<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: One of the worst WordPress security threats still alive</title>
	<atom:link href="http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive</link>
	<description>Joomla, Web Development, Joomla Templates</description>
	<pubDate>Thu, 21 Aug 2008 00:23:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Joey</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-515</link>
		<dc:creator>Joey</dc:creator>
		<pubDate>Wed, 11 Jun 2008 20:55:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-515</guid>
		<description>Wow, never knew that! Thanks for that info.

Joey - www.LeetWebmasters.com</description>
		<content:encoded><![CDATA[<p>Wow, never knew that! Thanks for that info.</p>
<p>Joey - <a href="http://www.LeetWebmasters.com" rel="nofollow">http://www.LeetWebmasters.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Copes Flavio</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-509</link>
		<dc:creator>Copes Flavio</dc:creator>
		<pubDate>Mon, 09 Jun 2008 07:35:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-509</guid>
		<description>@Sherif: thanks for your input, that's handy ;)</description>
		<content:encoded><![CDATA[<p>@Sherif: thanks for your input, that&#8217;s handy <img src='http://www.copesflavio.com/en/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sherif Elsisi</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-505</link>
		<dc:creator>Sherif Elsisi</dc:creator>
		<pubDate>Sun, 08 Jun 2008 22:57:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-505</guid>
		<description>Yes, it is amazing how your site can become vulnerable just by offering info you don't need to. Like plugins or wordpress version.

Another simple option is add to the htaccess file. 
Just add "Options –Indexes". This will disable directory browsing and do the same as index.html.

Regards.
Sherif</description>
		<content:encoded><![CDATA[<p>Yes, it is amazing how your site can become vulnerable just by offering info you don&#8217;t need to. Like plugins or wordpress version.</p>
<p>Another simple option is add to the htaccess file.<br />
Just add &#8220;Options –Indexes&#8221;. This will disable directory browsing and do the same as index.html.</p>
<p>Regards.<br />
Sherif</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Devon Young</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-474</link>
		<dc:creator>Devon Young</dc:creator>
		<pubDate>Tue, 03 Jun 2008 01:26:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-474</guid>
		<description>WOW! I just did the search, &#38; got "Results 1 - 100 of about 768,000 for Index of /wp-content/plugins". That's a lot of naked plugin directories.</description>
		<content:encoded><![CDATA[<p>WOW! I just did the search, &amp; got &#8220;Results 1 - 100 of about 768,000 for Index of /wp-content/plugins&#8221;. That&#8217;s a lot of naked plugin directories.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Copes Flavio</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-436</link>
		<dc:creator>Copes Flavio</dc:creator>
		<pubDate>Mon, 26 May 2008 19:17:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-436</guid>
		<description>@eTiger13: I share your opinion, this is something that should be done..</description>
		<content:encoded><![CDATA[<p>@eTiger13: I share your opinion, this is something that should be done..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: eTiger13</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-430</link>
		<dc:creator>eTiger13</dc:creator>
		<pubDate>Sun, 25 May 2008 17:55:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-430</guid>
		<description>One thing people seem to be forgetting is that even though Apache has a dominant market share, it is not the only web browser out there. So just throwing a line out like 'yeah all you have to do is change your htaccess file' doesn't always work. Also, instead of adding it to your htaccess file, it should be in your .conf file. That way you can always override it in your htaccess file but have it enabled by default.

Wordpress should do like Joomla and just do the simple fix that works for most people, include an index.html file in every folder. Very easy fix that goes a long way towards secure environments.</description>
		<content:encoded><![CDATA[<p>One thing people seem to be forgetting is that even though Apache has a dominant market share, it is not the only web browser out there. So just throwing a line out like &#8216;yeah all you have to do is change your htaccess file&#8217; doesn&#8217;t always work. Also, instead of adding it to your htaccess file, it should be in your .conf file. That way you can always override it in your htaccess file but have it enabled by default.</p>
<p>Wordpress should do like Joomla and just do the simple fix that works for most people, include an index.html file in every folder. Very easy fix that goes a long way towards secure environments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Copes Flavio</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-411</link>
		<dc:creator>Copes Flavio</dc:creator>
		<pubDate>Mon, 19 May 2008 08:51:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-411</guid>
		<description>@milo: You're right.. in the list you can even find a website such as http://development.mit.edu/ !</description>
		<content:encoded><![CDATA[<p>@milo: You&#8217;re right.. in the list you can even find a website such as <a href="http://development.mit.edu/" rel="nofollow">http://development.mit.edu/</a> !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: milo</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-410</link>
		<dc:creator>milo</dc:creator>
		<pubDate>Mon, 19 May 2008 08:43:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-410</guid>
		<description>What's really scary: a lot of "designer" sites are open this way, makes you wonder if their client sites share the same problem....</description>
		<content:encoded><![CDATA[<p>What&#8217;s really scary: a lot of &#8220;designer&#8221; sites are open this way, makes you wonder if their client sites share the same problem&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Copes Flavio</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-409</link>
		<dc:creator>Copes Flavio</dc:creator>
		<pubDate>Mon, 19 May 2008 08:27:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-409</guid>
		<description>@milo: Hi milo, thanks for stopping by. Yes, this is the solution to the problem, but I just wanted to show how many people don't implement any kind of protection to solve this problem! :-)

@TVSpy Voyeur: you can even take a look at the code of the files! Too bad</description>
		<content:encoded><![CDATA[<p>@milo: Hi milo, thanks for stopping by. Yes, this is the solution to the problem, but I just wanted to show how many people don&#8217;t implement any kind of protection to solve this problem! <img src='http://www.copesflavio.com/en/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>@TVSpy Voyeur: you can even take a look at the code of the files! Too bad</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: milo</title>
		<link>http://www.copesflavio.com/en/blog/cms/joomla/one-of-the-worst-wordpress-security-threats-still-alive#comment-407</link>
		<dc:creator>milo</dc:creator>
		<pubDate>Sun, 18 May 2008 11:31:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.copesflavio.com/en/blog/?p=140#comment-407</guid>
		<description>Deny the indexing via the robots txt file and secure it via ht access.</description>
		<content:encoded><![CDATA[<p>Deny the indexing via the robots txt file and secure it via ht access.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
