<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Oracle attack on Wordpress</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Sun, 27 Jul 2008 09:21:13 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: westi</title>
		<link>http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/#comment-605</link>
		<dc:creator>westi</dc:creator>
		<pubDate>Fri, 23 Jun 2006 09:15:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/#comment-605</guid>
		<description>The caching system at fault was disabled by default in 2.0.2 and 2.0.1 as well it was only enabled by default in the 2.0 release.

The fix in 2.0.3 for the cache removes the ability for any attack on the caching system giving you the ability to put executable code in the cache files and the serialized data is now base64 encoded and placed inside a multi line php comment.</description>
		<content:encoded><![CDATA[<p>The caching system at fault was disabled by default in 2.0.2 and 2.0.1 as well it was only enabled by default in the 2.0 release.</p>
<p>The fix in 2.0.3 for the cache removes the ability for any attack on the caching system giving you the ability to put executable code in the cache files and the serialized data is now base64 encoded and placed inside a multi line php comment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Purvis</title>
		<link>http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/#comment-601</link>
		<dc:creator>Mike Purvis</dc:creator>
		<pubDate>Thu, 22 Jun 2006 19:10:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/#comment-601</guid>
		<description>Rather than commenting out the entire file, couldn't you just put  as the first line in each?</description>
		<content:encoded><![CDATA[<p>Rather than commenting out the entire file, couldn&#8217;t you just put  as the first line in each?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Chait</title>
		<link>http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/#comment-600</link>
		<dc:creator>David Chait</dc:creator>
		<pubDate>Thu, 22 Jun 2006 19:04:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/06/22/oracle-attack-on-wordpress/#comment-600</guid>
		<description>Good analysis.  Obviously shows that embedding passwords into lesser hashes isn't always a good idea. ;)

Also, it would have been good to point out that the caching system at fault is disabled in 2.0.4, and should never have been defaulting enabled given it only helps a fraction of a percent of the WP population.  Only an expert admin would want/need to activate it.  Not only does it open security issues, but it also can be 'buggy' and overload certain server configs.</description>
		<content:encoded><![CDATA[<p>Good analysis.  Obviously shows that embedding passwords into lesser hashes isn&#8217;t always a good idea. <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Also, it would have been good to point out that the caching system at fault is disabled in 2.0.4, and should never have been defaulting enabled given it only helps a fraction of a percent of the WP population.  Only an expert admin would want/need to activate it.  Not only does it open security issues, but it also can be &#8216;buggy&#8217; and overload certain server configs.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
