<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Technosailor - Latest Comments in Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.disqus.com/</link><description></description><atom:link href="https://technosailor.disqus.com/democracy_plugin_xss_vulnerability_alert/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Tue, 26 Sep 2006 18:30:31 -0000</lastBuildDate><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033764</link><description>&lt;p&gt;Aaron. You have already validated my message and then I retrieved my "key" (it need for your version of wp-subscription-manager.php). And after looking to one of the vulnerable scripts (in this case - wp-subscription-manager.php), I can tell you that your site is &amp;lt;strong&amp;gt;vulnerable&amp;lt;/strong&amp;gt; (via Subscribe To Comments plugin)!&lt;/p&gt;&lt;p&gt;You need to update plugin. You can take Subscribe To Comments 2.0.5 from my MustLive Security Pack v.1.0.4 or download last version (Subscribe To Comments 2.0.8) from developer's site.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">MustLive</dc:creator><pubDate>Tue, 26 Sep 2006 18:30:31 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033751</link><description>&lt;p&gt;Aaron. As I wrote at my site &lt;a href="http://websecurity.com.ua/187/" rel="nofollow noopener" target="_blank" title="http://websecurity.com.ua/187/"&gt;http://websecurity.com.ua/187/&lt;/a&gt; two weeks ago, I was found a vulnerability in Subscribe To Comments WordPress plugin (and already released the path and plugin developer also worked on next version of plugin). So there are many other cases (among WordPress plugins) with plugin's vulnerabilities, not only in Democracy plugin. And as I see, you also use Subscribe To Comments at your site, so you need to draw attention to this information (and check your plugin).&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">MustLive</dc:creator><pubDate>Tue, 26 Sep 2006 18:03:42 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033763</link><description>&lt;p&gt;Aaron,&lt;br&gt;I may feel differently if one of my sites had been hacked - that'll certainly give you a different perspective on the matter.  Either way, it's necessary to post the expoit so that a fix can be produced, whether by the author or someone else.  Good to see that the author did come up with a fix, so that people had a solution instead of a freak-out period of waiting.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Leroy Brown</dc:creator><pubDate>Mon, 25 Sep 2006 13:25:40 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033762</link><description>&lt;p&gt;Leroy: Technically, no you can't hold an author liable. In reality though, he's liable. That's how anyone who would get exploited would feel. That's how I would feel if I was hacked as a result. Fortunately, I was able to post the exploit with a link to a new version, so I'd like to think that I worked &amp;lt;em&amp;gt;with&amp;lt;/em&amp;gt; Andrew to find a solution before it blew up.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Brazell</dc:creator><pubDate>Mon, 25 Sep 2006 09:40:14 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033761</link><description>&lt;p&gt;It's a shame that it always takes the public posting of the exploit for the author to fix the problem.  Although I can't be too hard on someone who creates a plugin at no cost, so I don't know.  Mixed feelings as usual.  &lt;br&gt;Can you hold the author liable for any problems, even though his software is free?  I'm not sure that it's fair to do so.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Leroy Brown</dc:creator><pubDate>Mon, 25 Sep 2006 08:58:26 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033760</link><description>&lt;p&gt;drmike - I wasn't saying they were safe. I'm talking about people who can code saying that other code is unsafe.&lt;/p&gt;&lt;p&gt;&amp;lt;a href="&lt;a href="http://www.tamba2.org.uk/T2/archives/2006/09/23/plugins-2/" rel="nofollow noopener" target="_blank" title="http://www.tamba2.org.uk/T2/archives/2006/09/23/plugins-2/"&gt;http://www.tamba2.org.uk/T2...&lt;/a&gt;" rel="nofollow"&amp;gt;I've a challenge&amp;lt;/a&amp;gt;. If it will be accepted.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">podz</dc:creator><pubDate>Sat, 23 Sep 2006 10:46:51 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033750</link><description>&lt;p&gt;Podz: Don't forget all those people over on the &lt;a href="http://wp.com" rel="nofollow noopener" target="_blank" title="wp.com"&gt;wp.com&lt;/a&gt; forums who keep saying that javascripts, embed, and object tags are safe as well. :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">drmike</dc:creator><pubDate>Sat, 23 Sep 2006 10:34:32 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033759</link><description>&lt;p&gt;Sure, &amp;lt;a href="&lt;a href="http://www.technosailor.com/why-release-software-vulnerability-details/" rel="nofollow noopener" target="_blank" title="http://www.technosailor.com/why-release-software-vulnerability-details/"&gt;http://www.technosailor.com...&lt;/a&gt;" rel="nofollow"&amp;gt;over here&amp;lt;/a&amp;gt;. ;)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Brazell</dc:creator><pubDate>Fri, 22 Sep 2006 21:43:15 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033758</link><description>&lt;p&gt;No link love for the person who actually discovered it? :-)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Duncan</dc:creator><pubDate>Fri, 22 Sep 2006 21:41:17 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033757</link><description>&lt;p&gt;Sure. And you could also subscribe to bugtraq and find this same kind of information numerous times a day. Secrecy is not always the best policy. I don't make a habit of reporting exploits but I read blogs everyday that do. It's quite the same thing.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Brazell</dc:creator><pubDate>Fri, 22 Sep 2006 19:50:49 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033756</link><description>&lt;p&gt;pods: posting the exploit is standard practice, whether it's Microsoft or Apache.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jeremy Wright</dc:creator><pubDate>Fri, 22 Sep 2006 19:50:23 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033755</link><description>&lt;p&gt;These plugins can be very dangerous.  I think the Wordpress culture is to install as many plugins as possible without doing a ton of research.&lt;/p&gt;&lt;p&gt;This one is a very insidious exploit.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Darren McLaughlin</dc:creator><pubDate>Fri, 22 Sep 2006 19:49:18 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033754</link><description>&lt;p&gt;But I could now google enough to find that plugin and hit those sites in a couple of clicks.&lt;br&gt;Surely just saying what you have and omitting the actual exploit would be the way to go?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">podz</dc:creator><pubDate>Fri, 22 Sep 2006 19:36:35 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033753</link><description>&lt;p&gt;Hey podz-&lt;/p&gt;&lt;p&gt;Most people tend to think, "Aww, a hack will never happen to me". The point of this exercise was to demonstrate how very simple it is. Maybe demonstration will cause folks to be cautious regarding plugins they use.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Aaron Brazell</dc:creator><pubDate>Fri, 22 Sep 2006 19:22:21 -0000</pubDate></item><item><title>Re: Democracy Plugin XSS Vulnerability ALERT</title><link>http://technosailor.com/2006/09/22/democracy-plugin-xss-vulnerability-alert/#comment-1033752</link><description>&lt;p&gt;I'm curious - why post the actual exploit? &lt;br&gt;Is it to prove it's existence?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">podz</dc:creator><pubDate>Fri, 22 Sep 2006 19:17:03 -0000</pubDate></item></channel></rss>