<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Serious email spam issue for Irish Wordpress blogs.</title>
	<atom:link href="http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/feed/" rel="self" type="application/rss+xml" />
	<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/</link>
	<description></description>
	<lastBuildDate>Thu, 29 Jul 2010 08:39:22 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: MarketBoy</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-9450</link>
		<dc:creator>MarketBoy</dc:creator>
		<pubDate>Fri, 16 Jan 2009 14:44:04 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-9450</guid>
		<description>Guys if you want your blogs to be secure and if you do not want to spend a lot of money…visit my website… wppadlock.com it is only 12.00$ but i am willing to cut the price down even more…any questions email me at wppadlockpro [at] gmail.com

- MarketBoy</description>
		<content:encoded><![CDATA[<p>Guys if you want your blogs to be secure and if you do not want to spend a lot of money…visit my website… wppadlock.com it is only 12.00$ but i am willing to cut the price down even more…any questions email me at wppadlockpro [at] gmail.com</p>
<p>- MarketBoy</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cuplaweb &#187; WordPress: Are your user&#8217;s email addresses secure?</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-8672</link>
		<dc:creator>Cuplaweb &#187; WordPress: Are your user&#8217;s email addresses secure?</dc:creator>
		<pubDate>Thu, 21 Aug 2008 05:16:41 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-8672</guid>
		<description>[...] Jason Roe has pointed out a potential security issue for Wordpress which I picked up on via boards.ie. [...]</description>
		<content:encoded><![CDATA[<p>[...] Jason Roe has pointed out a potential security issue for Wordpress which I picked up on via boards.ie. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Niall Devitt</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-7793</link>
		<dc:creator>Niall Devitt</dc:creator>
		<pubDate>Mon, 12 May 2008 10:05:11 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-7793</guid>
		<description>Thanks for the advice and well done on making the discovery</description>
		<content:encoded><![CDATA[<p>Thanks for the advice and well done on making the discovery</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason Roe</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1416</link>
		<dc:creator>Jason Roe</dc:creator>
		<pubDate>Thu, 18 Jan 2007 22:47:15 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1416</guid>
		<description>I made some revisions to the post to clear up what I was trying to say. I agree with matt, there was a bit more to this than some of the newer exploits. People on older versions should always upgrade (in an ideal world).</description>
		<content:encoded><![CDATA[<p>I made some revisions to the post to clear up what I was trying to say. I agree with matt, there was a bit more to this than some of the newer exploits. People on older versions should always upgrade (in an ideal world).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason Roe</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1396</link>
		<dc:creator>Jason Roe</dc:creator>
		<pubDate>Wed, 17 Jan 2007 08:29:59 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1396</guid>
		<description>Hi Matt, Thanks for popping by. This comment was based on my adventures inside my own blogs, so as you said it may not be the case for everyone. 

However, while looking at this issue on other blogs I noted that I could view 900 odd users.. These users closely related to comments posted. As far as I was aware, there was no real reason for the sites to have this enabled in the first place. The other strange thing is that there was no link for the users to register without manually entering a url. So how did these guys get accounts? 

I will test it again on another blog of mine with a standard 2.0.5 pre-patched install.</description>
		<content:encoded><![CDATA[<p>Hi Matt, Thanks for popping by. This comment was based on my adventures inside my own blogs, so as you said it may not be the case for everyone. </p>
<p>However, while looking at this issue on other blogs I noted that I could view 900 odd users.. These users closely related to comments posted. As far as I was aware, there was no real reason for the sites to have this enabled in the first place. The other strange thing is that there was no link for the users to register without manually entering a url. So how did these guys get accounts? </p>
<p>I will test it again on another blog of mine with a standard 2.0.5 pre-patched install.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1387</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Wed, 17 Jan 2007 01:02:17 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1387</guid>
		<description>&quot;Your blog meta data includes all of the e-mail address of every user &amp; also ever person who has commented on your blog.&quot;

This sentence is incorrect. I&#039;m not registering on your blog to make this comment, therefore I don&#039;t have a user ID. If you had registration open on your blog, an option which is off by default, and if I registered on your blog with a legitimate email address and went through the activation process, and if you were running a version older than 2.0.5, which was released about 3 months ago.

I totally agree that people on older versions should upgrade, or at the very least turn off the &quot;anyone can register&quot; option.</description>
		<content:encoded><![CDATA[<p>&#8220;Your blog meta data includes all of the e-mail address of every user &amp; also ever person who has commented on your blog.&#8221;</p>
<p>This sentence is incorrect. I&#8217;m not registering on your blog to make this comment, therefore I don&#8217;t have a user ID. If you had registration open on your blog, an option which is off by default, and if I registered on your blog with a legitimate email address and went through the activation process, and if you were running a version older than 2.0.5, which was released about 3 months ago.</p>
<p>I totally agree that people on older versions should upgrade, or at the very least turn off the &#8220;anyone can register&#8221; option.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Our Family Blog &#187; Blog Archive &#187; TUE LINKS 1/16/2007Uworld</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1386</link>
		<dc:creator>Our Family Blog &#187; Blog Archive &#187; TUE LINKS 1/16/2007Uworld</dc:creator>
		<pubDate>Tue, 16 Jan 2007 22:57:57 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1386</guid>
		<description>[...] Huge Wordpress Security Issue [...]</description>
		<content:encoded><![CDATA[<p>[...] Huge Wordpress Security Issue [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The day after tomorrow for SEO wordpress blogs! - Jason Roe Technology. Jason Roe - Web design, Development, SEO Advice</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1372</link>
		<dc:creator>The day after tomorrow for SEO wordpress blogs! - Jason Roe Technology. Jason Roe - Web design, Development, SEO Advice</dc:creator>
		<pubDate>Tue, 16 Jan 2007 10:20:10 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1372</guid>
		<description>[...] I guess this might be understandable just after I only highlighting an issue with wordpress last week! However, this was more of a heads up than a Tutorial how to exploit the issue. People keep putting 2 + 2 together and making 5 [...]</description>
		<content:encoded><![CDATA[<p>[...] I guess this might be understandable just after I only highlighting an issue with wordpress last week! However, this was more of a heads up than a Tutorial how to exploit the issue. People keep putting 2 + 2 together and making 5 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason Roe</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1361</link>
		<dc:creator>Jason Roe</dc:creator>
		<pubDate>Tue, 16 Jan 2007 01:42:46 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1361</guid>
		<description>I just found a bug while doing research on security. It had been fixed by the time I made the post.</description>
		<content:encoded><![CDATA[<p>I just found a bug while doing research on security. It had been fixed by the time I made the post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Dammann</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1360</link>
		<dc:creator>Mike Dammann</dc:creator>
		<pubDate>Tue, 16 Jan 2007 01:34:48 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1360</guid>
		<description>Is this when you realized how easy it was to hack wordpress blogs? ;)</description>
		<content:encoded><![CDATA[<p>Is this when you realized how easy it was to hack wordpress blogs? <img src='http://jasonroe.me/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuntdubl Marketing Consulting hacked - SEOs a target - Jason Roe Web Development. Jason Roe - Web design, Development, SEO Advice</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1353</link>
		<dc:creator>Stuntdubl Marketing Consulting hacked - SEOs a target - Jason Roe Web Development. Jason Roe - Web design, Development, SEO Advice</dc:creator>
		<pubDate>Mon, 15 Jan 2007 22:49:25 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1353</guid>
		<description>[...] Quick fix is to disable trackback until the patch is issued by wordpress. This is kinda similar to my other post about wordpress security. See pick below: [...]</description>
		<content:encoded><![CDATA[<p>[...] Quick fix is to disable trackback until the patch is issued by wordpress. This is kinda similar to my other post about wordpress security. See pick below: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cupla Web: Smart Website Development</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1239</link>
		<dc:creator>Cupla Web: Smart Website Development</dc:creator>
		<pubDate>Mon, 08 Jan 2007 17:21:11 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1239</guid>
		<description>&lt;strong&gt;WordPress: Are your user&#039;s email addresses secure?...&lt;/strong&gt;

Jason Roe has pointed out a potential security issue for Wordpress which I picked up on via boards.ie.
The issue can allow someone to scrape email addresses and other contact details from a wordpress site that allows user registration on it.
In the gra...</description>
		<content:encoded><![CDATA[<p><strong>WordPress: Are your user&#8217;s email addresses secure?&#8230;</strong></p>
<p>Jason Roe has pointed out a potential security issue for Wordpress which I picked up on via boards.ie.<br />
The issue can allow someone to scrape email addresses and other contact details from a wordpress site that allows user registration on it.<br />
In the gra&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Minor Wordpress vulnerability confirmed - amd on software - stuff for nerds, news that matters</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1218</link>
		<dc:creator>Minor Wordpress vulnerability confirmed - amd on software - stuff for nerds, news that matters</dc:creator>
		<pubDate>Sat, 06 Jan 2007 18:19:28 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1218</guid>
		<description>[...] Minor Wordpress vulnerability confirmed        Thanks to Jason for the heads-up - it seems that my Wordpress 2.0 blogs are vulnerable to the exploit listed in Wordpress issue #3142, but the effect is relatively minor.  Every logged in user can spy out the metadata of all other users by typing in the URL /wp-admin/user-edit.php?user_id=XXX irrespective if he has the right to do this or not. If not in fact there will be shown the error message &#8220;You do not have permission to edit this user.&#8221; but after that message the complete form with all data will also be shown. [...]</description>
		<content:encoded><![CDATA[<p>[...] Minor Wordpress vulnerability confirmed        Thanks to Jason for the heads-up &#8211; it seems that my Wordpress 2.0 blogs are vulnerable to the exploit listed in Wordpress issue #3142, but the effect is relatively minor.  Every logged in user can spy out the metadata of all other users by typing in the URL /wp-admin/user-edit.php?user_id=XXX irrespective if he has the right to do this or not. If not in fact there will be shown the error message &#8220;You do not have permission to edit this user.&#8221; but after that message the complete form with all data will also be shown. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: KAL Case</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1217</link>
		<dc:creator>KAL Case</dc:creator>
		<pubDate>Sat, 06 Jan 2007 17:55:14 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1217</guid>
		<description>Oh dear - I&#039;ve just found out about this via Damien Mulley&#039;s blog.  We get a fair few of spammy comments on our blog, so this could be an issue for us. 

I&#039;m a complete non-techy person, however - is there a way to explain the fix for this in layman&#039;s terms for a computer-illiterate like myself? 

Many thanks!</description>
		<content:encoded><![CDATA[<p>Oh dear &#8211; I&#8217;ve just found out about this via Damien Mulley&#8217;s blog.  We get a fair few of spammy comments on our blog, so this could be an issue for us. </p>
<p>I&#8217;m a complete non-techy person, however &#8211; is there a way to explain the fix for this in layman&#8217;s terms for a computer-illiterate like myself? </p>
<p>Many thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress Security Problem - Irish SEO, Marketing &#38; Webmaster Discussion</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1216</link>
		<dc:creator>Wordpress Security Problem - Irish SEO, Marketing &#38; Webmaster Discussion</dc:creator>
		<pubDate>Sat, 06 Jan 2007 14:35:09 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1216</guid>
		<description>[...] Wordpress Security Problem   Serious email spam issue for Irish Wordpress blogs. - Business. Jason Roe - Web design, Development, SEO Advice  __________________ Armchair.ie &#124; work&#124;Blog Tips&#124;Seo tips&#124;EU Domain ScandalTechie Toys&#124; Gadgets   Do you want your vbulletin site to be search engine friendly? Click here for info [...]</description>
		<content:encoded><![CDATA[<p>[...] Wordpress Security Problem   Serious email spam issue for Irish Wordpress blogs. &#8211; Business. Jason Roe &#8211; Web design, Development, SEO Advice  __________________ Armchair.ie | work|Blog Tips|Seo tips|EU Domain ScandalTechie Toys| Gadgets   Do you want your vbulletin site to be search engine friendly? Click here for info [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wordpress Security Hole</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1215</link>
		<dc:creator>Wordpress Security Hole</dc:creator>
		<pubDate>Sat, 06 Jan 2007 14:26:44 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1215</guid>
		<description>[...] Wordpress Security Hole Written on January 6th, 2007 by michele      Jason spotted a very serious security issue in Wordpress that does&#8217;t seem to have been addressed properly even though it was reported back in September of last year. [...]</description>
		<content:encoded><![CDATA[<p>[...] Wordpress Security Hole Written on January 6th, 2007 by michele      Jason spotted a very serious security issue in Wordpress that does&#8217;t seem to have been addressed properly even though it was reported back in September of last year. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Damien Mulley &#187; Blog Archive &#187; Attention Irish Wordpress users - Security Exploit to watch out for</title>
		<link>http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1214</link>
		<dc:creator>Damien Mulley &#187; Blog Archive &#187; Attention Irish Wordpress users - Security Exploit to watch out for</dc:creator>
		<pubDate>Sat, 06 Jan 2007 14:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://jasonroe.me/blog/serious-email-spam-issue-for-irish-wordpress-blogs/#comment-1214</guid>
		<description>[...] Jason has blogged about a Wordpress security issue which allows people to get the emails of all posters and event people who leave comments. Disabling public registration seems to fix it but see Jason&#8217;s blog for more.  blogs ireland irish irishblogs security wordpress [...]</description>
		<content:encoded><![CDATA[<p>[...] Jason has blogged about a Wordpress security issue which allows people to get the emails of all posters and event people who leave comments. Disabling public registration seems to fix it but see Jason&#8217;s blog for more.  blogs ireland irish irishblogs security wordpress [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->