt;&lt;p&gt;Only surveying 50 is not much though&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jermayn Parker</dc:creator><pubDate>Wed, 30 May 2007 03:57:17 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702301</link><description>&lt;p&gt;So how did you detect the version of the blog in your survey?  The header in the template?  Oooh... or the css href on wp-admin works, too...&lt;/p&gt;&lt;p&gt;I'm not very happy that the software and version is broadcast in wordpress.  It's not so much security by obscurity than hiding from the fricking spammers.  When I took out the header, my comment spam decreased over the next 3-4 weeks.&lt;/p&gt;&lt;p&gt;Ciao!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">docwhat</dc:creator><pubDate>Tue, 29 May 2007 20:14:37 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702298</link><description>&lt;p&gt;Lol that was funny, 1.5 o boy. But your right. people are so happy with what is running so smooth they never want to take a chance. In the era where taking backup is so easy and to get back to previous state is easier than that...I wonder why ppl don't upgrade.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ashish Mohta</dc:creator><pubDate>Mon, 28 May 2007 05:21:24 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702294</link><description>&lt;p&gt;I know, I know...I should upgrade both blogs.  Honestly when I read the instructions my eyes go all googly and I get a piercing pain in my head.&lt;/p&gt;&lt;p&gt;Sigh.  I'm a bad, bad blogger.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Carol</dc:creator><pubDate>Sat, 26 May 2007 23:57:28 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702292</link><description>&lt;p&gt;I'm waiting for FANTASTICO to let me upgrade. I fear the possibility of screwing up my site. At least this way, it's backed up from head to toe and I can easily reinstall it.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jenny</dc:creator><pubDate>Sat, 26 May 2007 17:55:24 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702293</link><description>&lt;p&gt;Why does the wordpress default theme include the version number in the header and order us to 'leave this for stats'? I know security by obscurity is no substitute for keeping up to date, but, realistically, not everyone is going to upgrade on a monthly basis and broadcasting your vulnerability in metatags doesn't seem the smartest move. Theme designers really need to start thinking about the code they're using and quit blindly copy-pasting from Kubrick.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">that girl again</dc:creator><pubDate>Sat, 26 May 2007 13:27:11 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702291</link><description>&lt;p&gt;The thing is, you never know if the new version will work with all the plug-ins. And to backup the DB and files before every update is kind of a pain...&lt;/p&gt;&lt;p&gt;I update... but I tend to be one version behind...:)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">brem</dc:creator><pubDate>Fri, 25 May 2007 18:02:44 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702289</link><description>&lt;p&gt;Well all the devs blogs have it. In addition, you should subscribe to &lt;a href="http://blogsearch.google.com/blogsearch_feeds?hl=en&amp;amp;q=wordpress+security&amp;amp;ie=utf-8&amp;amp;num=10&amp;amp;output=rss" rel="nofollow noopener" target="_blank" title="http://blogsearch.google.com/blogsearch_feeds?hl=en&amp;amp;q=wordpress+security&amp;amp;ie=utf-8&amp;amp;num=10&amp;amp;output=rss"&gt;this&lt;/a&gt; or setup a google alert.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Brazell</dc:creator><pubDate>Fri, 25 May 2007 16:39:34 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702288</link><description>&lt;p&gt;Adam is on target...&lt;/p&gt;&lt;p&gt;If WordPress x.x.x has a vulnerability WordPress the organization should be more active in communicating that to folks running the software. The only reason I knew 2.1.13 had a problem is because I read it here. My Dashboard says 2.2 is available, but it doesn't say I should upgrade ASAP because there's a security flaw. Security through obscurity?&lt;/p&gt;&lt;p&gt;Also upgrading can be stressful and a PITA for the less tech savvy. Again without learning abut upgrade scripts here, I'd still be putting it off.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dave Zatz</dc:creator><pubDate>Fri, 25 May 2007 16:35:39 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702286</link><description>&lt;p&gt;Aaron, you can take partial credit for the fact that I am running 2.2 thanks to your post a couple of weeks ago. :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Wendy Piersall</dc:creator><pubDate>Fri, 25 May 2007 16:34:06 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702284</link><description>&lt;p&gt;just for clarity-&lt;br&gt;if 2.1.3 is that eminently hackable, why is there no 2.0.11?  was the vulnerability only in the 2.1 branch?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">adam</dc:creator><pubDate>Fri, 25 May 2007 14:07:21 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702283</link><description>&lt;p&gt;adam: It's on Digg now - and yes you can &lt;a href="http://digg.com/software/98_of_WordPress_Blogs_Vulnerable" rel="nofollow noopener" target="_blank" title="http://digg.com/software/98_of_WordPress_Blogs_Vulnerable"&gt;feel free to Digg it&lt;/a&gt;. On the other hand, Digg's got a big bullhorn so thats another way to make lots of people hear about it.&lt;/p&gt;&lt;p&gt;YTour point about ongoing notifications though is well recieved.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Brazell</dc:creator><pubDate>Fri, 25 May 2007 13:32:56 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702282</link><description>&lt;p&gt;So you're saying you'd like me to demonstrate on your blog how 2.1.3 is vulnerable? Trust me when I say that I can gain admin access to your blog in 5 minutes.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Brazell</dc:creator><pubDate>Fri, 25 May 2007 13:05:59 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702281</link><description>&lt;p&gt;this might be something that should be broadcast from the dashboard.  i doubt that any of the people whose blogs are insecure are reading slashdot, or your blog, or the hackers list.&lt;/p&gt;&lt;p&gt;it's the people who spend more time actually blogging, than reading about blogging.  and it's the reason that it's &lt;strong&gt;so important&lt;/strong&gt; that "easy upgrading" gets finished before any more versions of wordpress ship.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">adam</dc:creator><pubDate>Fri, 25 May 2007 13:05:53 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702280</link><description>&lt;p&gt;2.2 only came out 10 days ago.  People running 2.1.3 are reasonably with-it.&lt;/p&gt;&lt;p&gt;It would be interesting if you check the same sites in a couple weeks to see how they change.&lt;/p&gt;&lt;p&gt;Ciao!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">docwhat</dc:creator><pubDate>Fri, 25 May 2007 12:59:15 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702274</link><description>&lt;p&gt;Running 2.2 on primary blogs, I have been slacking on a few niche ones and "marketing platforms"&lt;/p&gt;&lt;p&gt;At least I beat your statistics, but most don't&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andy Beard</dc:creator><pubDate>Fri, 25 May 2007 11:07:45 -0000</pubDate></item><item><title>Re: 98% of WordPress Blogs Vulnerable</title><link>http://technosailor.com/2007/05/24/98-of-wordpress-blogs-vulnerable/#comment-928702273</link><description>&lt;p&gt;Odd, that. Nine out of 10 of my blogs are up to date. The tenth is getting upgraded in a few minutes.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Michael Hampton</dc:creator><pubDate>Fri, 25 May 2007 10:57:53 -0000</pubDate></item></channel></rss>