<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wordpress Plugins Security Flaw – A Blackhats Dream</title>
	<atom:link href="http://explicitly.me/wordpress-plugins-secuirty-flaw-%E2%80%93-a-blackhats-dream/feed" rel="self" type="application/rss+xml" />
	<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream</link>
	<description>Rishil&#039;s Home on the Web</description>
	<lastBuildDate>Wed, 19 Jun 2013 00:17:59 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Paul Anthony</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-8081</link>
		<dc:creator>Paul Anthony</dc:creator>
		<pubDate>Sun, 21 Aug 2011 17:38:39 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-8081</guid>
		<description>Rishil,

I think Donncha has a security plugin - sweeps your code looking for Base64 and other various nasties.

http://ocaoimh.ie/exploit-scanner/

Well worth a look

Paul.</description>
		<content:encoded><![CDATA[<p>Rishil,</p>
<p>I think Donncha has a security plugin &#8211; sweeps your code looking for Base64 and other various nasties.</p>
<p><a href="http://ocaoimh.ie/exploit-scanner/" rel="nofollow">http://ocaoimh.ie/exploit-scanner/</a></p>
<p>Well worth a look</p>
<p>Paul.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rishil</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4918</link>
		<dc:creator>rishil</dc:creator>
		<pubDate>Mon, 18 Apr 2011 17:10:24 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4918</guid>
		<description>Hey Otto, thanks for dropping by. Rest assured, anything dodgy we find will get to you guys ;) 
I just wanted to highlight that stuff like this does and can happen.</description>
		<content:encoded><![CDATA[<p>Hey Otto, thanks for dropping by. Rest assured, anything dodgy we find will get to you guys <img src='http://explicitly.me/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
I just wanted to highlight that stuff like this does and can happen.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Otto</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4915</link>
		<dc:creator>Otto</dc:creator>
		<pubDate>Mon, 18 Apr 2011 16:49:09 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4915</guid>
		<description>For what it&#039;s worth, while the wordpress.org plugin repository isn&#039;t reviewed or monitored for bad plugins, we do have a very low tolerance for that sort of thing. 

If you find a plugin doing &quot;bad&quot; things (with a very liberal definition of &quot;bad&quot;), then emailing plugins@wordpress.org about it will get it looked at, possibly updated to remove the bad stuff from any existing installs (if there are any), as well as get the plugin developer burned and crucified on the &quot;no-spammer&quot; altar. Mark R (the plugins guy) has a very, very low tolerance and an unforgiving nature about that sort of thing.

We can&#039;t control what plugins are released elsewhere, but we do have complete control over what&#039;s on wordpress.org and will take whatever steps are necessary to remove spammy BS.

A plugin reviewer team would be nice, but it&#039;s a big, big job if you sit down and think about it. We&#039;re only just now getting into stride with the theme reviewer system, implementing a plugin review system is an order of magnitude more difficult.</description>
		<content:encoded><![CDATA[<p>For what it&#8217;s worth, while the wordpress.org plugin repository isn&#8217;t reviewed or monitored for bad plugins, we do have a very low tolerance for that sort of thing. </p>
<p>If you find a plugin doing &#8220;bad&#8221; things (with a very liberal definition of &#8220;bad&#8221;), then emailing <a href="mailto:plugins@wordpress.org">plugins@wordpress.org</a> about it will get it looked at, possibly updated to remove the bad stuff from any existing installs (if there are any), as well as get the plugin developer burned and crucified on the &#8220;no-spammer&#8221; altar. Mark R (the plugins guy) has a very, very low tolerance and an unforgiving nature about that sort of thing.</p>
<p>We can&#8217;t control what plugins are released elsewhere, but we do have complete control over what&#8217;s on wordpress.org and will take whatever steps are necessary to remove spammy BS.</p>
<p>A plugin reviewer team would be nice, but it&#8217;s a big, big job if you sit down and think about it. We&#8217;re only just now getting into stride with the theme reviewer system, implementing a plugin review system is an order of magnitude more difficult.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rishil</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4895</link>
		<dc:creator>rishil</dc:creator>
		<pubDate>Mon, 18 Apr 2011 08:17:45 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4895</guid>
		<description>yes you should. See my next post...</description>
		<content:encoded><![CDATA[<p>yes you should. See my next post&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: roey</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4840</link>
		<dc:creator>roey</dc:creator>
		<pubDate>Sat, 16 Apr 2011 17:28:44 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4840</guid>
		<description>thank you for this greay post. what about joomla plugins?
should i be worried as well?</description>
		<content:encoded><![CDATA[<p>thank you for this greay post. what about joomla plugins?<br />
should i be worried as well?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Derek Jansen</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4665</link>
		<dc:creator>Derek Jansen</dc:creator>
		<pubDate>Tue, 12 Apr 2011 13:49:37 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4665</guid>
		<description>Thanks for revealing this topic - while I&#039;ve always been aware of the SEO spam abuse element, but the hacking element was ignored.</description>
		<content:encoded><![CDATA[<p>Thanks for revealing this topic &#8211; while I&#8217;ve always been aware of the SEO spam abuse element, but the hacking element was ignored.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liam Kenneth</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4654</link>
		<dc:creator>Liam Kenneth</dc:creator>
		<pubDate>Tue, 12 Apr 2011 06:44:22 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4654</guid>
		<description>Interesting Article :)</description>
		<content:encoded><![CDATA[<p>Interesting Article <img src='http://explicitly.me/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rick</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4623</link>
		<dc:creator>Rick</dc:creator>
		<pubDate>Mon, 11 Apr 2011 17:06:40 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4623</guid>
		<description>Scary stuff...you always presume Wordpress is flaw free.</description>
		<content:encoded><![CDATA[<p>Scary stuff&#8230;you always presume Wordpress is flaw free.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roie</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4579</link>
		<dc:creator>Roie</dc:creator>
		<pubDate>Sun, 10 Apr 2011 11:32:21 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4579</guid>
		<description>It&#039;s the same concept as torrents and hacked software being bundled with viruses and trojans to hijack PC&#039;s of unsuspecting down-loaders eagerly awaiting to use the next MS or Adobe software for free... these days, anything offered free should come with a warning label on it.</description>
		<content:encoded><![CDATA[<p>It&#8217;s the same concept as torrents and hacked software being bundled with viruses and trojans to hijack PC&#8217;s of unsuspecting down-loaders eagerly awaiting to use the next MS or Adobe software for free&#8230; these days, anything offered free should come with a warning label on it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aussiewebmaster</title>
		<link>http://explicitly.me/wordpress-plugins-secuirty-flaw-%e2%80%93-a-blackhats-dream/comment-page-1#comment-4531</link>
		<dc:creator>Aussiewebmaster</dc:creator>
		<pubDate>Fri, 08 Apr 2011 22:19:16 +0000</pubDate>
		<guid isPermaLink="false">http://explicitly.me/?p=1275#comment-4531</guid>
		<description>Give away all my secrets - thanks mate</description>
		<content:encoded><![CDATA[<p>Give away all my secrets &#8211; thanks mate</p>
]]></content:encoded>
	</item>
</channel>
</rss>
