<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Yet another wordpress exploit</title>
	<atom:link href="http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/</link>
	<description>「偶然世界」で出逢い</description>
	<pubDate>Tue, 06 Jan 2009 06:10:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: WordPress and Other Criticisms. : The Private intellectual</title>
		<link>http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-15791</link>
		<dc:creator>WordPress and Other Criticisms. : The Private intellectual</dc:creator>
		<pubDate>Sun, 08 Jul 2007 09:08:37 +0000</pubDate>
		<guid isPermaLink="false">http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-15791</guid>
		<description>[...] his own. Rather, Wincent takes his comments - slightly re-written - from someone calling themselves Sho Fukamachi. This isn&#8217;t a problem in itself, since he has linked to the original article, although not [...]</description>
		<content:encoded><![CDATA[<p>[...] his own. Rather, Wincent takes his comments - slightly re-written - from someone calling themselves Sho Fukamachi. This isn&#8217;t a problem in itself, since he has linked to the original article, although not [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sho</title>
		<link>http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14795</link>
		<dc:creator>Sho</dc:creator>
		<pubDate>Sat, 23 Jun 2007 07:59:49 +0000</pubDate>
		<guid isPermaLink="false">http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14795</guid>
		<description>For my reply to the above missing-the-point comments, simple replace all instances of "WordPress", chronically insecure software aimed at non-technical users, with "Microsoft Windows", also chronically insecure software aimed at non-technical users.

No more comments! Sorry, I don't really run this blog to conduct conversations with strangers.</description>
		<content:encoded><![CDATA[<p>For my reply to the above missing-the-point comments, simple replace all instances of &#8220;WordPress&#8221;, chronically insecure software aimed at non-technical users, with &#8220;Microsoft Windows&#8221;, also chronically insecure software aimed at non-technical users.</p>
<p>No more comments! Sorry, I don&#8217;t really run this blog to conduct conversations with strangers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cody</title>
		<link>http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14792</link>
		<dc:creator>Cody</dc:creator>
		<pubDate>Sat, 23 Jun 2007 06:47:43 +0000</pubDate>
		<guid isPermaLink="false">http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14792</guid>
		<description>I'm of a like mind with Pi there. WordPress is not to blame for lazy people who don't bother to keep things up-to-date. The lazy-ass morons who don't know a thing about being safe on the Internet are to blame. I update manually every time there's a new release and somehow I don't have any problems doing it. Does it take too much time? No, not really. It's not really a "fucking pain in the ass" either. Maybe because I know enough about how WordPress works to only replace what needs to be replaced. You shouldn't need to mess with copying your themes since the wp-content folder does not usually need to be updated at all.

Granted, I'm not the average Joe blogger, but the average Joe blogger should be using a platform that doesn't require any technical knowledge at all, such as Blogger or WordPress.com, not a manual install of WordPress. If you don't know anything about being safe on the Internet, you shouldn't be installing things on an SQL database.

Besides, all software has its security holes. At least WordPress jumps on their holes when they become troublesome. That's the good thing about being open source. Anyone can pitch in to get rid of an exploit. What about the alternatives? Movable Type? It sucks, and (for now) you have to rely completely on Six Apart being open about any security holes. WordPress publicizes their exploits, which results in a relatively quick turnaround for fixes. What, is a couple of weeks too long to wait for a fix? Better than a couple of months as it is with most closed source software.

But really, if you dislike WP so much, ditch it. I've read about many people switching from Movable Type to WordPress. If they can do that, you can surely switch from WordPress. Or would that just take up too much of your precious ranting time?</description>
		<content:encoded><![CDATA[<p>I&#8217;m of a like mind with Pi there. WordPress is not to blame for lazy people who don&#8217;t bother to keep things up-to-date. The lazy-ass morons who don&#8217;t know a thing about being safe on the Internet are to blame. I update manually every time there&#8217;s a new release and somehow I don&#8217;t have any problems doing it. Does it take too much time? No, not really. It&#8217;s not really a &#8220;fucking pain in the ass&#8221; either. Maybe because I know enough about how WordPress works to only replace what needs to be replaced. You shouldn&#8217;t need to mess with copying your themes since the wp-content folder does not usually need to be updated at all.</p>
<p>Granted, I&#8217;m not the average Joe blogger, but the average Joe blogger should be using a platform that doesn&#8217;t require any technical knowledge at all, such as Blogger or WordPress.com, not a manual install of WordPress. If you don&#8217;t know anything about being safe on the Internet, you shouldn&#8217;t be installing things on an SQL database.</p>
<p>Besides, all software has its security holes. At least WordPress jumps on their holes when they become troublesome. That&#8217;s the good thing about being open source. Anyone can pitch in to get rid of an exploit. What about the alternatives? Movable Type? It sucks, and (for now) you have to rely completely on Six Apart being open about any security holes. WordPress publicizes their exploits, which results in a relatively quick turnaround for fixes. What, is a couple of weeks too long to wait for a fix? Better than a couple of months as it is with most closed source software.</p>
<p>But really, if you dislike WP so much, ditch it. I&#8217;ve read about many people switching from Movable Type to WordPress. If they can do that, you can surely switch from WordPress. Or would that just take up too much of your precious ranting time?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pi</title>
		<link>http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14791</link>
		<dc:creator>Pi</dc:creator>
		<pubDate>Sat, 23 Jun 2007 06:09:55 +0000</pubDate>
		<guid isPermaLink="false">http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14791</guid>
		<description>I find it strange seeing people condemning WordPress for doing exactly what they demand others, such as Microsoft and Company, do. Were it not for the regular security fixes and updates to WordPress it would be dead in the water like so many other software applications which are unable to keep up with the times, or with the threat level.

As to your list of what needs to be done for each and every upgrade or update, really? I have never had the need to move a single picture from one file to another when updating or upgrading - and I have several hundred on my weblog - and switching off plug-ins is a piece of cake, there is an interface there exactly for that task.

So some people don't upgrade - including an Internet company - is that a WordPress fault? I don't think so. Everyone can decide for themselves whether they upgrade or not, the information is always readily available, and that often within an hour or so of a problem arising - when it's a serious one, and that is rare to say the least.

You quote the svn update facility, anfd then recommend that people don't use WordPress? Biting yourself in the ass, I would say, since the svn update facility is one of those good sides other providers do not have. Perhaps you realise this an, despite your rather random and ill-thought out tirade, you'll come to see tzhat you use WordPress because it is better than the others, and likely to remain that way for a long time to come. Or would you rather switch to Moveable Type - about to go Open Source just like WordPress - and close down your comments, hide in a hole and only venture out to sniff at the competition as it races into the future, leaving you and Wincent Colaiuta behind?

Pi.</description>
		<content:encoded><![CDATA[<p>I find it strange seeing people condemning WordPress for doing exactly what they demand others, such as Microsoft and Company, do. Were it not for the regular security fixes and updates to WordPress it would be dead in the water like so many other software applications which are unable to keep up with the times, or with the threat level.</p>
<p>As to your list of what needs to be done for each and every upgrade or update, really? I have never had the need to move a single picture from one file to another when updating or upgrading - and I have several hundred on my weblog - and switching off plug-ins is a piece of cake, there is an interface there exactly for that task.</p>
<p>So some people don&#8217;t upgrade - including an Internet company - is that a WordPress fault? I don&#8217;t think so. Everyone can decide for themselves whether they upgrade or not, the information is always readily available, and that often within an hour or so of a problem arising - when it&#8217;s a serious one, and that is rare to say the least.</p>
<p>You quote the svn update facility, anfd then recommend that people don&#8217;t use WordPress? Biting yourself in the ass, I would say, since the svn update facility is one of those good sides other providers do not have. Perhaps you realise this an, despite your rather random and ill-thought out tirade, you&#8217;ll come to see tzhat you use WordPress because it is better than the others, and likely to remain that way for a long time to come. Or would you rather switch to Moveable Type - about to go Open Source just like WordPress - and close down your comments, hide in a hole and only venture out to sniff at the competition as it races into the future, leaving you and Wincent Colaiuta behind?</p>
<p>Pi.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wincent Colaiuta</title>
		<link>http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14663</link>
		<dc:creator>Wincent Colaiuta</dc:creator>
		<pubDate>Thu, 21 Jun 2007 08:41:35 +0000</pubDate>
		<guid isPermaLink="false">http://fukamachi.org/wp/2007/06/21/yet-another-wordpress-exploit/#comment-14663</guid>
		<description>&lt;a href="http://wincent.com/a/about/wincent/weblog/archives/2007/06/wordpress_flaw.php" rel="nofollow"&gt;My thoughts exactly&lt;/a&gt;.</description>
		<content:encoded><![CDATA[<p><a href="http://wincent.com/a/about/wincent/weblog/archives/2007/06/wordpress_flaw.php" rel="nofollow">My thoughts exactly</a>.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
