<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mr Mist&#039;s Blog &#187; security</title>
	<atom:link href="http://www.misthaven.org.uk/blog/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.misthaven.org.uk/blog</link>
	<description>Tech News, Random Stuff, WordPress, and things going mouldy.</description>
	<lastBuildDate>Sun, 01 Jan 2012 13:01:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Upgrade your copy now…</title>
		<link>http://www.misthaven.org.uk/blog/2009/07/31/upgrade-your-copy-now/</link>
		<comments>http://www.misthaven.org.uk/blog/2009/07/31/upgrade-your-copy-now/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 20:35:51 +0000</pubDate>
		<dc:creator>Mrmist</dc:creator>
				<category><![CDATA[Web and Tech]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.misthaven.org.uk/blog/?p=1790</guid>
		<description><![CDATA[<hr />This article is tagged with: <a href="http://www.misthaven.org.uk/blog/tag/security/" rel="tag">security</a>, <a href="http://www.misthaven.org.uk/blog/tag/wordpress/" rel="tag">WordPress</a><hr />There seems to be growing evidence that the XSS vunerability in versions of WordPress before 2.8.2 is now being exploited for real in the wild. The manifestation seems to be that, after recieving a maliciously-crafted comment, affected blogs display a login panel Title: Authentication Required Text: The server (yourserver) at Magic requires a username and<a style="text-decoration : none;" href="http://www.misthaven.org.uk/blog/2009/07/31/upgrade-your-copy-now/"> [...]</a>]]></description>
			<content:encoded><![CDATA[<hr />This article is tagged with: <a href="http://www.misthaven.org.uk/blog/tag/security/" rel="tag">security</a>, <a href="http://www.misthaven.org.uk/blog/tag/wordpress/" rel="tag">WordPress</a><hr /><p>There seems to be growing evidence that the XSS vunerability in versions of WordPress before 2.8.2 is now being exploited for real in the wild.  The manifestation seems to be that, after recieving a maliciously-crafted comment, affected blogs display a login panel</p>
<p>Title: Authentication Required<br />
Text: The server (yourserver) at Magic requires a username and password</p>
<p>It would appear at the moment as though the malicious content can be removed by replacing wp-includes with a fresh copy from the WordPress source for your version.  But if I were you I wouldn&#8217;t take that chance.  I&#8217;d <a href="http://wordpress.org/download/">upgrade to 2.8.2 now</a>.  Otherwise you can&#8217;t really be sure that the hack hasn&#8217;t stolen any credentials, or caused other changes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.misthaven.org.uk/blog/2009/07/31/upgrade-your-copy-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AOL IM security hole</title>
		<link>http://www.misthaven.org.uk/blog/2002/01/03/aol-im-security-hole/</link>
		<comments>http://www.misthaven.org.uk/blog/2002/01/03/aol-im-security-hole/#comments</comments>
		<pubDate>Thu, 03 Jan 2002 09:06:27 +0000</pubDate>
		<dc:creator>Mrmist</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[AOL]]></category>
		<category><![CDATA[IM]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.misthaven.org.uk/2002/01/03/aol-im-security-hole/</guid>
		<description><![CDATA[<hr />This article is tagged with: <a href="http://www.misthaven.org.uk/blog/tag/aol/" rel="tag">AOL</a>, <a href="http://www.misthaven.org.uk/blog/tag/im/" rel="tag">IM</a>, <a href="http://www.misthaven.org.uk/blog/tag/security/" rel="tag">security</a><hr />BBC News is just one place that has noted the security hole in AOL instant messenger. The original advisory is here if you can get to it.]]></description>
			<content:encoded><![CDATA[<hr />This article is tagged with: <a href="http://www.misthaven.org.uk/blog/tag/aol/" rel="tag">AOL</a>, <a href="http://www.misthaven.org.uk/blog/tag/im/" rel="tag">IM</a>, <a href="http://www.misthaven.org.uk/blog/tag/security/" rel="tag">security</a><hr /><p><a href="http://news.bbc.co.uk/hi/english/sci/tech/newsid_1740000/1740135.stm">BBC News</a> is just one place that has noted the security hole in AOL instant messenger.  The original advisory is <a href="http://www.w00w00.org/advisories/aim.html">here</a> if you can get to it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.misthaven.org.uk/blog/2002/01/03/aol-im-security-hole/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 1/15 queries in 0.254 seconds using disk: basic
Object Caching 257/282 objects using disk: basic

Served from: www.misthaven.org.uk @ 2012-02-08 20:46:30 -->
