<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>JaypeeOnline &#187; blogsecurity</title> <atom:link href="http://jaypeeonline.net/tag/blogsecurity/feed/" rel="self" type="application/rss+xml" /><link>http://jaypeeonline.net</link> <description>Technology, Blogging News, WordPress Theme and Plugin Reviews, Tips and Tricks</description> <lastBuildDate>Fri, 10 Feb 2012 01:41:37 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>&#8220;How To Secure WordPress&#8221;</title><link>http://jaypeeonline.net/wordpress/how-to-secure-wordpress/</link> <comments>http://jaypeeonline.net/wordpress/how-to-secure-wordpress/#comments</comments> <pubDate>Fri, 02 Nov 2007 03:09:51 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[Blogging]]></category> <category><![CDATA[WordPress]]></category> <category><![CDATA[blogsecurity]]></category> <category><![CDATA[how to secure wordpress]]></category> <category><![CDATA[Social Networks]]></category> <category><![CDATA[web blogs]]></category> <category><![CDATA[whitepaper]]></category> <category><![CDATA[wordpress-security]]></category> <category><![CDATA[wpids]]></category><guid
isPermaLink="false">http://jaypeeonline.net/wordpress/how-to-secure-wordpress/</guid> <description><![CDATA[BlogSecurity, the only organization that deals with social networking and web blog security has recently released a WordPress security whitepaper entitled &#8220;How to Secure WordPress&#8220;. I haven&#8217;t finished reading the whole thing but I&#8217;ve already learned many things and gained more knowledge about securing WordPress installations. When I find the time, I&#8217;ll try to apply [...]]]></description> <content:encoded><![CDATA[<p><a
href="http://blogsecurity.net/">BlogSecurity</a>, the only organization that deals with social networking and web blog security has recently <a
href="http://blogsecurity.net/wordpress/wordpress-security-whitepaper/">released a WordPress security whitepaper</a> entitled &#8220;<strong>How to Secure WordPress</strong>&#8220;.</p><p>I haven&#8217;t finished reading the whole thing but I&#8217;ve already learned many things and gained more knowledge about securing WordPress installations. When I find the time, I&#8217;ll try to apply some of the things I&#8217;ve learned. One thing I&#8217;m really interested in trying out is the WPIDS plugin that detects intrusions. This is just an initial release so some aspects and topics were missed or weren&#8217;t fully covered. Expect additional topics and improvements in the next release or versions of this whitepaper.</p><p>Here&#8217;s what you&#8217;ll find inside version 1.0:</p><ul><li>Table of Contents</li><li>Introduction</li><li>Installing WordPress</li><ul><li>Accessing your WordPress tables</li><li>Changing your WordPress Table Prefix</li><li>Before Installation</li><li>Manually Change</li><li>Through WP Prefix Table Changer</li></ul><li>Preparing the Blog</li><ul><li>Changing your Admin Username</li><li>Create a new limited access user</li></ul><li>Hardening your WP Install</li><ul><li>Restricting wp-content &#038; wp-includes</li><li>Restricting wp-admin</li><li>Block all except your IP</li><li>Password Required &#8211; .htpasswd</li><li>The .htaccess file</li><li>The .htpasswd file</li></ul><li>MUSTHAVE Plugins</li><ul><li>WPIDS &#8211; Detect Intrusions</li><li>WordPress Plugin Tracker – Are you updated?</li><li>WordPress Online Security Scanner</li></ul></ul><p>Anyone else read the &#8220;<strong>How To Secure WordPress</strong>&#8221; whitepaper? What topics or additional information should the authors add in the next version? Share your thoughts!</p><p><a
href="http://blogsecurity.net/projects/secure-wp-whitepaper.pdf">Download the &#8220;Hot To Secure WordPress&#8221; PDF.</a></p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/" rel="bookmark" class="crp_title">Top 10 Vulnerable WP Themes</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-2-8-5/" rel="bookmark" class="crp_title">WordPress 2.8.5: Hardening Release</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-265/" rel="bookmark" class="crp_title">WordPress 2.6.5</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-222-2011-security-upgrades/" rel="bookmark" class="crp_title">WordPress 2.2.2 &#038; 2.0.11 Security Upgrades</a></li><li><a
href="http://jaypeeonline.net/wordpress/100-things-you-need-to-know-about-wordpress-anthony-montalbano-jtpratt/" rel="bookmark" class="crp_title">100 Things You Need to Know About WordPress by Anthony Montalbano &#038; JTPratt</a></li><li><a
href="http://jaypeeonline.net/gadgets/victorinox-super-secure-usb-drive/" rel="bookmark" class="crp_title">Victorinox Swiss Army Knife/Secure USB Drive</a></li><li><a
href="http://jaypeeonline.net/wordpress-plugins/wp-plugin-review-serverbuddy/" rel="bookmark" class="crp_title">WP Plugin Review: ServerBuddy</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-0-2-security-release/" rel="bookmark" class="crp_title">WordPress 3.0.2 Security Release</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-0-5-hotfix/" rel="bookmark" class="crp_title">WordPress 3.0.5 Security Release Hotfix</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-2-8-3-security-release/" rel="bookmark" class="crp_title">WordPress 2.8.3 Security Release</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/wordpress/how-to-secure-wordpress/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>Top 10 Vulnerable WP Themes</title><link>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/</link> <comments>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/#comments</comments> <pubDate>Fri, 10 Aug 2007 16:23:18 +0000</pubDate> <dc:creator>Jaypee Habaradas</dc:creator> <category><![CDATA[WordPress]]></category> <category><![CDATA[blogsecurity]]></category> <category><![CDATA[cross-site-scripting]]></category> <category><![CDATA[k2]]></category> <category><![CDATA[redoable]]></category> <category><![CDATA[vistered-little]]></category> <category><![CDATA[vulnerable-wordpress-themes]]></category><guid
isPermaLink="false">http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/</guid> <description><![CDATA[BlogSecurity an organization that deals with web blog security recently posted a list of the top 10 WordPress themes that are vulnerable to Cross-Site Scripting due to template flaws. 1. field-of-dreams 2. tarski 3. mandigo-14,1.22 4. connections 5. default 6. freshy 7. redoable 8. k2 9. vistered-little-1.6a 10. wp-multiflex-3 Some of the themes on the [...]]]></description> <content:encoded><![CDATA[<p></p><p><a
href="http://blogsecurity.net/">BlogSecurity</a> an organization that deals with web blog security recently posted a list of the <a
href="http://blogsecurity.net/wordpress/article-050807/">top 10 WordPress themes</a> that are vulnerable to <a
href="http://en.wikipedia.org/wiki/Cross-site_scripting">Cross-Site Scripting</a> due to template flaws.</p><p>1. <a
href="http://www.notsoboringlife.com/the-arts/blogging/wordpress-theme-field-of-dreams/">field-of-dreams</a><br
/> 2. <a
href="http://tarskitheme.com/">tarski</a><br
/> 3. <a
href="http://www.onehertz.com/portfolio/wordpress/mandigo/">mandigo-14,1.22</a><br
/> 4. <a
href="http://vanillamist.com/blog/?page_id=64">connections</a><br
/> 5. default<br
/> 6. <a
href="http://www.jide.fr/english/downloads/template-freshy-wordpress/">freshy</a><br
/> 7. <a
href="http://www.deanjrobinson.com/wordpress/redoable">redoable</a><br
/> 8. <a
href="http://getk2.com/">k2</a><br
/> 9. <a
href="http://windyroad.org/">vistered-little-1.6a</a><br
/> 10. <a
href="http://webgazette.co.uk/web-design/wordpress-themes/wp-multiflex-3/">wp-multiflex-3</a></p><p><span
id="more-368"></span></p><p>Some of the themes on the list are popular WordPress themes, like <strong>freshy</strong>, <strong>k2</strong> and <strong>redoable</strong>. I hope that the theme authors would look into this and make the necessary changes and fix the template flaws.</p><p>If you want to perform the same test for your blog or WordPress themes that you&#8217;ve created, you can use the same method used by BlogSecurity team. All you need to do is follow the installation instructions:</p><ul><li>Download the <a
href="http://blogsecurity.net/projects/wp-scanner.zip">wp-scanner activator</a> plugin.</li><li>Upload the plugin file to your <strong>wp-contents/plugin</strong> folder.</li><li><strong>Activate</strong> the plugin from the admin panel.</li><li><a
href="http://blogsecurity.net/wpscan">Launch the wp-scanner</a> and perform the test.</li><li>As soon as you&#8217;re done, <strong>de-activate</strong> the plugin so other people can&#8217;t to scan your blog.</li></ul><p>Btw, I performed the test for JaypeeOnline and I&#8217;m happy with the result:</p><p><img
src="http://maxcdn.jaypeeonline.net/images/wpscanner_result.jpg" alt="WP Scanner Result for JaypeeOnline" /></p><p>I strongly recommend that you also perform this test so you can find out if the WordPress theme you&#8217;re using is vulnerable or not. It would only take a few minutes of your time. If you&#8217;ve also performed the test, please share your test results or your thoughts regarding this matter. Thank you!</p><p>Oh yeah, I almost forgot. Make it a habit to download WordPress themes or plugins from reliable sources or directly from the author&#8217;s site. Better safe than sorry!</p><p>Have a good weekend everyone! :)</p><div
id="crp_related"><ul><li><a
href="http://jaypeeonline.net/wordpress/how-to-secure-wordpress/" rel="bookmark" class="crp_title">&#8220;How To Secure WordPress&#8221;</a></li><li><a
href="http://jaypeeonline.net/wordpress/49-most-downloaded-wordpress-themes/" rel="bookmark" class="crp_title">49 Most downloaded WordPress Themes</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/vistered-little-theme-security-alert/" rel="bookmark" class="crp_title">Vistered Little Theme Security Alert</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/wp-theme-review-redoable-11/" rel="bookmark" class="crp_title">WP Theme Review: Redoable 1.1</a></li><li><a
href="http://jaypeeonline.net/wordpress/wordpress-3-2-rc1/" rel="bookmark" class="crp_title">WordPress 3.2 Release Candidate 1</a></li><li><a
href="http://jaypeeonline.net/wordpress-themes/wp-theme-review-redoable-12/" rel="bookmark" class="crp_title">WP Theme Review: Redoable 1.2</a></li><li><a
href="http://jaypeeonline.net/tips-tricks/wordpress-reverting-default-theme-fix/" rel="bookmark" class="crp_title">WordPress Reverting Default Theme Fix</a></li><li><a
href="http://jaypeeonline.net/wordpress-plugins/wp-plugin-review-theme-authenticity-checker/" rel="bookmark" class="crp_title">WP Plugin Review: TAC (Theme Authenticity Checker)</a></li><li><a
href="http://jaypeeonline.net/wordpress/why-you-shouldnt-look-for-free-wordpress-themes-on-search-engines/" rel="bookmark" class="crp_title">Why You Shouldn&#8217;t Look for Free WordPress Themes on Search Engines</a></li><li><a
href="http://jaypeeonline.net/wordpress/another-warning-to-wordpress-users/" rel="bookmark" class="crp_title">Another Warning To WordPress Users</a></li></ul></div>]]></content:encoded> <wfw:commentRss>http://jaypeeonline.net/wordpress/top-10-vulnerable-wp-themes/feed/</wfw:commentRss> <slash:comments>14</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced) (User agent is rejected)
Database Caching 33/47 queries in 0.102 seconds using disk
Object Caching 779/867 objects using disk
Content Delivery Network via maxcdn.jaypeeonline.net

Served from: jaypeeonline.net @ 2012-02-13 22:27:39 -->
