<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wp-config.php security leak &#8211; hundreds of blogs hacked</title>
	<atom:link href="http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/</link>
	<description>The latest in blogging</description>
	<lastBuildDate>Wed, 11 Jan 2012 20:02:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
	<item>
		<title>By: Nash</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-16577</link>
		<dc:creator>Nash</dc:creator>
		<pubDate>Mon, 05 Sep 2011 23:09:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-16577</guid>
		<description>This is a serious problem and an invisible threat to diabetics. There&#039;s no way to trace who committed the crime. I first learned about the hacking controversy here: http://blogs.carouselindustries.com/security/security-breach-roundup-2-banks-2-schools-and-an-insulin-pump Turns out that the companies are turning a blind eye. However, the same can&#039;t be said for citigroup and other financial institutions even though those don&#039;t necessary result in death.</description>
		<content:encoded><![CDATA[<p>This is a serious problem and an invisible threat to diabetics. There&#8217;s no way to trace who committed the crime. I first learned about the hacking controversy here: <a href="http://blogs.carouselindustries.com/security/security-breach-roundup-2-banks-2-schools-and-an-insulin-pump">http://blogs.carouselindustries.com/security/security-breach-roundup-2-banks-2-schools-and-an-insulin-pump</a> Turns out that the companies are turning a blind eye. However, the same can&#8217;t be said for citigroup and other financial institutions even though those don&#8217;t necessary result in death.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mix Twist</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-16521</link>
		<dc:creator>Mix Twist</dc:creator>
		<pubDate>Sat, 03 Sep 2011 09:35:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-16521</guid>
		<description>I was still looking to make my wordpress blog more secure and this article solved my problme Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>I was still looking to make my wordpress blog more secure and this article solved my problme Thanks for sharing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Securing a new WordPress installation, part 1: wp-config.php</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-15770</link>
		<dc:creator>Securing a new WordPress installation, part 1: wp-config.php</dc:creator>
		<pubDate>Thu, 04 Aug 2011 19:53:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-15770</guid>
		<description>[...] of this behaviour happened in 2010 when hundreds of WordPress installations were hacked due to a defective configuration of a shared hosting by Network Solutions, that allowed the hackers to access the data from other [...]</description>
		<content:encoded><![CDATA[<p>[...] of this behaviour happened in 2010 when hundreds of WordPress installations were hacked due to a defective configuration of a shared hosting by Network Solutions, that allowed the hackers to access the data from other [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Business Strategies For Online Business &#124; Business Management &#124; mekagycete</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-15349</link>
		<dc:creator>Business Strategies For Online Business &#124; Business Management &#124; mekagycete</dc:creator>
		<pubDate>Fri, 15 Jul 2011 02:03:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-15349</guid>
		<description>[...] sudan da vinci code gangs of new york gangs of new york migraine rpm the social network           This entry was posted in Uncategorized. Bookmark the permalink.    [...]</description>
		<content:encoded><![CDATA[<p>[...] sudan da vinci code gangs of new york gangs of new york migraine rpm the social network           This entry was posted in Uncategorized. Bookmark the permalink.    [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vic</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-13431</link>
		<dc:creator>Vic</dc:creator>
		<pubDate>Thu, 17 Feb 2011 18:59:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-13431</guid>
		<description>Thanks for this security tips. Because of too much automation, we often neglect to set the right CHMOD for the wp-config.php file. So it&#039;s 640.</description>
		<content:encoded><![CDATA[<p>Thanks for this security tips. Because of too much automation, we often neglect to set the right CHMOD for the wp-config.php file. So it&#8217;s 640.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stephen</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-11548</link>
		<dc:creator>stephen</dc:creator>
		<pubDate>Wed, 22 Dec 2010 04:03:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-11548</guid>
		<description>most blog owner will not know what user running webserver.
chmod to 644 will always make sure the webserver can read wp-config.php. So you can chmod 640 if the files owned by webserver. even 600 is ok.

this problem in Network Solutions is the case of internal user who own probably one of these blog. This user knows where the path to wp-config.php in filesystem. and he can create a php file that read wp-config.php file in his browser.

for outside user, this not possible if the file is 640.</description>
		<content:encoded><![CDATA[<p>most blog owner will not know what user running webserver.<br />
chmod to 644 will always make sure the webserver can read wp-config.php. So you can chmod 640 if the files owned by webserver. even 600 is ok.</p>
<p>this problem in Network Solutions is the case of internal user who own probably one of these blog. This user knows where the path to wp-config.php in filesystem. and he can create a php file that read wp-config.php file in his browser.</p>
<p>for outside user, this not possible if the file is 640.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bob</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-8676</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Wed, 18 Aug 2010 22:41:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-8676</guid>
		<description>Thanks, I have been looking around trying to figure out what my wp-config should be set at ... much appreciated!</description>
		<content:encoded><![CDATA[<p>Thanks, I have been looking around trying to figure out what my wp-config should be set at &#8230; much appreciated!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harsh Agrawal</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-915</link>
		<dc:creator>Harsh Agrawal</dc:creator>
		<pubDate>Wed, 14 Apr 2010 18:40:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-915</guid>
		<description>As far as I know, Wordpress is giving liberty in file permission to make sure that wordpress will not have any issue with any web-hosting...</description>
		<content:encoded><![CDATA[<p>As far as I know, WordPress is giving liberty in file permission to make sure that wordpress will not have any issue with any web-hosting&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ankit</title>
		<link>http://www.blogtap.net/wp-config-php-security-leak-hundreds-of-blogs-hacked/comment-page-1/#comment-872</link>
		<dc:creator>Ankit</dc:creator>
		<pubDate>Tue, 13 Apr 2010 16:55:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.blogtap.net/?p=1224#comment-872</guid>
		<description>:O I didn&#039;t know about this. Recently I came to know that CERT has also issued a high alert for Cyber Attacks</description>
		<content:encoded><![CDATA[<p>:O I didn&#8217;t know about this. Recently I came to know that CERT has also issued a high alert for Cyber Attacks</p>
]]></content:encoded>
	</item>
</channel>
</rss>

