<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Funny WordPress Vulnerability</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Tue, 30 Jun 2009 09:29:51 -0000</lastBuildDate><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-11932128</link><description>&lt;B&gt;&lt;a href="http://www.odasohbeti.com/" title="Sohbet" target="_top" rel="nofollow"&gt;SOHBET&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/bursa.html" title="Sohbet" target="_top" rel="nofollow"&gt;BURSA SOHBET&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/istanbul.html" title="Sohbet" target="_top" rel="nofollow"&gt;ISTANBUL CHAT&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/islamidini.html" title="islami dini" target="_top" rel="nofollow"&gt;ISLAMI CHAT&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/izmir.html" title="izmir Sohbet" target="_top" rel="nofollow"&gt;IZMIR CHAT&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/ankara.html" title="Ankara Sohbet" target="_top" rel="nofollow"&gt;ANKARA ARKADAS&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/almanya.html" title="Almanya Sohbet" target="_top" rel="nofollow"&gt;ALMANYA CHAT&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/turkiye.html" title="TURKEY" target="_top" rel="nofollow"&gt;TURKEY CHAT&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/mynet.html" title="Mynet" target="_top" rel="nofollow"&gt;MYNET&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/siteneekle.html" title="Sitene Ekle" target="_top" rel="nofollow"&gt;SITENE EKLE&lt;/a&gt;&lt;/B&gt;&lt;br&gt;&lt;B&gt;&lt;a href="http://www.odasohbeti.com/ensonyerlivideomuzikleriklipleridinleizle.html" title="video" target="_top" rel="nofollow"&gt;VIDEO KLIP IZLE&lt;/a&gt;&lt;/B&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">chatsohbet</dc:creator><pubDate>Tue, 30 Jun 2009 09:29:51 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323603</link><description>Haha, thanks for that, very entertaining. It's disappointing that no-one's fixed this rather weak looking bit of coding (e.g. the entirety of wordpress) yet!</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">SEO Ranter</dc:creator><pubDate>Fri, 11 Apr 2008 05:08:10 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323596</link><description>Interesting. There are some good ideass presented here. I need to do spend some time reading more about these topics.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Doug Steele</dc:creator><pubDate>Sun, 17 Feb 2008 22:01:50 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323602</link><description>ndg: Thank you for the clarification.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike Tracy</dc:creator><pubDate>Wed, 23 Jan 2008 18:43:12 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323601</link><description>"Apparently, we’re using the is_admin() call to figure out if a user is administrator after all?"&lt;br&gt;&lt;br&gt;No, it's because pending/draft posts are only displayed in the administration interface (on the "manage posts" page, etc).&lt;br&gt;&lt;br&gt;The issue here is that WordPress classifies posts along two axes, published-unpublished and public-private. The exploit reveals (unpublished &amp;amp; public) data only; posts marked as "private" stay private, even though an administrator would be able to see them.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ndg</dc:creator><pubDate>Wed, 23 Jan 2008 18:21:16 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323600</link><description>And why does my blog post all of a sudden become about Tom?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike Tracy</dc:creator><pubDate>Wed, 23 Jan 2008 17:29:56 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323599</link><description>What does that comment even mean?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 23 Jan 2008 17:29:21 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323595</link><description>Oh no, you're picking up the Thomas style of oblique asides.  Trying to sort info from cuteness and failing...</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nate</dc:creator><pubDate>Wed, 23 Jan 2008 17:12:12 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323598</link><description>I'm not sure about "wrong".  All that statement was intended to do was point out that the way the bug was exploited in the snippet at &lt;a href="http://blackhatdomainer.com" rel="nofollow"&gt;blackhatdomainer.com&lt;/a&gt; requires the use of REQUEST_URI.  It was not intended to suggest a fix or in any other way condone the coding practices of the WordPress crew.&lt;br&gt;&lt;br&gt;I probably should have been more clear in the idea I was expressing but I was too busy snorting a perfectly good bottle of wine out of my nose.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike Tracy</dc:creator><pubDate>Wed, 23 Jan 2008 14:00:57 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323597</link><description>"In PHP, the difference between _SERVER[‘PHP_SELF’] and _SERVER[‘REQUEST_URI’] is that the latter also gives you the parameters that were passed to a GET request."&lt;br&gt;&lt;br&gt;Perhaps by now you already know your'e wrong. PHP_SELF is as much vulnerable as REQUEST_URI.&lt;br&gt;&lt;br&gt;Peace. Lets see what gobless saz :]</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hugo</dc:creator><pubDate>Wed, 23 Jan 2008 13:41:40 -0000</pubDate></item></channel></rss>