<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: WordPress 1.5.1.3 Remote Access Exploit</title>
	<atom:link href="http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/</link>
	<description>Tech, Web, How to, Reviews, Tips, Downloads, and Make Money Online</description>
	<pubDate>Sat, 22 Nov 2008 00:27:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>By: Amir Schricker &#62; Blog Archive &#62; How to Turn register_globals Off</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-23051</link>
		<dc:creator>Amir Schricker &#62; Blog Archive &#62; How to Turn register_globals Off</dc:creator>
		<pubDate>Sun, 16 Apr 2006 05:12:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-23051</guid>
		<description>[...] I have to give credit to this site  for telling me how: [...]</description>
		<content:encoded><![CDATA[<p>[...] I have to give credit to this site  for telling me how: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Schleifstein.net &#187; Blog Archive &#187; more hack fixes</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-17347</link>
		<dc:creator>Schleifstein.net &#187; Blog Archive &#187; more hack fixes</dc:creator>
		<pubDate>Wed, 08 Feb 2006 15:09:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-17347</guid>
		<description>[...] my info on wordpress 1.5 vunerability [...]</description>
		<content:encoded><![CDATA[<p>[...] my info on wordpress 1.5 vunerability [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-12031</link>
		<dc:creator>James</dc:creator>
		<pubDate>Wed, 17 Aug 2005 10:01:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-12031</guid>
		<description>update wordpress to the latest version :) fixes the problem</description>
		<content:encoded><![CDATA[<p>update wordpress to the latest version <img src='http://www.liewcf.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> fixes the problem</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark J</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11948</link>
		<dc:creator>Mark J</dc:creator>
		<pubDate>Sun, 14 Aug 2005 13:55:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11948</guid>
		<description>Info on patching the vulnerability &lt;a href="http://wordpress.org/support/topic/41836" rel="nofollow"&gt;here&lt;/a&gt;.  The hole has been plugged, and a 1.5.2 release should be coming out shortly.</description>
		<content:encoded><![CDATA[<p>Info on patching the vulnerability <a href="http://wordpress.org/support/topic/41836" rel="nofollow">here</a>.  The hole has been plugged, and a 1.5.2 release should be coming out shortly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gilachess</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11945</link>
		<dc:creator>gilachess</dc:creator>
		<pubDate>Sun, 14 Aug 2005 12:30:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11945</guid>
		<description>Ha ha.. I reported this hack and vulnerability at least 2-3 weeks ago but got nobody's attention. Some people even questioned me how their beloved WordPress could possibly have any security holes in it.

Well now I'm vindicated. :)

Anyway I've also removed PHPRPC modules from my postnuke as well as my WordPress installation.</description>
		<content:encoded><![CDATA[<p>Ha ha.. I reported this hack and vulnerability at least 2-3 weeks ago but got nobody&#8217;s attention. Some people even questioned me how their beloved WordPress could possibly have any security holes in it.</p>
<p>Well now I&#8217;m vindicated. <img src='http://www.liewcf.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Anyway I&#8217;ve also removed PHPRPC modules from my postnuke as well as my WordPress installation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: My Other Side of the Stories &#187; &#187; Wordpress v1.5.1.3 Exploit</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11942</link>
		<dc:creator>My Other Side of the Stories &#187; &#187; Wordpress v1.5.1.3 Exploit</dc:creator>
		<pubDate>Sun, 14 Aug 2005 10:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11942</guid>
		<description>[...] If you&#8217;re using Wordpress v1.5.1.3, you should aware of the latest exploit found on this latest Wordpress version. SecuriTeam posted this exploit on August 10th, as quoted below (via LiewCF): A vulnerability in WordPress’s handling of incoming cookie information allows remote attackers to cause the program to execute arbitrary code if the PHP settings of register_globals has been set to On. [...]</description>
		<content:encoded><![CDATA[<p>[...] If you&#8217;re using Wordpress v1.5.1.3, you should aware of the latest exploit found on this latest Wordpress version. SecuriTeam posted this exploit on August 10th, as quoted below (via LiewCF): A vulnerability in WordPress’s handling of incoming cookie information allows remote attackers to cause the program to execute arbitrary code if the PHP settings of register_globals has been set to On. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LcF</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11933</link>
		<dc:creator>LcF</dc:creator>
		<pubDate>Sat, 13 Aug 2005 16:57:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11933</guid>
		<description>Thank you, Edrei. :)</description>
		<content:encoded><![CDATA[<p>Thank you, Edrei. <img src='http://www.liewcf.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Edrei</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11930</link>
		<dc:creator>Edrei</dc:creator>
		<pubDate>Sat, 13 Aug 2005 15:01:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11930</guid>
		<description>Well...that actually have come up with a fix a while ago. I don't know why Matt hasn't released the new version yet.

The fix can be found &lt;a href="http://trac.wordpress.org/file/branches/1.5/wp-settings.php" rel="nofollow"&gt;here&lt;/a&gt;

Sorry you guys had to go through the trouble of fixing it. Next time tell me and I'll give the heads up direct from the WP peeps. :)</description>
		<content:encoded><![CDATA[<p>Well&#8230;that actually have come up with a fix a while ago. I don&#8217;t know why Matt hasn&#8217;t released the new version yet.</p>
<p>The fix can be found <a href="http://trac.wordpress.org/file/branches/1.5/wp-settings.php" rel="nofollow">here</a></p>
<p>Sorry you guys had to go through the trouble of fixing it. Next time tell me and I&#8217;ll give the heads up direct from the WP peeps. <img src='http://www.liewcf.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LcF</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11923</link>
		<dc:creator>LcF</dc:creator>
		<pubDate>Sat, 13 Aug 2005 05:34:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11923</guid>
		<description>&lt;blockquote&gt;The quick fix is to place

unset($wp_filter);&lt;/blockquote&gt;I will still goto turn off register_globals. However, the quick fix is good if you are running other web script that required register_global ON.</description>
		<content:encoded><![CDATA[<blockquote><p>The quick fix is to place</p>
<p>unset($wp_filter);</p></blockquote>
<p>I will still goto turn off register_globals. However, the quick fix is good if you are running other web script that required register_global ON.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uzyn</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11922</link>
		<dc:creator>uzyn</dc:creator>
		<pubDate>Sat, 13 Aug 2005 05:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11922</guid>
		<description>&lt;blockquote&gt;Yeah can be done from windows box if you does have a shell account.&lt;/blockquote&gt;

I did it without any shell account or whatsoever. 

Directly from my PC, not virtually through other Linux box.</description>
		<content:encoded><![CDATA[<blockquote><p>Yeah can be done from windows box if you does have a shell account.</p></blockquote>
<p>I did it without any shell account or whatsoever. </p>
<p>Directly from my PC, not virtually through other Linux box.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pandaboy</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11920</link>
		<dc:creator>pandaboy</dc:creator>
		<pubDate>Sat, 13 Aug 2005 04:11:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11920</guid>
		<description>I found this via Blogsome forum:

&lt;blockquote&gt;"There is an exploit for Wordpress up and including to 1.5.1.3 out in the wild, which works on webservers with enabled register_globals..

The quick fix is to place

unset($wp_filter);

in index.php at the very top, right after 

Link: &lt;a href="http://www.blogsome.com/forum/viewtopic.php?t=1039" rel="nofollow"&gt;http://www.blogsome.com/forum/viewtopic.php?t=1039&lt;/a&gt;

Sounds like an easier approach, what do you think?&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>I found this via Blogsome forum:</p>
<blockquote><p>&#8220;There is an exploit for Wordpress up and including to 1.5.1.3 out in the wild, which works on webservers with enabled register_globals..</p>
<p>The quick fix is to place</p>
<p>unset($wp_filter);</p>
<p>in index.php at the very top, right after </p>
<p>Link: <a href="http://www.blogsome.com/forum/viewtopic.php?t=1039" rel="nofollow">http://www.blogsome.com/forum/viewtopic.php?t=1039</a></p>
<p>Sounds like an easier approach, what do you think?</p></blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: ahkiong</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11919</link>
		<dc:creator>ahkiong</dc:creator>
		<pubDate>Sat, 13 Aug 2005 03:46:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11919</guid>
		<description>Yeah can be done from windows box if you does have a shell account.</description>
		<content:encoded><![CDATA[<p>Yeah can be done from windows box if you does have a shell account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LcF</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11918</link>
		<dc:creator>LcF</dc:creator>
		<pubDate>Sat, 13 Aug 2005 03:03:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11918</guid>
		<description>&lt;blockquote&gt;Err… if you don’t mind… my name is uzyn. not uync.&lt;/blockquote&gt;
Sorry, corrected.</description>
		<content:encoded><![CDATA[<blockquote><p>Err… if you don’t mind… my name is uzyn. not uync.</p></blockquote>
<p>Sorry, corrected.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uzyn</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11917</link>
		<dc:creator>uzyn</dc:creator>
		<pubDate>Sat, 13 Aug 2005 00:31:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11917</guid>
		<description>Yup. He's just secured it.

The exploit is not just Linux only. Those are just means to pass in variables.

I'm doing it from a Windows box.</description>
		<content:encoded><![CDATA[<p>Yup. He&#8217;s just secured it.</p>
<p>The exploit is not just Linux only. Those are just means to pass in variables.</p>
<p>I&#8217;m doing it from a Windows box.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ahkiong</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11916</link>
		<dc:creator>ahkiong</dc:creator>
		<pubDate>Sat, 13 Aug 2005 00:16:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11916</guid>
		<description>Less poeple would know how to use Linux but probably out there, some will do it. The exploit could only be run from either any sort of linux console. Perl *.php http://*.com /dir port "uname -a" and seems like LiewCF website is fine from here. There are no available vulnerable i guess.</description>
		<content:encoded><![CDATA[<p>Less poeple would know how to use Linux but probably out there, some will do it. The exploit could only be run from either any sort of linux console. Perl *.php <a href="http://" rel="nofollow">http://</a>*.com /dir port &#8220;uname -a&#8221; and seems like LiewCF website is fine from here. There are no available vulnerable i guess.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: geckoseiya</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11817</link>
		<dc:creator>geckoseiya</dc:creator>
		<pubDate>Fri, 12 Aug 2005 22:19:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11817</guid>
		<description>LOL</description>
		<content:encoded><![CDATA[<p>LOL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uzyn</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11814</link>
		<dc:creator>uzyn</dc:creator>
		<pubDate>Fri, 12 Aug 2005 18:55:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11814</guid>
		<description>Err... if you don't mind... my name is uzyn. not uync.

Thanks.</description>
		<content:encoded><![CDATA[<p>Err&#8230; if you don&#8217;t mind&#8230; my name is uzyn. not uync.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uzyn.com</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11813</link>
		<dc:creator>uzyn.com</dc:creator>
		<pubDate>Fri, 12 Aug 2005 18:50:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11813</guid>
		<description>&lt;strong&gt;Wordpress Exploit: How to Secure Yourself&lt;/strong&gt;

	There&#8217;s a newly discovered Wordpress exploit that the Wordpress team did not get in time to fix yet. Basically, what that means is that virtually almost all Wordpress-powered blogs are vulnerable to the attack. 
	RTFA, there&#8217;s even the cod...</description>
		<content:encoded><![CDATA[<p><strong>Wordpress Exploit: How to Secure Yourself</strong></p>
<p>	There&#8217;s a newly discovered Wordpress exploit that the Wordpress team did not get in time to fix yet. Basically, what that means is that virtually almost all Wordpress-powered blogs are vulnerable to the attack.<br />
	RTFA, there&#8217;s even the cod&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LcF</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11812</link>
		<dc:creator>LcF</dc:creator>
		<pubDate>Fri, 12 Aug 2005 18:39:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11812</guid>
		<description>thank you for the advice. I was only want to make more people aware of it. Now I think many WP blogger will be protected because of your tips. Thank you. :)</description>
		<content:encoded><![CDATA[<p>thank you for the advice. I was only want to make more people aware of it. Now I think many WP blogger will be protected because of your tips. Thank you. <img src='http://www.liewcf.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uzyn</title>
		<link>http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/#comment-11811</link>
		<dc:creator>uzyn</dc:creator>
		<pubDate>Fri, 12 Aug 2005 18:24:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.liewcf.com/blog/?p=1688#comment-11811</guid>
		<description>Just another advice, when you know that your site is vulnerable, you don't post code for people to hack your own site.

That's like leaving your house key at the door knob.</description>
		<content:encoded><![CDATA[<p>Just another advice, when you know that your site is vulnerable, you don&#8217;t post code for people to hack your own site.</p>
<p>That&#8217;s like leaving your house key at the door knob.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
