<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Net Data Design, LLC Blog &#187; trackback</title>
	<atom:link href="http://blog.nddllc.com/tag/trackback/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.nddllc.com</link>
	<description>Software and Database Development Blog</description>
	<lastBuildDate>Fri, 20 Aug 2010 16:33:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1-alpha</generator>
		<item>
		<title>WordPress Releases 2.8.6 Security Patch</title>
		<link>http://blog.nddllc.com/2009/11/12/wordpress-releases-2-8-6-security-patch/</link>
		<comments>http://blog.nddllc.com/2009/11/12/wordpress-releases-2-8-6-security-patch/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 22:25:50 +0000</pubDate>
		<dc:creator>Chris Smith</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[NDD Websites]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[trackback]]></category>

		<guid isPermaLink="false">http://blog.nddllc.com/?p=33</guid>
		<description><![CDATA[2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended. The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue [...]]]></description>
			<content:encoded><![CDATA[<p>2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.</p>
<p>The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.nddllc.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.nddllc.com/2009/11/12/wordpress-releases-2-8-6-security-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.8.5 has been released</title>
		<link>http://blog.nddllc.com/2009/10/23/wordpress-2-8-5-has-been-released/</link>
		<comments>http://blog.nddllc.com/2009/10/23/wordpress-2-8-5-has-been-released/#comments</comments>
		<pubDate>Fri, 23 Oct 2009 12:23:17 +0000</pubDate>
		<dc:creator>Chris Smith</dc:creator>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[denial-of-service]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[trackback]]></category>

		<guid isPermaLink="false">http://blog.nddllc.com/?p=16</guid>
		<description><![CDATA[This update is a “security hardening release” – intended to protect against potential problems, and one issue already in the wild.]]></description>
			<content:encoded><![CDATA[<p>This update is a “security hardening release” – intended to protect against potential problems, and one issue already in the wild.</p>
<ul>
<li>A fix for the Trackback Denial-of-Service attack that is currently being seen.</li>
<li>Removal of areas within the code where php code in variables was evaluated.</li>
<li>Switched the file upload functionality to be whitelisted for all users including Admins.</li>
<li>Retiring of the two importers of Tag data from old plugins.</li>
</ul>
<p>You can get all the details here from <a href="http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/" target="_blank">WordPress.Org</a>.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.nddllc.com/2009/10/23/wordpress-2-8-5-has-been-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
