<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress &lt;= 2.8.3 Remote admin reset password</title>
	<atom:link href="http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:40:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: My final Wordpress security solution</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-2976</link>
		<dc:creator>My final Wordpress security solution</dc:creator>
		<pubDate>Tue, 06 Dec 2011 10:35:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-2976</guid>
		<description>[...] Here&#039;s more instruction on how hackers might be working:&#160;http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html [...]</description>
		<content:encoded><![CDATA[<p>[...] Here&#039;s more instruction on how hackers might be working:&nbsp;<a href="http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html" rel="nofollow">http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SEO Tips</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-835</link>
		<dc:creator>SEO Tips</dc:creator>
		<pubDate>Wed, 16 Sep 2009 23:38:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-835</guid>
		<description>It&#039;s helpful. Thanks for great tips</description>
		<content:encoded><![CDATA[<p>It&#39;s helpful. Thanks for great tips</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lane</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-836</link>
		<dc:creator>Lane</dc:creator>
		<pubDate>Tue, 11 Aug 2009 20:20:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-836</guid>
		<description>OK, I think I see how it works now. I have a blog running 2.8.3. At login, I click &quot;Lost your password?&quot; and am presented with a page where I can enter either a username or an email. So entering &quot;admin&quot; would reset the password without further action? Weird!&lt;br /&gt;&lt;br /&gt;I&#039;ve made the Line 190 edit and will start copying it to my blogs. Thanks, Securi, for this post.</description>
		<content:encoded><![CDATA[<p>OK, I think I see how it works now. I have a blog running 2.8.3. At login, I click &quot;Lost your password?&quot; and am presented with a page where I can enter either a username or an email. So entering &quot;admin&quot; would reset the password without further action? Weird!</p>
<p>I&#39;ve made the Line 190 edit and will start copying it to my blogs. Thanks, Securi, for this post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-837</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 11 Aug 2009 19:34:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-837</guid>
		<description>It&#039;s telling the amount of kiddies trying this and failing. I can attest that it works, as I had my own blog&#039;s admin pass changed through an anon proxy, so it seems there are people actively exploiting this. I just fixed mine through the line 190 edit - thanks!</description>
		<content:encoded><![CDATA[<p>It&#39;s telling the amount of kiddies trying this and failing. I can attest that it works, as I had my own blog&#39;s admin pass changed through an anon proxy, so it seems there are people actively exploiting this. I just fixed mine through the line 190 edit &#8211; thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: http://sucuri.net</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-838</link>
		<dc:creator>http://sucuri.net</dc:creator>
		<pubDate>Tue, 11 Aug 2009 17:27:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-838</guid>
		<description>Lane:&lt;br /&gt;&lt;br /&gt;It only works on 2.8.x versions. It gives you the option to reset using the user name (admin only) or the email...</description>
		<content:encoded><![CDATA[<p>Lane:</p>
<p>It only works on 2.8.x versions. It gives you the option to reset using the user name (admin only) or the email&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lane</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-839</link>
		<dc:creator>Lane</dc:creator>
		<pubDate>Tue, 11 Aug 2009 17:10:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-839</guid>
		<description>I tried the function, and it sends an email to the registered user. Unless the registered user chooses to change the password it remains the same.</description>
		<content:encoded><![CDATA[<p>I tried the function, and it sends an email to the registered user. Unless the registered user chooses to change the password it remains the same.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BlackTigerX</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-840</link>
		<dc:creator>BlackTigerX</dc:creator>
		<pubDate>Tue, 11 Aug 2009 17:05:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-840</guid>
		<description>the hack is not about getting access or getting the passwod at all, just changing it</description>
		<content:encoded><![CDATA[<p>the hack is not about getting access or getting the passwod at all, just changing it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lane</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-841</link>
		<dc:creator>Lane</dc:creator>
		<pubDate>Tue, 11 Aug 2009 12:59:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-841</guid>
		<description>I don&#039;t get it. You have to supply the email address that belongs to a registered user. Where it the hacker going to get that?</description>
		<content:encoded><![CDATA[<p>I don&#39;t get it. You have to supply the email address that belongs to a registered user. Where it the hacker going to get that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-842</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 11 Aug 2009 12:56:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-842</guid>
		<description>Only works on 2.8.x versions.</description>
		<content:encoded><![CDATA[<p>Only works on 2.8.x versions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: http://sucuri.net</title>
		<link>http://blog.sucuri.net/2009/08/wordpress-2-8-3-remote-admin-reset-password.html/comment-page-1#comment-843</link>
		<dc:creator>http://sucuri.net</dc:creator>
		<pubDate>Tue, 11 Aug 2009 12:53:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=85#comment-843</guid>
		<description>I was testing it over here and noticed that only works on Wordpress 2.8.0, 2.8.1, 2.8.2 and 2.8.3...&lt;br /&gt;&lt;br /&gt;I guess they didn&#039;t test on &lt;= 2.7 versions.</description>
		<content:encoded><![CDATA[<p>I was testing it over here and noticed that only works on WordPress 2.8.0, 2.8.1, 2.8.2 and 2.8.3&#8230;</p>
<p>I guess they didn&#39;t test on <= 2.7 versions.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

