<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Anonymous Security Specialist</title>
	<atom:link href="http://bavatuesdays.com/anonymous-security-specialist/feed/" rel="self" type="application/rss+xml" />
	<link>http://bavatuesdays.com/anonymous-security-specialist/</link>
	<description>a "b" blog</description>
	<lastBuildDate>Thu, 18 Mar 2010 19:50:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Reverend</title>
		<link>http://bavatuesdays.com/anonymous-security-specialist/comment-page-1/#comment-69126</link>
		<dc:creator>Reverend</dc:creator>
		<pubDate>Tue, 08 Apr 2008 21:52:05 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/anonymous-security-specialist/#comment-69126</guid>
		<description>@Scott: Wow, thanks for all the amazing info.  This is great stuff, and it is about time the education started in earnest about the holes in WP, for every app has them.

@Andre: I&#039;d love some more details on this issue. How does this XSS hack work? All this information is great, and sharing these issues of security are key for us.

@Another Victim: Robin Hood strikes again. I fully support your suggestion that we reward the A.S.S. somehow, although I imagine his line o work requires a certain amount of anonymity, but more power to him.</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=a3ce4e45c979a8523a2098808847fcc5&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />@Scott: Wow, thanks for all the amazing info.  This is great stuff, and it is about time the education started in earnest about the holes in WP, for every app has them.</p>
<p>@Andre: I&#8217;d love some more details on this issue. How does this XSS hack work? All this information is great, and sharing these issues of security are key for us.</p>
<p>@Another Victim: Robin Hood strikes again. I fully support your suggestion that we reward the A.S.S. somehow, although I imagine his line o work requires a certain amount of anonymity, but more power to him.
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Another Victim</title>
		<link>http://bavatuesdays.com/anonymous-security-specialist/comment-page-1/#comment-69058</link>
		<dc:creator>Another Victim</dc:creator>
		<pubDate>Mon, 07 Apr 2008 21:48:04 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/anonymous-security-specialist/#comment-69058</guid>
		<description>He paid me a visit as well, and sure enough i had my links full of spam.
I (hopefully) cleaned everything up and upgraded wordpress.

Mister Anonymous, my offer for sending you some beer money stands. Just name your poison ;)</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=612561c32bd4f14228d4a1d3a01b61b1&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />He paid me a visit as well, and sure enough i had my links full of spam.<br />
I (hopefully) cleaned everything up and upgraded wordpress.</p>
<p>Mister Anonymous, my offer for sending you some beer money stands. Just name your poison <img src='http://bavatuesdays.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andre Malan</title>
		<link>http://bavatuesdays.com/anonymous-security-specialist/comment-page-1/#comment-69055</link>
		<dc:creator>Andre Malan</dc:creator>
		<pubDate>Mon, 07 Apr 2008 20:44:34 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/anonymous-security-specialist/#comment-69055</guid>
		<description>As far as XSS goes, one thing that you should ensure is never to click on any link on the front end of a multi-user blog while logged in as admin. Our &quot;support&quot; person on UBC blogs is going to only have &quot;subscriber&quot; privileges. That way if someone does hack them, they can&#039;t do something crazy like delete all the blogs. admin should only ever be logged in to administrate the back end of the blog and then quickly logged out again.</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=1ec6b520a60486daa13e7204fac7412a&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />As far as XSS goes, one thing that you should ensure is never to click on any link on the front end of a multi-user blog while logged in as admin. Our &#8220;support&#8221; person on UBC blogs is going to only have &#8220;subscriber&#8221; privileges. That way if someone does hack them, they can&#8217;t do something crazy like delete all the blogs. admin should only ever be logged in to administrate the back end of the blog and then quickly logged out again.
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://bavatuesdays.com/anonymous-security-specialist/comment-page-1/#comment-68969</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Mon, 07 Apr 2008 00:44:35 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/anonymous-security-specialist/#comment-68969</guid>
		<description>That sucks.

If you don&#039;t upgrade it&#039;s not if but when you will be hacked. What the dude did is illegal (imagine if he broke into your office and latter emailed you to say your alarm system is faulty)... but I guess it is good that he got you to act. 

You might want to check out this video to see how easy it is to &quot;hack&quot; wordpress (or any app) if you are not careful (the examples in video could have been avoided). 
Part 1:
http://ca.youtube.com/watch?v=WZCXIrW0xZ0
Part 2:
http://ca.youtube.com/watch?v=JBpG2fie_aA

I think WP is secure in general it is the plugins that scare me. Often coded by newbies with little or no knowledge of info sec.

Good intro article on the topic of XSS  to learn more:
http://www.informit.com/articles/article.aspx?p=603037

Another on RSS injection... 
Zero Day Subscriptions: Using RSS and Atom Feeds As Attack Delivery Systems by: Bob Auger (Presented at Black Hat USA 2006):
http://h71028.www7.hp.com/enterprise/downloads/BobAuger-RSS_Security.pdf</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=bccfe7abf83682fee9d8704bca86e2de&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />That sucks.</p>
<p>If you don&#8217;t upgrade it&#8217;s not if but when you will be hacked. What the dude did is illegal (imagine if he broke into your office and latter emailed you to say your alarm system is faulty)&#8230; but I guess it is good that he got you to act. </p>
<p>You might want to check out this video to see how easy it is to &#8220;hack&#8221; wordpress (or any app) if you are not careful (the examples in video could have been avoided).<br />
Part 1:<br />
<a href="http://ca.youtube.com/watch?v=WZCXIrW0xZ0" rel="nofollow">http://ca.youtube.com/watch?v=WZCXIrW0xZ0</a><br />
Part 2:<br />
<a href="http://ca.youtube.com/watch?v=JBpG2fie_aA" rel="nofollow">http://ca.youtube.com/watch?v=JBpG2fie_aA</a></p>
<p>I think WP is secure in general it is the plugins that scare me. Often coded by newbies with little or no knowledge of info sec.</p>
<p>Good intro article on the topic of XSS  to learn more:<br />
<a href="http://www.informit.com/articles/article.aspx?p=603037" rel="nofollow">http://www.informit.com/articles/article.aspx?p=603037</a></p>
<p>Another on RSS injection&#8230;<br />
Zero Day Subscriptions: Using RSS and Atom Feeds As Attack Delivery Systems by: Bob Auger (Presented at Black Hat USA 2006):<br />
<a href="http://h71028.www7.hp.com/enterprise/downloads/BobAuger-RSS_Security.pdf" rel="nofollow">http://h71028.www7.hp.com/enterprise/downloads/BobAuger-RSS_Security.pdf</a>
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Reverend</title>
		<link>http://bavatuesdays.com/anonymous-security-specialist/comment-page-1/#comment-68813</link>
		<dc:creator>Reverend</dc:creator>
		<pubDate>Sun, 06 Apr 2008 08:46:38 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/anonymous-security-specialist/#comment-68813</guid>
		<description>Thanks Bill,

It&#039;s nice to know people who know far more than me.  And I think what you said about my focus on open source applications being vulnerable is important.  I, of all people, would hate to be coming off as a pill when it comes to open source application vulnerability, so that is a much needed correction to my verbiage!

I can&#039;t tell you how cool this anonymous security specialist seems to me, a much needed kick in the ass is always welcome, for as you suggest, the reverend must ride, always  :)</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=a3ce4e45c979a8523a2098808847fcc5&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />Thanks Bill,</p>
<p>It&#8217;s nice to know people who know far more than me.  And I think what you said about my focus on open source applications being vulnerable is important.  I, of all people, would hate to be coming off as a pill when it comes to open source application vulnerability, so that is a much needed correction to my verbiage!</p>
<p>I can&#8217;t tell you how cool this anonymous security specialist seems to me, a much needed kick in the ass is always welcome, for as you suggest, the reverend must ride, always  <img src='http://bavatuesdays.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Fitzgerald</title>
		<link>http://bavatuesdays.com/anonymous-security-specialist/comment-page-1/#comment-68801</link>
		<dc:creator>Bill Fitzgerald</dc:creator>
		<pubDate>Sun, 06 Apr 2008 07:10:41 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/anonymous-security-specialist/#comment-68801</guid>
		<description>Hello, Jim,

I would definitely have your ISP look at your server logs to see if anything looks out of place -- 

But my guess is that you got lucky with this one, and that your site was surveyed by someone who knew what they were doing and had no bad intentions -- 

The only danger you&#039;d have from upgrading would be if the WP downloads were themselves compromised -- not likely at all, despite the fact that it happened last year: http://it.slashdot.org/article.pl?sid=07/03/03/0427211

RE: &quot;how vulnerable an out-of-date open source applications&quot; -- an out of date app is vulnerable, whether it&#039;s proprietary or Open Source -- however, when another ginormous security hole appears in Windows, we think nothing of it, because it&#039;s &quot;normal.&quot; Yet, when an open source app patches a vulnerability, it&#039;s fodder for the FUD-sters looking to point out the insecurity of open source apps.

Glad to hear you upgraded. I don&#039;t want the Reverend&#039;s digital presence going down into the hellfires, brought there by the purveyors of pill-powered tumescence.</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=c0eb3e06a324ace9c70bd3e1b397d0e7&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />Hello, Jim,</p>
<p>I would definitely have your ISP look at your server logs to see if anything looks out of place &#8212; </p>
<p>But my guess is that you got lucky with this one, and that your site was surveyed by someone who knew what they were doing and had no bad intentions &#8212; </p>
<p>The only danger you&#8217;d have from upgrading would be if the WP downloads were themselves compromised &#8212; not likely at all, despite the fact that it happened last year: <a href="http://it.slashdot.org/article.pl?sid=07/03/03/0427211" rel="nofollow">http://it.slashdot.org/article.pl?sid=07/03/03/0427211</a></p>
<p>RE: &#8220;how vulnerable an out-of-date open source applications&#8221; &#8212; an out of date app is vulnerable, whether it&#8217;s proprietary or Open Source &#8212; however, when another ginormous security hole appears in Windows, we think nothing of it, because it&#8217;s &#8220;normal.&#8221; Yet, when an open source app patches a vulnerability, it&#8217;s fodder for the FUD-sters looking to point out the insecurity of open source apps.</p>
<p>Glad to hear you upgraded. I don&#8217;t want the Reverend&#8217;s digital presence going down into the hellfires, brought there by the purveyors of pill-powered tumescence.
<div style='clear:both'></div>
]]></content:encoded>
	</item>
</channel>
</rss>
