<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Matasano Chargen - Latest Comments in Funny WordPress Vulnerability</title><link>http://matasanochargen.disqus.com/</link><description></description><atom:link href="https://matasanochargen.disqus.com/funny_wordpress_vulnerability/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Tue, 30 Jun 2009 09:29:51 -0000</lastBuildDate><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-11932128</link><description>&lt;p&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/" rel="nofollow noopener" target="_blank" title="Sohbet"&gt;SOHBET&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/bursa.html" rel="nofollow noopener" target="_blank" title="Sohbet"&gt;BURSA SOHBET&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/istanbul.html" rel="nofollow noopener" target="_blank" title="Sohbet"&gt;ISTANBUL CHAT&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/islamidini.html" rel="nofollow noopener" target="_blank" title="islami dini"&gt;ISLAMI CHAT&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/izmir.html" rel="nofollow noopener" target="_blank" title="izmir Sohbet"&gt;IZMIR CHAT&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/ankara.html" rel="nofollow noopener" target="_blank" title="Ankara Sohbet"&gt;ANKARA ARKADAS&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/almanya.html" rel="nofollow noopener" target="_blank" title="Almanya Sohbet"&gt;ALMANYA CHAT&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/turkiye.html" rel="nofollow noopener" target="_blank" title="TURKEY"&gt;TURKEY CHAT&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/mynet.html" rel="nofollow noopener" target="_blank" title="Mynet"&gt;MYNET&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/siteneekle.html" rel="nofollow noopener" target="_blank" title="Sitene Ekle"&gt;SITENE EKLE&lt;/a&gt;&lt;/b&gt;&lt;br&gt;&lt;b&gt;&lt;a href="http://www.odasohbeti.com/ensonyerlivideomuzikleriklipleridinleizle.html" rel="nofollow noopener" target="_blank" title="video"&gt;VIDEO KLIP IZLE&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">sohbet</dc:creator><pubDate>Tue, 30 Jun 2009 09:29:51 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323603</link><description>&lt;p&gt;Haha, thanks for that, very entertaining. It's disappointing that no-one's fixed this rather weak looking bit of coding (e.g. the entirety of wordpress) yet!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">SEO Ranter</dc:creator><pubDate>Fri, 11 Apr 2008 05:08:10 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323596</link><description>&lt;p&gt;Interesting. There are some good ideass presented here. I need to do spend some time reading more about these topics.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Doug Steele</dc:creator><pubDate>Sun, 17 Feb 2008 22:01:50 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323602</link><description>&lt;p&gt;ndg: Thank you for the clarification.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike Tracy</dc:creator><pubDate>Wed, 23 Jan 2008 18:43:12 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323601</link><description>&lt;p&gt;"Apparently, we’re using the is_admin() call to figure out if a user is administrator after all?"&lt;/p&gt;&lt;p&gt;No, it's because pending/draft posts are only displayed in the administration interface (on the "manage posts" page, etc).&lt;/p&gt;&lt;p&gt;The issue here is that WordPress classifies posts along two axes, published-unpublished and public-private. The exploit reveals (unpublished &amp;amp; public) data only; posts marked as "private" stay private, even though an administrator would be able to see them.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ndg</dc:creator><pubDate>Wed, 23 Jan 2008 18:21:16 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323600</link><description>&lt;p&gt;And why does my blog post all of a sudden become about Tom?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike Tracy</dc:creator><pubDate>Wed, 23 Jan 2008 17:29:56 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323599</link><description>&lt;p&gt;What does that comment even mean?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Wed, 23 Jan 2008 17:29:21 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323595</link><description>&lt;p&gt;Oh no, you're picking up the Thomas style of oblique asides.  Trying to sort info from cuteness and failing...&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Nate</dc:creator><pubDate>Wed, 23 Jan 2008 17:12:12 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323598</link><description>&lt;p&gt;I'm not sure about "wrong".  All that statement was intended to do was point out that the way the bug was exploited in the snippet at &lt;a href="http://blackhatdomainer.com" rel="nofollow noopener" target="_blank" title="blackhatdomainer.com"&gt;blackhatdomainer.com&lt;/a&gt; requires the use of REQUEST_URI.  It was not intended to suggest a fix or in any other way condone the coding practices of the WordPress crew.&lt;/p&gt;&lt;p&gt;I probably should have been more clear in the idea I was expressing but I was too busy snorting a perfectly good bottle of wine out of my nose.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mike Tracy</dc:creator><pubDate>Wed, 23 Jan 2008 14:00:57 -0000</pubDate></item><item><title>Re: Funny WordPress Vulnerability</title><link>http://www.matasano.com/log/1019/funny/#comment-2323597</link><description>&lt;p&gt;"In PHP, the difference between _SERVER[‘PHP_SELF’] and _SERVER[‘REQUEST_URI’] is that the latter also gives you the parameters that were passed to a GET request."&lt;/p&gt;&lt;p&gt;Perhaps by now you already know your'e wrong. PHP_SELF is as much vulnerable as REQUEST_URI.&lt;/p&gt;&lt;p&gt;Peace. Lets see what gobless saz :]&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hugo</dc:creator><pubDate>Wed, 23 Jan 2008 13:41:40 -0000</pubDate></item></channel></rss>