<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Diary of Michael Daw &#187; Alerts</title>
	<atom:link href="http://michaeldaw.org/category/alerts/feed" rel="self" type="application/rss+xml" />
	<link>http://michaeldaw.org</link>
	<description>Weekly humour</description>
	<lastBuildDate>Thu, 21 May 2009 15:45:22 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress Adsense Deluxe Vulnerability</title>
		<link>http://michaeldaw.org/alerts/alerts-200507</link>
		<comments>http://michaeldaw.org/alerts/alerts-200507#comments</comments>
		<pubDate>Sun, 20 May 2007 00:08:44 +0000</pubDate>
		<dc:creator>dk</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://michaeldaw.org/alerts/alerts-200507/</guid>
		<description><![CDATA[David Kierznowski of Operation n has discovered some serious flaws in the WordPress Adsense Deluxe plugin as part of the WordPress Angel Project. The vulnerability(s) affect all versions.

This vulnerability reminds me of the the old Hacker movies, where a worm is released that steals random pennys from unsuspecting victims. This vulnerability is the closest I [...]]]></description>
			<content:encoded><![CDATA[<p>David Kierznowski of <a href="http://michaeldaw.org">Operation n</a> has discovered some serious flaws in the WordPress Adsense Deluxe plugin as part of the <a href="http://michaeldaw.org/wp-angelproject/">WordPress Angel Project</a>. The vulnerability(s) affect all versions.</p>
<p><b><i><br />
This vulnerability reminds me of the the old Hacker movies, where a worm is released that steals random pennys from unsuspecting victims. This vulnerability is the closest I have seen to this scenario.<br />
</i></b></p>
<p>The vendor has been notified, and more information regarding the vulnerability will be released after 30 days or until such a time as the author feels that WordPress users have had a chance to upgrade.</p>
<p>Unfortunately, the developer has not gotten back to me, and as many blogs use this plugin as a source of income, I have gone ahead and made the necessary changes myself as a temporary solution. Please note this is an unofficial release. Hopefully the vendor will verify the changes and make an official release shortly.</p>
<p>As with any plugin, please make sure you have made a backup before downloading and installing this.</p>
<p>Download <a href="http://michaeldaw.org/projects/adsense-deluxe.zip">adsense-deluxe.zip</a>.</p>
<p><!--adsense--></p>
<p>The vendor was notified: 18/05/07<br />
Response received: None as yet<br />
Fix received: <a href="http://michaeldaw.org/projects/adsense-deluxe.zip">Temporary fix</a> released as part of the <a href="http://michaeldaw.org/wp-angelproject/">WordPress Angel Project</a>.</p>
<p>References:</p>
<ul>
<li><a href="http://michaeldaw.org/papers/securing_wp_plugins/">Writing Secure WordPress Plugins</a></l>
</ul>
<p><a href="http://store.templatemonster.com?aff=dkza"><img src="http://www.templatehelp.com/banners/1/wps_promote_aff_468x60.gif" width="468" height="60" border="0" alt="" ></a></p>
]]></content:encoded>
			<wfw:commentRss>http://michaeldaw.org/alerts/alerts-200507/feed</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
		<item>
		<title>WordPress Akismet Fixed</title>
		<link>http://michaeldaw.org/alerts/alerts-140507-1</link>
		<comments>http://michaeldaw.org/alerts/alerts-140507-1#comments</comments>
		<pubDate>Mon, 14 May 2007 20:44:37 +0000</pubDate>
		<dc:creator>dk</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://michaeldaw.org/alerts/alerts-140507-1/</guid>
		<description><![CDATA[
This is a quick alert to let everyone know that a new version of Akismet has been released to address the recent security vulnerability. As usual, I was very impressed with the speed and accuracy of WordPress in addressing this issue, in particular Ryan Boren and Matt Mullenweg.
For details on downloading the latest WordPress Akismet [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://store.templatemonster.com?aff=dkza"><img src="http://www.templatehelp.com/banners/1/wps_promote_aff_468x60.gif" width="468" height="60" border="0" alt="" ></a></p>
<p>This is a quick alert to let everyone know that a new version of Akismet has been released to address the recent security vulnerability. As usual, I was very impressed with the speed and accuracy of WordPress in addressing this issue, in particular <a href="http://automattic.com">Ryan Boren</a> and <a href="http://automattic.com">Matt Mullenweg</a>.</p>
<p>For details on downloading the latest WordPress Akismet Plugin, please see: <a href="http://michaeldaw.org/alerts/alert-140507/">WordPress 2.1.3 Akismet Vulnerability</a>.</p>
<p>I will wait a period of time to allow everyone to upgrade before releasing the full advisory, so keep an eye out for it.</p>
]]></content:encoded>
			<wfw:commentRss>http://michaeldaw.org/alerts/alerts-140507-1/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>WordPress 2.1.3 Akismet Vulnerability</title>
		<link>http://michaeldaw.org/alerts/alert-140507</link>
		<comments>http://michaeldaw.org/alerts/alert-140507#comments</comments>
		<pubDate>Mon, 14 May 2007 01:17:30 +0000</pubDate>
		<dc:creator>dk</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://michaeldaw.org/alerts/alert-140507/</guid>
		<description><![CDATA[
Updates:
14/05/07 Added link to new version
David Kierznowski of Operation n has discovered a serious flaw in the Akismet anti-spam plugin that comes by default with the latest version of WordPress (2.1.3).
It has not been confirmed as yet, but I believe this will affect all versions of the plugin. The vendor has been notified, and more [...]]]></description>
			<content:encoded><![CDATA[<p><!--adsense#mdaw_imgbanner--></p>
<p>Updates:<br />
14/05/07 Added link to new version</p>
<p><a href="">David Kierznowski</a> of <a href="http://michaeldaw.org">Operation n</a> has discovered a serious flaw in the <a href="http://akismet.com/">Akismet</a> anti-spam plugin that comes <b>by default</b> with the latest version of <a href="http://wordpress.org/download/">WordPress (2.1.3)</a>.</p>
<p>It has not been confirmed as yet, but I believe this will affect all versions of the plugin. The vendor has been notified, and more information regarding the vulnerability will be released when a suitable fix has been released.</p>
<p>I know its painful, but its recommended that you disable the <a href="http://akismet.com/">Akismet</a> plugin immediately.</p>
<p>The vendor was notified: 14/05/07<br />
Response received: 14/05/07<br />
Fix received: 14/05/07 </p>
<p>The <a href="http://dev.wp-plugins.org/browser/akismet/trunk/akismet.php?format=raw" target="_blank">Akismet v2.0.2 Download</a> upgrade has been made to address these issues and may be downloaded <a href="http://dev.wp-plugins.org/browser/akismet/trunk/akismet.php?format=raw" target="_blank">here</a>.</p>
<p><!--adsense--></p>
<p><a href="http://store.templatemonster.com?aff=dkza"><img src="http://www.templatehelp.com/banners/1/wps_promote_aff_468x60.gif" width="468" height="60" border="0" alt="" ></a></p>
]]></content:encoded>
			<wfw:commentRss>http://michaeldaw.org/alerts/alert-140507/feed</wfw:commentRss>
		<slash:comments>35</slash:comments>
		</item>
		<item>
		<title>modsecurity hack</title>
		<link>http://michaeldaw.org/alerts/130307-2</link>
		<comments>http://michaeldaw.org/alerts/130307-2#comments</comments>
		<pubDate>Tue, 13 Mar 2007 12:40:24 +0000</pubDate>
		<dc:creator>dk</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://michaeldaw.org/alerts/130307-2/</guid>
		<description><![CDATA[
Stefen Esser is has been credited in discovering a serious vulnerability in the popular open source web application firewall software, modsecurity.



When mod_security receives a request it parses it into web application parameters in a way it believes is correct. Because the way it parses the incoming data follows the rules defined in RFCs and not [...]]]></description>
			<content:encoded><![CDATA[<p>
<a href="">Stefen Esser</a> is has been credited in discovering a <a href="http://www.php-security.org/MOPB/BONUS-12-2007.html">serious vulnerability</a> in the popular open source web application firewall software, <a href="http://www.modsecurity.org">modsecurity</a>.
</p>
<p>
<i><br />
When mod_security receives a request it parses it into web application parameters in a way it believes is correct. Because the way it parses the incoming data follows the rules defined in RFCs and not the reality of how the HTTP request parsers are implemented in Perl, Python, Java, PHP there are a number of bypass vulnerabilities when the RFC and reality mismatch.<br />
</i>
</p>
<p>
Alot of legacy web applications are in it now. Thats what <a href="http://www.ivanristic.com/">Ivan Ristic</a> gets for following the RFCs, I mean who does that? :)
</p>
<p>
From what I can tell the latest version is affected and I do not know of any fix. In fact, I think it will be quite difficult to patch this as its a human weakness problem rather then a programmatical error.</p>
]]></content:encoded>
			<wfw:commentRss>http://michaeldaw.org/alerts/130307-2/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WordPress 2.0.7 Released</title>
		<link>http://michaeldaw.org/alerts/wordpress-207-released</link>
		<comments>http://michaeldaw.org/alerts/wordpress-207-released#comments</comments>
		<pubDate>Tue, 16 Jan 2007 07:25:33 +0000</pubDate>
		<dc:creator>dk</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://michaeldaw.org/alerts/wordpress-207-released/</guid>
		<description><![CDATA[Intro

A serious security vulnerability has been found in WordPress &#60;=2.0.6. This can&#8217;t be good for them as they just released 2.0.6 &#8220;11 days ago&#8221;.

Proof of Concept

http://milw0rm.com/exploits/3109

Solution

Get the latest version here.
The quicker fix here.
]]></description>
			<content:encoded><![CDATA[<h3>Intro</h3>
<p>
A serious security vulnerability has been found in WordPress &lt;=2.0.6. This can&#8217;t be good for them as they just released 2.0.6 &#8220;11 days ago&#8221;.
</p>
<h3>Proof of Concept</h3>
<p>
<a href="http://milw0rm.com/exploits/3109">http://milw0rm.com/exploits/3109</a>
</p>
<h3>Solution</h3>
<p>
Get the latest version <a href="http://wordpress.org/download/">here</a>.<br />
The quicker fix <a href="http://wordpress.org/development/2007/01/wordpress-207/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://michaeldaw.org/alerts/wordpress-207-released/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress rawurlencode Vulnerability</title>
		<link>http://michaeldaw.org/alerts/alert-150106-01</link>
		<comments>http://michaeldaw.org/alerts/alert-150106-01#comments</comments>
		<pubDate>Mon, 15 Jan 2007 07:26:50 +0000</pubDate>
		<dc:creator>dk</dc:creator>
				<category><![CDATA[Alerts]]></category>

		<guid isPermaLink="false">http://michaeldaw.org/alerts/alert-150106-01/</guid>
		<description><![CDATA[Intro

xy7 found an information disclosure vulnerability in WordPress &#60;= 2.0.6.


It looks like this vulnerability is limited to information leakage only. If you want to test your WP installation see below.

Test if you are vulnerable (most likely):
http://my_wordpress/index.php?m[]=
OR
http://my_wordpress/?m[]=
Temporary fix:

Note: Always make backups before making any changes.
As a temporary fix we ensure that the input being passed to [...]]]></description>
			<content:encoded><![CDATA[<h3>Intro</h3>
<p>
<a href="http://seclists.org/bugtraq/2007/Jan/0343.html">xy7</a> found an information disclosure vulnerability in WordPress &lt;= 2.0.6.
</p>
<p>
It looks like this vulnerability is limited to information leakage only. If you want to test your WP installation see below.
</p>
<h3>Test if you are vulnerable (most likely):</h3>
<p>http://my_wordpress/index.php?m[]=<br />
OR<br />
http://my_wordpress/?m[]=</p>
<h3>Temporary fix:</h3>
<p>
<i>Note: Always make backups before making any changes.</i><br />
As a temporary fix we ensure that the input being passed to the rawurlencode function is a string and not an array which is what is causing the problems.
</p>
<ul>
<li>edit wp-includes/classes.php</li>
<li>Go to line 1663</li>
<li>The line should look like this:<br />
if (isset($this->query_vars[$wpvar]) &#038;&#038; &#8221; != $this->query_vars[$wpvar]) { </li>
<li>Add the following (after the above-mentioned line):<br />
if(!is_string($this->query_vars[$wpvar])) {<br />
 $this->query_vars[$wpvar] = &#8216;fixed&#8217;;<br />
 }
</li>
</ul>
<h3>Summary</h3>
<p>
If I hear of <a href="http://www.wordpress.com">WordPress</a> releasing an official patch I will update this post.</p>
]]></content:encoded>
			<wfw:commentRss>http://michaeldaw.org/alerts/alert-150106-01/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
