<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Meditation Expert &#187; wordpress</title>
	<atom:link href="http://www.meditationexpert.com/blog/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.meditationexpert.com/blog</link>
	<description>Everything you want to know about meditation and spiritual cultivation</description>
	<lastBuildDate>Fri, 20 Aug 2010 02:46:52 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Blog is back, But What a Scare</title>
		<link>http://www.meditationexpert.com/blog/2008/09/the-blog-is-back-but-what-a-scare/</link>
		<comments>http://www.meditationexpert.com/blog/2008/09/the-blog-is-back-but-what-a-scare/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 17:25:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Real World]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.meditationexpert.com/blog/?p=155</guid>
		<description><![CDATA[What a scare. The blog was hacked and I thought the posts were gone forever. For days I&#8217;ve been trying to retrieve things and posting the articles as static html pages just in case.  For those of you who are Wordpress inclined, here&#8217;s what happened &#8211; a new exploit:
There&#8217;s a Wordpress plugin that uploads jpg [...]]]></description>
			<content:encoded><![CDATA[<p>What a scare. The blog was hacked and I thought the posts were gone forever. For days I&#8217;ve been trying to retrieve things and posting the articles as static html pages just in case.  For those of you who are Wordpress inclined, here&#8217;s what happened &#8211; a new exploit:</p>
<p>There&#8217;s a Wordpress plugin that uploads jpg and png avatars for users.  As we found out the hard way,  do not activate it ever. It&#8217;s the exact way how the attacker can get into your files (png can be script). Any plugins/addons that allow your subscribers to upload something (you can allow jpg or gifs for avatars, but better keep it safe) turns out to be DANGEROUS.</p>
<p>Here&#8217;s how the attacker gets in the database for Wordpress and starts causing mischief.  In the database appears javascript code that creates a second administrator.  It will have no name but all rights and call itself Wordpress (like a superuser).  So you have no chance to see this user in a list. But, there&#8217;s still one place where you can see it (please remember it).  When you&#8217;re on the user managing page, theres a list</p>
<p>All users | administrators (1) | subscribers (65)</p>
<p>When you click on the All Users, you will see administrators (2) &#8211; so if you know there&#8217;s only 1 administrator, the second is an exploit.</p>
<p>Why tell you all this? Maybe you can use this info to save a friend.  It sure is hard running a website to offer information nowadays!</p>
<div></div>
]]></content:encoded>
			<wfw:commentRss>http://www.meditationexpert.com/blog/2008/09/the-blog-is-back-but-what-a-scare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.311 seconds -->
