<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress and some questions about Blogland Security</title>
	<atom:link href="http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/</link>
	<description>a "b" blog</description>
	<lastBuildDate>Fri, 19 Mar 2010 17:25:38 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bill Fitzgerald</title>
		<link>http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/comment-page-1/#comment-20420</link>
		<dc:creator>Bill Fitzgerald</dc:creator>
		<pubDate>Wed, 08 Aug 2007 22:23:18 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/#comment-20420</guid>
		<description>Hello, Jim,

WP and security have a long and stormy relationship -- it would make for a great B movie -- 

I can just imagine the following line of dialogue: &quot;His script came from without, and entered my private place.&quot;

From Oct, 04 -- http://developers.slashdot.org/article.pl?sid=04/10/01/2050216

Fast forward ahead 2.5 years: 
http://it.slashdot.org/it/07/03/03/0427211.shtml

And from May, 07:
http://it.slashdot.org/article.pl?sid=07/05/24/167223

All kidding aside, ouch. 

I don&#039;t know if the WP community has any equivalent of this (http://drupal.org/writing-secure-code) in their developer docs, but it would be good to see some standards like this integrated into their code review process, both for core and contrib code.

Cheers,

Bill</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=c0eb3e06a324ace9c70bd3e1b397d0e7&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />Hello, Jim,</p>
<p>WP and security have a long and stormy relationship &#8212; it would make for a great B movie &#8212; </p>
<p>I can just imagine the following line of dialogue: &#8220;His script came from without, and entered my private place.&#8221;</p>
<p>From Oct, 04 &#8212; <a href="http://developers.slashdot.org/article.pl?sid=04/10/01/2050216" rel="nofollow">http://developers.slashdot.org/article.pl?sid=04/10/01/2050216</a></p>
<p>Fast forward ahead 2.5 years:<br />
<a href="http://it.slashdot.org/it/07/03/03/0427211.shtml" rel="nofollow">http://it.slashdot.org/it/07/03/03/0427211.shtml</a></p>
<p>And from May, 07:<br />
<a href="http://it.slashdot.org/article.pl?sid=07/05/24/167223" rel="nofollow">http://it.slashdot.org/article.pl?sid=07/05/24/167223</a></p>
<p>All kidding aside, ouch. </p>
<p>I don&#8217;t know if the WP community has any equivalent of this (<a href="http://drupal.org/writing-secure-code" rel="nofollow">http://drupal.org/writing-secure-code</a>) in their developer docs, but it would be good to see some standards like this integrated into their code review process, both for core and contrib code.</p>
<p>Cheers,</p>
<p>Bill
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: D'Arcy Norman</title>
		<link>http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/comment-page-1/#comment-20194</link>
		<dc:creator>D'Arcy Norman</dc:creator>
		<pubDate>Wed, 08 Aug 2007 05:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/#comment-20194</guid>
		<description>Drupal also has the advantage of having a meaner, leaner codebase. WordPress has many more lines of code, meaning there may be more opportunities for bugs and/or security holes.

http://buytaert.net/cms-code-base-comparison

Drupal core has less than half the code of WordPress...</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=4f523b36360882764462462cc95f040d&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />Drupal also has the advantage of having a meaner, leaner codebase. WordPress has many more lines of code, meaning there may be more opportunities for bugs and/or security holes.</p>
<p><a href="http://buytaert.net/cms-code-base-comparison" rel="nofollow">http://buytaert.net/cms-code-base-comparison</a></p>
<p>Drupal core has less than half the code of WordPress&#8230;
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: jimgroom</title>
		<link>http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/comment-page-1/#comment-20186</link>
		<dc:creator>jimgroom</dc:creator>
		<pubDate>Wed, 08 Aug 2007 02:54:46 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/#comment-20186</guid>
		<description>You&#039;re a sick puppy, Norman -and I love it!</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=a3ce4e45c979a8523a2098808847fcc5&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />You&#8217;re a sick puppy, Norman -and I love it!
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: D'Arcy Norman</title>
		<link>http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/comment-page-1/#comment-20182</link>
		<dc:creator>D'Arcy Norman</dc:creator>
		<pubDate>Wed, 08 Aug 2007 02:43:29 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/#comment-20182</guid>
		<description>I&#039;ll be the Vietnamese villager, and you can be the water buffalo. Apocalypse Now, Redux.

It&#039;s probably not completely insecure - I mean, every blog on the planet (save maybe a handful) runs that way...</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=4f523b36360882764462462cc95f040d&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />I&#8217;ll be the Vietnamese villager, and you can be the water buffalo. Apocalypse Now, Redux.</p>
<p>It&#8217;s probably not completely insecure &#8211; I mean, every blog on the planet (save maybe a handful) runs that way&#8230;
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: jimgroom</title>
		<link>http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/comment-page-1/#comment-20180</link>
		<dc:creator>jimgroom</dc:creator>
		<pubDate>Wed, 08 Aug 2007 02:16:05 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/#comment-20180</guid>
		<description>Thanks for putting me at ease D&#039;Arcy. Next time bring a machete and finish the job why don&#039;t you...</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=a3ce4e45c979a8523a2098808847fcc5&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />Thanks for putting me at ease D&#8217;Arcy. Next time bring a machete and finish the job why don&#8217;t you&#8230;
<div style='clear:both'></div>
]]></content:encoded>
	</item>
	<item>
		<title>By: D'Arcy Norman</title>
		<link>http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/comment-page-1/#comment-20178</link>
		<dc:creator>D'Arcy Norman</dc:creator>
		<pubDate>Wed, 08 Aug 2007 02:03:18 +0000</pubDate>
		<guid isPermaLink="false">http://bavatuesdays.com/wordpress-and-some-questions-about-blogland-security/#comment-20178</guid>
		<description>Even with a fully patched web app, we&#039;re all running the admin side without SSL and HTTPS, so anyone with a packet sniffer could grab usernames, passwords, and/or cookies and have their way with the blogs anyway...</description>
		<content:encoded><![CDATA[<p><img style='float: right; margin-left: 10px;' src='http://www.gravatar.com/avatar.php?gravatar_id=4f523b36360882764462462cc95f040d&amp;size=60&amp;default=http%3A%2F%2Fuse.perl.org%2Fimages%2Fpix.gif' alt='' />Even with a fully patched web app, we&#8217;re all running the admin side without SSL and HTTPS, so anyone with a packet sniffer could grab usernames, passwords, and/or cookies and have their way with the blogs anyway&#8230;
<div style='clear:both'></div>
]]></content:encoded>
	</item>
</channel>
</rss>
