<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Kakkoi &#187; patch</title>
	<atom:link href="http://42.kaizeku.com/taxonomy/patch//feed/" rel="self" type="application/rss+xml" />
	<link>http://42.kaizeku.com</link>
	<description>web development, software, windows tips and trick</description>
	<pubDate>Sat, 12 Jul 2008 15:10:01 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>WordPress 2.3.3 Security Release</title>
		<link>http://42.kaizeku.com/wordpress/wordpress-233-security-release/</link>
		<comments>http://42.kaizeku.com/wordpress/wordpress-233-security-release/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 06:01:34 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[patch]]></category>

		<category><![CDATA[remote+injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/wordpress-233-securities-release/</guid>
		<description><![CDATA[

Wordpress 2.3.3 fixes a few minor bugs and the debatable Wordpress 2.3.2 XMLRPC vulnerability. It took 4 months to track the XMLRPC exploit and 1 days for the patch to be release. Kudos to WordPress Developer especially Ryan &#038; Joseph Scott for these quick security release.
Wordpress 2.3.2 XMLRPC vulnerability patches by josephscott

xmlrpc.php.diff (0.7 kB) -on [...]]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img class="fl" src='http://blog.kakkoi.net/wp-content/uploads/2008/02/wordpress-small.png' alt='wordpress small logo' width="33" height="33" longdesc="http://blog.kakkoi.net/wp-content/uploads/2008/02/wordpress-small.png" /><strong>Wordpress 2.3.3</strong> fixes a few <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.3.3" class="exturl icn-r">minor bugs</a> and the debatable <a href="/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/">Wordpress 2.3.2 XMLRPC vulnerability</a>. It took 4 months to track the <em><a href="http://trac.wordpress.org/ticket/5313" class="exturl icn-r">XMLRPC exploit</a></em> and 1 days for the patch to be release. Kudos to WordPress Developer especially <span class="vcard"><a href="http://boren.nu/" class="url fn microformat icn-l">Ryan</a></span> &#038; <span class="vcard"><a href="http://joseph.randomnetworks.com/" class="url fn microformat icn-l"><span class="given-name">Joseph</span> <span class="family-name">Scott</span></a></span> for these quick security release.</p>
<h2>Wordpress 2.3.2 XMLRPC vulnerability patches by josephscott</h2>
<ul>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/xmlrpc.php.diff">xmlrpc.php.diff</a> (0.7 kB) -on 02/02/08 16:53:22.</li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/xmlrpc.php.2.diff">xmlrpc.php.2.diff</a> (3.2 kB) - on 02/03/08 04:49:26.</li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/attachment/ticket/5313/2.3-xmlrpc.php.diff">2.3-xmlrpc.php.diff</a> (3.2 kB) - on 02/04/08 18:48:23 (2.3.3).</li>
</ul>
<p><span id="more-174"></span></p>
<h2>External Links</h2>
<ul>
<li><a class="exturl icn-r" href="http://wordpress.org/download/">Wordpress 2.3.3 Download</a></li>
<li><a class="exturl icn-r" href="http://wordpress.org/development/2008/02/wordpress-233/">Wordpress Development Blog</a></li>
<li><a class="exturl icn-r" href="http://trac.wordpress.org/milestone/2.3.3">Wordpress 2.3.3 Milestone</a></li>
<li><a class="exturl icn-r" href="http://www.village-idiot.org/archives/2008/02/04/wordpress-2-3-3/">village-idiot.org &rarr; WordPress 2.3.3 List of changed files</a> <small>(download available)</small></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/wordpress-233-security-release/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wordpress 2.3.2 XMLRPC Exploit Unofficial Patch</title>
		<link>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</link>
		<comments>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 21:32:51 +0000</pubDate>
		<dc:creator>Noah Ark</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[WordPress]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[0-day]]></category>

		<category><![CDATA[metaWeblog]]></category>

		<category><![CDATA[patch]]></category>

		<category><![CDATA[xmlrpc]]></category>

		<guid isPermaLink="false">http://blog.kakkoi.net/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/</guid>
		<description><![CDATA[This issue has been raised 4 months ago (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WP Developer decide to stop arguing on the mailing list and came out with WordPress securities fix release (maybe for v 2.3.5) You might want to try this “Temporary” workaround suggest by SecuriTeam - Paul (Yabba) Jones.]]></description>
			<content:encoded><![CDATA[
<!-- google_ad_section_start -->
<p><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.thumbnail.jpg' alt='this is relevant to my interest lolcat' width='128' height='100' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/2000455272489756911_rs.jpg' />This issue has been raised <a href="http://wordpress.org/support/topic/134928/">4 months ago</a> (october 2007). Certainly this is one of BadPress Ticketing Problems. Until WordPress Developer release Official securities fix (v 2.3.2.1 || 2.3.5 ?? ) You might want to try this &#8220;debatable&#8221; patch by <a href="http://www.securiteam.com" class="exturl icn-r">SecuriTeam</a> - Paul (Yabba) Jones. </p>
<p class="notice cb mgt">Note: <span class="vcard"><a class="url fn microformat icn-r" href="http://ma.tt" title="Matt Mullenweg - PhotoMatt"><span class="given-name">Matt</span> <span class="family-name">Mullenweg</span></a></span> &#038; the <a href="http://lists.automattic.com/mailman/listinfo/wp-hackers">WP-Hackers</a> is against secureTeam &#8220;hasty-patch&#8221; and their <abbr title="Proof of Concept">POC</abbr> release. <small><a href="http://comox.textdrive.com/pipermail/wp-hackers/2008-February/017544" class="exturl icn-r">[wp-hackers] xmlrpc issue or no?</a></small>.</p>
<p><em>Excerpt from Wordpress Support Forum &raquo; <a href="http://wordpress.org/support/topic/134928/">iframe injection problem?</a></em></p>
<blockquote cite="http://wordpress.org/support/topic/134928/page/3#post-686803"><p class="quote"><a href="http://wordpress.org/support/topic/134928/page/3#post-686803" class="exturl icn-r">Matt Mullenweg</a> &rarr; [...] I would rather not have people think they&#8217;re safe and really not be, and there is a release coming shortly anyway. [...]<br />
If anyone is scared and wants a fix NOW, they should either turn off registration (which is off by default) or delete xmlrpc.php. <small>~ Feb 3, 2008</small> </p>
</blockquote>
<p><span id="more-170"></span></p>
<p class="notice"><a href="http://blog.kakkoi.net/wordpress/wordpress-233-security-release/">WordPress 2.3.3</a> has been release it&#8217;s advice not to try this patches</p>
<h2>Patch xmlrpc.php via WordPress Admin</h2>
<ol class="xoxo">
<li> Login to Wordpress Admin</li>
<li class="cf"><a href='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' title='manage-files-xmlrpc.png' class="rr fr"><img src='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.thumbnail.png' alt='manage-files-xmlrpc.png' width='128' height='64' longdesc='http://blog.kakkoi.net/wp-content/uploads/2008/02/manage-files-xmlrpc.png' /></a> Goto Manage &raquo; Files then scroll down to &#8220;Other Files&#8221; sections, type in <em>xmlrpc.php</em>. otherwise type the following URL in your browser address-bar &darr;
<pre>mydomain.com/wp-admin/templates.php?file=xmlrpc.php&#038;submit=Edit+file+%C2%BB</pre>
</li>
<li>Find the following code (around Line <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">1151</a> - 1203 ) within <a href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#1123" class="exturl icn-r">wp_xmlrpc_server::mw_editPost()</a> class methods &darr;
<pre>if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )</pre>
</li>
<li>Replace with
<pre class="prebox">
//if ( ( 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
 if ( ( 1 || 'post' == $post_type ) &#038;&#038; !current_user_can('edit_post', $post_ID) )
</pre>
<p>saved.
</li>
<li>Disabled New User Registrations for temporary.</li>
</ol>
<h2>External Links</h2>
<ul>
<li><a href="http://wordpress.org/support/topic/134928/" class="exturl icn-r">Wordpress Support Forum &rarr; iframe injection problem?</a></li>
<li><a href="http://www.securiteam.com/unixfocus/5HP010KNFK.html#ArticleTABLE" class="exturl icn-r">SecuriTeam &rarr; WordPress 2.3.2 XMLRPC Vulnerability <abbr title="proof of concept">POC</abbr></a>
<li><a href="http://en.wikipedia.org/wiki/XML-RPC" class="exturl icn-r">Wikipedia XML-RPC</a></li>
<li><a href="http://www.google.com/search?hl=en&amp;q=Wordpress+XML-RPC+Vulnerabilities" class="exturl icn-r">Google &rarr; Wordpress XML-RPC Vulnerabilities</a></li>
<li><a class="exturl icn-r" href="http://xref.redalt.com/wptrunk/xmlrpc.php.source.htm#l1151">PHPXREF wp-trunk xmlrpc source</a></li>
</ul>
<!-- google_ad_section_end -->
]]></content:encoded>
			<wfw:commentRss>http://42.kaizeku.com/wordpress/wordpress-232-xmlrpc-exploit-unofficial-patch/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
