<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>WassUp Forums &#187; Topic: Vulnerability in /lib !</title>
		<link>http://www.wpwp.org/forums/topic/vulnerability-in-lib</link>
		<description>WassUp Forums &raquo; Topic: Vulnerability in /lib !</description>
		<language>en-US</language>
		<pubDate>Fri, 10 Feb 2012 17:25:49 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.3</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.wpwp.org/forums/search.php</link>
		</textInput>
		<atom:link href="http://www.wpwp.org/forums/rss/topic/vulnerability-in-lib" rel="self" type="application/rss+xml" />

		<item>
			<title>RogerDue on "Vulnerability in /lib !"</title>
			<link>http://www.wpwp.org/forums/topic/vulnerability-in-lib#post-968</link>
			<pubDate>Wed, 20 Jan 2010 23:05:47 +0000</pubDate>
			<dc:creator>RogerDue</dc:creator>
			<guid isPermaLink="false">968@http://www.wpwp.org/forums/</guid>
			<description>&#60;p&#62;Helene,&#60;br /&#62;
I would like to thank you for pointing out the &#34;Bad Behavior&#34; plugin!!! I installed it yesterday on 3 WP site, signed up for Project Honey Pot, &#38;amp; enabled http:BL. Within only a few hours the &#34;Bad Behavior&#34; plugin blocked traffic, some of which was caught via http:BL. Of course I also have Akismet activated. What is most interesting about all of this is that the site I have been working on recently is only a few months old and already I am getting this kind of malicious traffic. Thanks!
&#60;/p&#62;</description>
		</item>
		<item>
			<title>helene on "Vulnerability in /lib !"</title>
			<link>http://www.wpwp.org/forums/topic/vulnerability-in-lib#post-962</link>
			<pubDate>Sun, 10 Jan 2010 07:38:58 +0000</pubDate>
			<dc:creator>helene</dc:creator>
			<guid isPermaLink="false">962@http://www.wpwp.org/forums/</guid>
			<description>&#60;p&#62;This is a serious problem that we would like to fix ASAP, but your information is incomplete and the attached image/warning is not related to Wassup. &#60;/p&#62;
&#60;p&#62;What versions of Wassup and wordpress were you running? Do you have any logs or messages that pinpoint Wassup as the source of the javascript vulnerability that you can show us? Did wassup record the exploit attempt and can you show us that raw record? &#60;/p&#62;
&#60;p&#62;As an aside, I recommend that you add the plugin, 'Bad Behavior' (&#60;a href=&#34;http://wordpress.org/extend/plugins/bad-behavior/&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/extend/plugins/bad-behavior/&#60;/a&#62;) to your blog security regimen. It is a gatekeeper plugin that monitors request headers for suspicious code and can block javascript and SQL injection attempts before they reach your blog.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Perspective on "Vulnerability in /lib !"</title>
			<link>http://www.wpwp.org/forums/topic/vulnerability-in-lib#post-961</link>
			<pubDate>Sat, 09 Jan 2010 08:19:44 +0000</pubDate>
			<dc:creator>Perspective</dc:creator>
			<guid isPermaLink="false">961@http://www.wpwp.org/forums/</guid>
			<description>&#60;p&#62;Guys.. it seems that you got a vulnerability in /lib folder... in my case it was in main.php if I remember well.&#60;br /&#62;
My website was hacked based on that.. exploited on one of the java script file that your programm has. &#60;/p&#62;
&#60;p&#62;I lost everything on it.. and there was hard work.. believe me. i have to start all from 0 as far as I didn't have a backup (which is my f**cking fault).&#60;/p&#62;
&#60;p&#62;After they injected the code I received the following error:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://img685.imageshack.us/img685/3727/errorsite.jpg&#34; rel=&#34;nofollow&#34;&#62;http://img685.imageshack.us/img685/3727/errorsite.jpg&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;You might have a look on the plugin codding again and fix it.&#60;br /&#62;
Personally I won't use wassup for my web-blog anymore.&#60;/p&#62;
&#60;p&#62;Wanted to report it.. maybe's useful for you.&#60;/p&#62;
&#60;p&#62;Cheers.
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>

