<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: WordPress Exploits and Patches</title>
	<atom:link href="http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/</link>
	<description></description>
	<pubDate>Sat, 10 Jan 2009 00:15:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: banane</title>
		<link>http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/comment-page-1/#comment-75148</link>
		<dc:creator>banane</dc:creator>
		<pubDate>Sun, 16 Dec 2007 05:04:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/#comment-75148</guid>
		<description>Oh- thanks Matt! It's not in the footer, but at the end of a post, the individual post content, which users can't see, you can only see if you "view code" in the interface. I will change the db password, seems like the best idea.</description>
		<content:encoded><![CDATA[<p>Oh- thanks Matt! It&#8217;s not in the footer, but at the end of a post, the individual post content, which users can&#8217;t see, you can only see if you &#8220;view code&#8221; in the interface. I will change the db password, seems like the best idea.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/comment-page-1/#comment-75113</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Sun, 16 Dec 2007 02:28:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/#comment-75113</guid>
		<description>If there is spammy HTML in the footer.php of a theme, it's unlikely that it has anything to do with the cookie thing, it's more likely file permissions and/or an old XML-RPC problem. The cookie thing only applies to you if they've already read your database directly, which is not possible if you're on a secure version, and changing your password protects you if they have. I wouldn't attempt to apply the phpass patch by hand.</description>
		<content:encoded><![CDATA[<p>If there is spammy HTML in the footer.php of a theme, it&#8217;s unlikely that it has anything to do with the cookie thing, it&#8217;s more likely file permissions and/or an old XML-RPC problem. The cookie thing only applies to you if they&#8217;ve already read your database directly, which is not possible if you&#8217;re on a secure version, and changing your password protects you if they have. I wouldn&#8217;t attempt to apply the phpass patch by hand.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
