<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Daily Gadgets, Computer, and Electronics News &#187; exploit</title>
	<atom:link href="http://www.funponsel.com/blog/tag/exploit/feed" rel="self" type="application/rss+xml" />
	<link>http://www.funponsel.com/blog</link>
	<description>Daily Gadgets, Computer, and Electronics News</description>
	<lastBuildDate>Sun, 22 Nov 2009 16:31:53 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Wordpress v1.5.1.3 Exploit</title>
		<link>http://www.funponsel.com/blog/wordpress/wordpress-v1513-exploit.html</link>
		<comments>http://www.funponsel.com/blog/wordpress/wordpress-v1513-exploit.html#comments</comments>
		<pubDate>Sun, 14 Aug 2005 10:29:02 +0000</pubDate>
		<dc:creator>cosa</dc:creator>
				<category><![CDATA[WordPress]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.funponsel.com/blog/?p=366</guid>
		<description><![CDATA[If you&#8217;re using Wordpress v1.5.1.3, you should aware of the latest exploit found on this latest Wordpress version. SecuriTeam posted this exploit on August 10th, as quoted below (via LiewCF):
A vulnerability in WordPress&#8217;s handling of incoming cookie information allows remote attackers to cause the program to execute arbitrary code if the PHP settings of register_globals [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://www.funponsel.net/images//wplogo.png" width="181" height="30" alt="WordPress Logo" title="WordPress Logo" />If you&#8217;re using <a href="http://www.wordpress.org/">Wordpress</a> v1.5.1.3, you should aware of the latest exploit found on this latest Wordpress version. SecuriTeam <a href="http://www.securiteam.com/unixfocus/5BP0G00GLK.html">posted this exploit</a> on August 10th, as quoted below (via <a href="http://www.liewcf.com/blog/archives/2005/08/wordpress-1513-remote-access-exploit/">LiewCF</a>):</p>
<blockquote><p>A vulnerability in WordPress&#8217;s handling of incoming cookie information allows remote attackers to cause the program to execute arbitrary code if the PHP settings of register_globals has been set to On.</p></blockquote>
<p><span id="more-366"></span>To protect your blog, you can choose between these 2 solution:</p>
<ol>
<li>From <a href="http://www.tamba2.org.uk/T2/archives/2005/08/13/stop-your-blog-being-hacked/">Tamba2</a>, edit <strong>.htaccess</strong> file that covered your blog and add the following line:<br />
<code>php_flag register_globals off</code></li>
<li>From <a href="http://www.kamigoroshi.net/archive/2005/08/13/771">Kamigoroshi</a>, if you&#8217;re too lazy to edit the file, just download the fix <a href="http://trac.wordpress.org/file/branches/1.5/wp-settings.php?rev=2779&#038;format=raw">here</a>, and upload it to your blog directory. It will replace <strong>wp-settings.php</strong> file.</li>
</ol>
<p>That&#8217;s it, you&#8217;re now immune to the remote attack caused by this exploit. It&#8217;s easy and take less than 5 minutes, so you should do it a.s.a.p before it&#8217;s too late :d</p>
]]></content:encoded>
			<wfw:commentRss>http://www.funponsel.com/blog/wordpress/wordpress-v1513-exploit.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
