<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Black Hat 2008: Pwnie Award Ceremony</title>
	<atom:link href="http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Sat, 21 Nov 2009 20:59:31 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Security</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-51266</link>
		<dc:creator>Security</dc:creator>
		<pubDate>Tue, 18 Nov 2008 14:18:31 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-51266</guid>
		<description>Now I understand how it works. Keep it up! I love this game.</description>
		<content:encoded><![CDATA[<p>Now I understand how it works. Keep it up! I love this game.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim Spence</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-46331</link>
		<dc:creator>Jim Spence</dc:creator>
		<pubDate>Sat, 18 Oct 2008 23:38:07 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-46331</guid>
		<description>Saturday I was searching for sites related to Search Engine Placement and specifically  and found this site.</description>
		<content:encoded><![CDATA[<p>Saturday I was searching for sites related to Search Engine Placement and specifically  and found this site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Abel Cheung</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-40214</link>
		<dc:creator>Abel Cheung</dc:creator>
		<pubDate>Sun, 17 Aug 2008 16:36:11 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-40214</guid>
		<description>Under current design having &#039;secured&#039; wordpress plugin invocation sounds impossible. Plugins are basically just included into the core and invoked like the core does. Though some function hooks are available for sanitizing input, those functions are only optional, and no expose for the function occur at any plugin writing tutorials.&lt;br&gt;&lt;br&gt;Until recent releases, wordpress press releases have a tradition of suppressing any security announcement in order to make it look good. This is still true right now if press release is written by Matt himself. Only when it is written by others (like Ryan Boren) did it at least mention something. In this area Matt exactly behaves like Linus Torvald (including svn changelog messages too), if not worse.&lt;br&gt;&lt;br&gt;And my personal experience with security@wordpress.org is that, it&#039;s yet another blackhole like those utterly dysfunctional vendors.</description>
		<content:encoded><![CDATA[<p>Under current design having &#8217;secured&#8217; wordpress plugin invocation sounds impossible. Plugins are basically just included into the core and invoked like the core does. Though some function hooks are available for sanitizing input, those functions are only optional, and no expose for the function occur at any plugin writing tutorials.</p>
<p>Until recent releases, wordpress press releases have a tradition of suppressing any security announcement in order to make it look good. This is still true right now if press release is written by Matt himself. Only when it is written by others (like Ryan Boren) did it at least mention something. In this area Matt exactly behaves like Linus Torvald (including svn changelog messages too), if not worse.</p>
<p>And my personal experience with <a href="mailto:security@wordpress.org">security@wordpress.org</a> is that, it&#8217;s yet another blackhole like those utterly dysfunctional vendors.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dr. Mike Wendell</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-40213</link>
		<dc:creator>Dr. Mike Wendell</dc:creator>
		<pubDate>Wed, 13 Aug 2008 17:02:22 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-40213</guid>
		<description>What&#039;s really sad about Wordpress outside of Matt&#039;s lack of manners, his inability to function in society and it&#039;s lack of security is that a full security audit has been mentioned and discussed previously but nothing has yet occurred.  Gallery did one and they don&#039;t have the millions to spend like Matt does.&lt;br&gt;&lt;br&gt;You would have thought the number of times they&#039;ve had their own sites hacked, security would have taken a step up in importance.  Guess not.&lt;br&gt;&lt;br&gt;But considering that Matt&#039;s now spamming his own site where ever he can instead of paying any attention to the splogs on wp.com and ignoring reports about them, does anything surprise you anymore?</description>
		<content:encoded><![CDATA[<p>What&#8217;s really sad about WordPress outside of Matt&#8217;s lack of manners, his inability to function in society and it&#8217;s lack of security is that a full security audit has been mentioned and discussed previously but nothing has yet occurred.  Gallery did one and they don&#8217;t have the millions to spend like Matt does.</p>
<p>You would have thought the number of times they&#8217;ve had their own sites hacked, security would have taken a step up in importance.  Guess not.</p>
<p>But considering that Matt&#8217;s now spamming his own site where ever he can instead of paying any attention to the splogs on wp.com and ignoring reports about them, does anything surprise you anymore?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Guido</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-40212</link>
		<dc:creator>Dan Guido</dc:creator>
		<pubDate>Tue, 12 Aug 2008 06:23:44 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-40212</guid>
		<description>viper007bond: plugins are not the reason Wordpress is insecure. You can check it&#039;s history of security problems over at osvdb.org if you&#039;re curious.</description>
		<content:encoded><![CDATA[<p>viper007bond: plugins are not the reason WordPress is insecure. You can check it&#8217;s history of security problems over at osvdb.org if you&#8217;re curious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Viper007Bond</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-40211</link>
		<dc:creator>Viper007Bond</dc:creator>
		<pubDate>Thu, 07 Aug 2008 10:44:48 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-40211</guid>
		<description>klintor:&lt;br&gt;&lt;br&gt;I&#039;m a bit of a noob, but I don&#039;t even see how that&#039;s physically possible in a PHP based environment. As far as I know, you can&#039;t easily run a PHP script in like a container or whatever.&lt;br&gt;&lt;br&gt;The only way I can think of to provide a plugin capability that met your requirements was if the plugin was like a XML file or something that just toggled flags/parameters in the software -- a configuration file basically. You wouldn&#039;t be able to expand on the software at all and would pretty much defeat the purpose of having plugins or an API.&lt;br&gt;&lt;br&gt;And by your definition then just about every piece of software on the web that has an API should get the same award. Look at Firefox, vBulletin, PunBB, etc. etc. etc. etc. They all load external files that could potentially compromise the security of the computer/server.&lt;br&gt;&lt;br&gt;If you have some brilliant idea or method to solve the problem, then please by all means, say so. Assuming it&#039;s a reasonable solution, I&#039;d be more than happy to contribute code towards such a solution for submission to the people that run the WordPress development.</description>
		<content:encoded><![CDATA[<p>klintor:</p>
<p>I&#8217;m a bit of a noob, but I don&#8217;t even see how that&#8217;s physically possible in a PHP based environment. As far as I know, you can&#8217;t easily run a PHP script in like a container or whatever.</p>
<p>The only way I can think of to provide a plugin capability that met your requirements was if the plugin was like a XML file or something that just toggled flags/parameters in the software &#8212; a configuration file basically. You wouldn&#8217;t be able to expand on the software at all and would pretty much defeat the purpose of having plugins or an API.</p>
<p>And by your definition then just about every piece of software on the web that has an API should get the same award. Look at Firefox, vBulletin, PunBB, etc. etc. etc. etc. They all load external files that could potentially compromise the security of the computer/server.</p>
<p>If you have some brilliant idea or method to solve the problem, then please by all means, say so. Assuming it&#8217;s a reasonable solution, I&#8217;d be more than happy to contribute code towards such a solution for submission to the people that run the WordPress development.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: klintor</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-40210</link>
		<dc:creator>klintor</dc:creator>
		<pubDate>Thu, 07 Aug 2008 09:24:24 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-40210</guid>
		<description>viper:&lt;br&gt;&lt;br&gt;A truly secure platform (or OS) shouldn&#039;t allow 3rd party apps to introduce system-level vulnerabilities.  Period</description>
		<content:encoded><![CDATA[<p>viper:</p>
<p>A truly secure platform (or OS) shouldn&#8217;t allow 3rd party apps to introduce system-level vulnerabilities.  Period</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Viper007Bond</title>
		<link>http://hackaday.com/2008/08/06/black-hat-2008-pwnie-award-ceremony/comment-page-1/#comment-40209</link>
		<dc:creator>Viper007Bond</dc:creator>
		<pubDate>Thu, 07 Aug 2008 06:29:05 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/08/06/black-hat-2008-pwnie-award-ceremony/#comment-40209</guid>
		<description>I&#039;m confused about WordPress -- how can you consider vulnerable 3rd party code (plugins) manually installed by the user a vulnerability of WordPress itself? Especially more so if the user opts not to keep the 3rd party code up to date?&lt;br&gt;&lt;br&gt;It&#039;s as if I installed Firefox on my computer, a vulnerability was found in Firefox, and then the OS was deemed insecure as a result.&lt;br&gt;&lt;br&gt;Or am I missing something?</description>
		<content:encoded><![CDATA[<p>I&#8217;m confused about WordPress &#8212; how can you consider vulnerable 3rd party code (plugins) manually installed by the user a vulnerability of WordPress itself? Especially more so if the user opts not to keep the 3rd party code up to date?</p>
<p>It&#8217;s as if I installed Firefox on my computer, a vulnerability was found in Firefox, and then the OS was deemed insecure as a result.</p>
<p>Or am I missing something?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
