<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Sucuri</title>
	<atom:link href="http://blog.sucuri.net/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.sucuri.net</link>
	<description>Protect Your Interwebs</description>
	<lastBuildDate>Sat, 21 Jan 2012 23:06:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on DreamHost Security Issue Prompts FTP Password Resets by Dreamhost hacked, mass password-reset issued &#124; ZDNet</title>
		<link>http://blog.sucuri.net/2012/01/dreamhost-security-issue-prompts-ftp-password-resets.html/comment-page-1#comment-3028</link>
		<dc:creator>Dreamhost hacked, mass password-reset issued &#124; ZDNet</dc:creator>
		<pubDate>Sat, 21 Jan 2012 23:06:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=3106#comment-3028</guid>
		<description>[...] Blog, the company has detected a security breach at one of their database servers.  According to a blog post at DreamHost Status Blog, the company has detected a security breach in one of their database [...]</description>
		<content:encoded><![CDATA[<p>[...] Blog, the company has detected a security breach at one of their database servers.  According to a blog post at DreamHost Status Blog, the company has detected a security breach in one of their database [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on GoDaddy store your passwords in clear-text and may try to SSH to your VPS without permission by Experiences with using GoDaddy, Linux Web Hosting &#124; The (Unorganized) Musings of a Computer Scientist</title>
		<link>http://blog.sucuri.net/2010/02/godaddy-store-your-passwords-in-clear-text-and-may-try-to-ssh-to-your-vps-without-permission.html/comment-page-1#comment-3025</link>
		<dc:creator>Experiences with using GoDaddy, Linux Web Hosting &#124; The (Unorganized) Musings of a Computer Scientist</dc:creator>
		<pubDate>Sun, 15 Jan 2012 05:05:19 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=61#comment-3025</guid>
		<description>[...] I first tried to accomplish goal #2 &#8212; the first thing I learned was that SSH functionality is an &#8216;opt-in&#8217; program. In other words, you have to explicitly &#8216;activate&#8217; the feature (instructions on how to do this are here: How to Enable SSH Access to your GoDaddy Hosting Account). Before I went ahead and pushed the Button, I did a Google search on any security implications of allowing SSH access (sorry, it&#8217;s the Computer Security in me!). Luckily, nothing glaring popped out in the search results &#8212; though, the following article did provide an amusing read: GoDaddy store your passwords in clear-text and may try to SSH to your VPS without permission. [...]</description>
		<content:encoded><![CDATA[<p>[...] I first tried to accomplish goal #2 &#8212; the first thing I learned was that SSH functionality is an &#8216;opt-in&#8217; program. In other words, you have to explicitly &#8216;activate&#8217; the feature (instructions on how to do this are here: How to Enable SSH Access to your GoDaddy Hosting Account). Before I went ahead and pushed the Button, I did a Google search on any security implications of allowing SSH access (sorry, it&#8217;s the Computer Security in me!). Luckily, nothing glaring popped out in the search results &#8212; though, the following article did provide an amusing read: GoDaddy store your passwords in clear-text and may try to SSH to your VPS without permission. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Timthumb.php Mass Infection &#8211; Aftermath &#8211; Part I by &#187; Wordpress Security Best Practices &#38; Plugins</title>
		<link>http://blog.sucuri.net/2011/10/timthumb-php-mass-infection-aftermath-part-i.html/comment-page-1#comment-3023</link>
		<dc:creator>&#187; Wordpress Security Best Practices &#38; Plugins</dc:creator>
		<pubDate>Sat, 14 Jan 2012 01:35:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=2852#comment-3023</guid>
		<description>[...] the vulnerability on TimThumb was released (0-day) last year in early August it is estimated that a couple of million wordpress sites got compromised. This vulnerability would allow the arbitrary upload of files to a [...]</description>
		<content:encoded><![CDATA[<p>[...] the vulnerability on TimThumb was released (0-day) last year in early August it is estimated that a couple of million wordpress sites got compromised. This vulnerability would allow the arbitrary upload of files to a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WP-phpmyadmin WordPress plugin &#8211; Delete it now by WordPress.org repository will not show plugins older than 2 years</title>
		<link>http://blog.sucuri.net/2011/06/wp-phpmyadmin-wordpress-plugin-delete-it-now.html/comment-page-1#comment-3021</link>
		<dc:creator>WordPress.org repository will not show plugins older than 2 years</dc:creator>
		<pubDate>Fri, 13 Jan 2012 18:25:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=2231#comment-3021</guid>
		<description>[...] older than 5.2, and 95% of websites are using some version of mySQL 5.David Dede from Sucuri.net tells us as an example of &#8216;security&#8217; that a plugin called &#8220;wp-phpmyadmin&#8221; was [...]</description>
		<content:encoded><![CDATA[<p>[...] older than 5.2, and 95% of websites are using some version of mySQL 5.David Dede from Sucuri.net tells us as an example of &#8216;security&#8217; that a plugin called &#8220;wp-phpmyadmin&#8221; was [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cleaning up an infected website &#8211; Part I: WordPress and the Pharma Hack by Wordpress News - The Best WordPress Tips and Tutorials of 2011Wordpress News</title>
		<link>http://blog.sucuri.net/2011/02/cleaning-up-an-infected-web-site-part-i-wordpress-and-the-pharma-hack.html/comment-page-1#comment-3018</link>
		<dc:creator>Wordpress News - The Best WordPress Tips and Tutorials of 2011Wordpress News</dc:creator>
		<pubDate>Fri, 06 Jan 2012 12:01:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=1518#comment-3018</guid>
		<description>[...] Cleaning up an infected website – Part I: WordPress and the Pharma Hack [...]</description>
		<content:encoded><![CDATA[<p>[...] Cleaning up an infected website – Part I: WordPress and the Pharma Hack [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Timthumb Security Vulnerability &#8211; List of Themes by TimThumb.php Sicherheits-Update</title>
		<link>http://blog.sucuri.net/2011/08/timthumb-security-vulnerability-list-of-themes-including-it.html/comment-page-1#comment-3016</link>
		<dc:creator>TimThumb.php Sicherheits-Update</dc:creator>
		<pubDate>Thu, 05 Jan 2012 12:42:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=2390#comment-3016</guid>
		<description>[...] vor. Nahezu jeder, der eine Version vor dem 1. August 2011 installiert hat, ist verwundbar. Unter Timthumb Security Vulnerability – List of Themes findet man eine unvollständige Auflistung freier Themes, in denen TimThumb zum Einsatz kommt. [...]</description>
		<content:encoded><![CDATA[<p>[...] vor. Nahezu jeder, der eine Version vor dem 1. August 2011 installiert hat, ist verwundbar. Unter Timthumb Security Vulnerability – List of Themes findet man eine unvollständige Auflistung freier Themes, in denen TimThumb zum Einsatz kommt. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WordPress 3.3 XSS Vulnerability Patched (3.3.1 Released) by A Free wordpress newsletter &#187; WordPress 3.3.1 is available, ready for your upgradin’</title>
		<link>http://blog.sucuri.net/2012/01/wordpress-3-3-xss-vulnerability-patched-3-3-1-released.html/comment-page-1#comment-3015</link>
		<dc:creator>A Free wordpress newsletter &#187; WordPress 3.3.1 is available, ready for your upgradin’</dc:creator>
		<pubDate>Thu, 05 Jan 2012 03:13:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=3003#comment-3015</guid>
		<description>[...] just what the security issue was, though I do trust the folks at Sucuri when they refer to it as not a &#8220;serious vulnerability.&#8221; Even so, you should go ahead and update your sites today. Go on, you know you want [...]</description>
		<content:encoded><![CDATA[<p>[...] just what the security issue was, though I do trust the folks at Sucuri when they refer to it as not a &#8220;serious vulnerability.&#8221; Even so, you should go ahead and update your sites today. Go on, you know you want [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WordPress 3.3 XSS Vulnerability Patched (3.3.1 Released) by wp-coder.net &#187; WordPress 3.3.1 is available, ready for your upgradin’</title>
		<link>http://blog.sucuri.net/2012/01/wordpress-3-3-xss-vulnerability-patched-3-3-1-released.html/comment-page-1#comment-3014</link>
		<dc:creator>wp-coder.net &#187; WordPress 3.3.1 is available, ready for your upgradin’</dc:creator>
		<pubDate>Thu, 05 Jan 2012 03:04:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=3003#comment-3014</guid>
		<description>[...] just what the security issue was, though I do trust the folks at Sucuri when they refer to it as not a &#8220;serious vulnerability.&#8221; Even so, you should go ahead and update your sites today. Go on, you know you want [...]</description>
		<content:encoded><![CDATA[<p>[...] just what the security issue was, though I do trust the folks at Sucuri when they refer to it as not a &#8220;serious vulnerability.&#8221; Even so, you should go ahead and update your sites today. Go on, you know you want [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cleaning up an infected website &#8211; Part I: WordPress and the Pharma Hack by WordPress: The Best of 2011 and Future Predictions &#124; Wptuts+</title>
		<link>http://blog.sucuri.net/2011/02/cleaning-up-an-infected-web-site-part-i-wordpress-and-the-pharma-hack.html/comment-page-1#comment-3012</link>
		<dc:creator>WordPress: The Best of 2011 and Future Predictions &#124; Wptuts+</dc:creator>
		<pubDate>Mon, 02 Jan 2012 18:01:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=1518#comment-3012</guid>
		<description>[...] Tutorial Link [...]</description>
		<content:encoded><![CDATA[<p>[...] Tutorial Link [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Automattic / WordPress hacked &#8211; Security incident by 2011: Year of the Data Breach &#171; CCSK Guide</title>
		<link>http://blog.sucuri.net/2011/04/automattic-wordpress-compromise-security-incident.html/comment-page-1#comment-3010</link>
		<dc:creator>2011: Year of the Data Breach &#171; CCSK Guide</dc:creator>
		<pubDate>Wed, 28 Dec 2011 12:02:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.sucuri.net/?p=1940#comment-3010</guid>
		<description>[...] Automattic &amp; WordPress (April 14, 2011) – Attackers were able to hack a number of servers run by Automattic, the company responsible for maintenance and augmentation of WordPress code. With root-level access, the attackers stole the WordPress source code, the majority of which is open source, but some is proprietary. It’s suspected that partner code was also accessed. [...]</description>
		<content:encoded><![CDATA[<p>[...] Automattic &amp; WordPress (April 14, 2011) – Attackers were able to hack a number of servers run by Automattic, the company responsible for maintenance and augmentation of WordPress code. With root-level access, the attackers stole the WordPress source code, the majority of which is open source, but some is proprietary. It’s suspected that partner code was also accessed. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

