<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>follow the white rabbit &#187; Security</title>
	<atom:link href="http://blog.ftwr.co.uk/archives/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ftwr.co.uk</link>
	<description>Random commentary...</description>
	<lastBuildDate>Thu, 09 Sep 2010 21:11:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1-alpha</generator>
		<item>
		<title>WordPress 2.3.3</title>
		<link>http://blog.ftwr.co.uk/archives/2008/02/08/wordpress-233/</link>
		<comments>http://blog.ftwr.co.uk/archives/2008/02/08/wordpress-233/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 22:15:00 +0000</pubDate>
		<dc:creator>westi</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.ftwr.co.uk/archives/2008/02/08/wordpress-233/</guid>
		<description><![CDATA[WordPress 2.3.3 was released recently so if you haven&#8217;t updated yet take this as a friendly reminder as it includes a security fix. You can read a more detailed look at the changes over on my other blog.]]></description>
			<content:encoded><![CDATA[<p><a href="http://wordpress.org/development/2008/02/wordpress-233/" onclick="pageTracker._trackPageview('/outgoing/wordpress.org/development/2008/02/wordpress-233/?referer=');">WordPress 2.3.3</a> was released recently so if you haven&#8217;t updated yet take this as a friendly reminder as it includes a security fix.  <a href="http://westi.wordpress.com/2008/02/08/wordpress-233-in-detail/" onclick="pageTracker._trackPageview('/outgoing/westi.wordpress.com/2008/02/08/wordpress-233-in-detail/?referer=');">You can read a more detailed look at the changes over on my other blog</a>.</p>
<img src="http://blog.ftwr.co.uk/9538f80a/266bbf64/CCBot/1.0 (+http://www.commoncrawl.org/bot.html).gif" />]]></content:encoded>
			<wfw:commentRss>http://blog.ftwr.co.uk/archives/2008/02/08/wordpress-233/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.3.2</title>
		<link>http://blog.ftwr.co.uk/archives/2007/12/30/wordpress-232/</link>
		<comments>http://blog.ftwr.co.uk/archives/2007/12/30/wordpress-232/#comments</comments>
		<pubDate>Sun, 30 Dec 2007 08:15:22 +0000</pubDate>
		<dc:creator>westi</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.ftwr.co.uk/archives/2007/12/30/wordpress-232/</guid>
		<description><![CDATA[WordPress 2.3.2 has hit the streets as a late christmas early new years present for you all it include a security fix. You can read a more detailed look at the changes over on my other blog.]]></description>
			<content:encoded><![CDATA[<p><a href="http://wordpress.org/development/2007/12/wordpress-232/" onclick="pageTracker._trackPageview('/outgoing/wordpress.org/development/2007/12/wordpress-232/?referer=');">WordPress 2.3.2 has hit the streets</a> as a late christmas early new years present for you all it include a security fix.  <a href="http://westi.wordpress.com/2007/12/30/wordpress-232-in-detail/" onclick="pageTracker._trackPageview('/outgoing/westi.wordpress.com/2007/12/30/wordpress-232-in-detail/?referer=');">You can read a more detailed look at the changes over on my other blog</a>.</p>
<img src="http://blog.ftwr.co.uk/9538f80a/266bbf64/CCBot/1.0 (+http://www.commoncrawl.org/bot.html).gif" />]]></content:encoded>
			<wfw:commentRss>http://blog.ftwr.co.uk/archives/2007/12/30/wordpress-232/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.3.1</title>
		<link>http://blog.ftwr.co.uk/archives/2007/10/26/wordpress-231/</link>
		<comments>http://blog.ftwr.co.uk/archives/2007/10/26/wordpress-231/#comments</comments>
		<pubDate>Fri, 26 Oct 2007 21:11:55 +0000</pubDate>
		<dc:creator>westi</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.ftwr.co.uk/archives/2007/10/26/wordpress-231/</guid>
		<description><![CDATA[WordPress 2.3.1 has hit the streets including one security fix. You can read a more detailed look at the changes over on my other blog.]]></description>
			<content:encoded><![CDATA[<p><a href="http://wordpress.org/development/2007/10/wordpress-231/" onclick="pageTracker._trackPageview('/outgoing/wordpress.org/development/2007/10/wordpress-231/?referer=');">WordPress 2.3.1 has hit the streets</a> including one security fix.  <a href="http://westi.wordpress.com/2007/10/26/wordpress-231-in-detail/" onclick="pageTracker._trackPageview('/outgoing/westi.wordpress.com/2007/10/26/wordpress-231-in-detail/?referer=');">You can read a more detailed look at the changes over on my other blog</a>.</p>
<img src="http://blog.ftwr.co.uk/9538f80a/266bbf64/CCBot/1.0 (+http://www.commoncrawl.org/bot.html).gif" />]]></content:encoded>
			<wfw:commentRss>http://blog.ftwr.co.uk/archives/2007/10/26/wordpress-231/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Version Check v1.0</title>
		<link>http://blog.ftwr.co.uk/archives/2005/12/08/wordpress-version-check-v10/</link>
		<comments>http://blog.ftwr.co.uk/archives/2005/12/08/wordpress-version-check-v10/#comments</comments>
		<pubDate>Thu, 08 Dec 2005 19:06:01 +0000</pubDate>
		<dc:creator>westi</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[plugin]]></category>

		<guid isPermaLink="false">http://blog.ftwr.co.uk/?p=134</guid>
		<description><![CDATA[WordPress Version Check v1.00 is now available. The follow changes have been made in v1.00: Added support for WordPress v2.0-RC1 (see below for a screen shot) Added timeout to XML-RPC calls. Updated version number to 1.00. Version 1.00 can be downloaded here: pjw_wp_version_monitor.1.00.zip]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.ftwr.co.uk/wordpress/wp-version-check/">WordPress Version Check</a> v1.00 is now available.  </p>
<p>The follow changes have been made in v1.00:</p>
<ol>
<li>Added support for WordPress v2.0-RC1 (see below for a screen shot)</li>
<li>Added timeout to XML-RPC calls.</li>
<li>Updated version number to 1.00.</li>
</ol>
<p><span id="more-134"></span></p>
<p><a href="http://blog.ftwr.co.uk/wp-content/dropbox/wp2.0versioncheck.png" title="WordPress Version Check with WordPress-2.0-RC1"><img src="http://blog.ftwr.co.uk/wp-content/dropbox/thumb-wp2.0versioncheck.png" alt="WordPress Version Check with WordPress-2.0-RC1" /></a></p>
<p>Version 1.00 can be downloaded here: <a href='http://blog.ftwr.co.uk/wp-content/dropbox/pjw_wp_version_monitor.1.00.zip'>pjw_wp_version_monitor.1.00.zip</a></p>
<img src="http://blog.ftwr.co.uk/9538f80a/266bbf64/CCBot/1.0 (+http://www.commoncrawl.org/bot.html).gif" />]]></content:encoded>
			<wfw:commentRss>http://blog.ftwr.co.uk/archives/2005/12/08/wordpress-version-check-v10/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>WordPress Version Check v0.90</title>
		<link>http://blog.ftwr.co.uk/archives/2005/07/27/wordpress-version-check-v090/</link>
		<comments>http://blog.ftwr.co.uk/archives/2005/07/27/wordpress-version-check-v090/#comments</comments>
		<pubDate>Wed, 27 Jul 2005 21:20:29 +0000</pubDate>
		<dc:creator>westi</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[plugin]]></category>

		<guid isPermaLink="false">http://blog.ftwr.co.uk/?p=100</guid>
		<description><![CDATA[WordPress Version Check v0.90 is now available. The follow minor changes have been made in v0.90: Improved check for Tiger Admin Plugin &#8211; When detected alternate CSS is used for message display. Thanks to MarkJ for the new and improved CSS. readme.txt included in the zip file with installation instructions. Updated version number to 0.90. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.ftwr.co.uk/archives/2005/06/27/wordpress-version-check/">WordPress Version Check</a> v0.90 is now available.  </p>
<p>The follow minor changes have been made in v0.90:</p>
<ol>
<li>Improved check for Tiger Admin Plugin &#8211; When detected alternate CSS is used for message display.  Thanks to <a href="http://txfx.net" onclick="pageTracker._trackPageview('/outgoing/txfx.net?referer=');">MarkJ</a> for the new and improved CSS.</li>
<li>readme.txt included in the zip file with installation instructions.</li>
<li>Updated version number to 0.90.</li>
</ol>
<p>The following new features have been added in v0.90:</p>
<ol>
<li>Added support for <a href="http://somethingunpredictable.com/wp-dash/" onclick="pageTracker._trackPageview('/outgoing/somethingunpredictable.com/wp-dash/?referer=');">wp-dash</a> plugin with a builtin WordPress Version Check widget.</li>
<li>For advanced users who are installing this plugin on multiple blogs that they administer for others you can now enable email notification of new messages. </li>
</ol>
<p><span id="more-100"></span><br />
The email notification feature works in the following way. If you look in the source code of the plugin near the top you will see a line with:</p>
<pre>var $admin_email = &quot;&quot;;</pre>
<p>If you put an email address in there then an email will be sent every time the message to be displayed changes.<br />
e.g.</p>
<pre>var $admin_email = &quot;user@example.com&quot;;</pre>
<p>The email received will look something like this:</p>
<pre>
Message from Version-Check/0.90
Running at http://example.com
Wordpress version is up to date.
Previous message was:
Wordpress version is out of date please upgrade.
</pre>
<p>Version 0.90 can be downloaded here: <a href='http://blog.ftwr.co.uk/wp-content/dropbox/pjw_wp_version_monitor.0.90.zip'>pjw_wp_version_monitor.0.90.zip</a></p>
<img src="http://blog.ftwr.co.uk/9538f80a/266bbf64/CCBot/1.0 (+http://www.commoncrawl.org/bot.html).gif" />]]></content:encoded>
			<wfw:commentRss>http://blog.ftwr.co.uk/archives/2005/07/27/wordpress-version-check-v090/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>WordPress Version Check v0.80</title>
		<link>http://blog.ftwr.co.uk/archives/2005/07/09/wordpress-version-check-080/</link>
		<comments>http://blog.ftwr.co.uk/archives/2005/07/09/wordpress-version-check-080/#comments</comments>
		<pubDate>Sat, 09 Jul 2005 01:26:12 +0000</pubDate>
		<dc:creator>westi</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[plugin]]></category>

		<guid isPermaLink="false">http://blog.ftwr.co.uk/?p=89</guid>
		<description><![CDATA[WordPress Version Check v0.80 is now available. Upgrade is recommended especially if you are using the Tiger Admin UI as you will now be able to see the plugin&#8217;s messages much easier. The changes for the Tiger Admin UI have been tested with v1.3 of the Tiger Admin UI plugin. There is also now a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.ftwr.co.uk/archives/2005/06/27/wordpress-version-check/">WordPress Version Check</a> v0.80 is now available.  Upgrade is recommended especially if you are using the Tiger Admin UI as you will now be able to see the plugin&#8217;s messages much easier.  The changes for the Tiger Admin UI have been tested with v1.3 of the Tiger Admin UI plugin.</p>
<p>There is also now a page for <a href="http://blog.ftwr.co.uk/wordpress/wp-version-check/">WordPress Version Check</a> which will always have the latest news.</p>
<p>Changes in v0.80:</p>
<ol>
<li>Added GPL Licence Text.</li>
<li>Added check for Tiger Admin Plugin &#8211; When detected alternate CSS is used for message display.</li>
<li>Changed default CSS so that info level messages are displayed in grey rather than green.</li>
<li>Added version info to the IXR UserAgent &#8211; To enable tracking versions of the plugin in use.</li>
<li>Used action hooks to ensure only run update checks when in admin ui.</li>
<li>Updated version number to 0.80.</li>
</ol>
<p>Version 0.80 can be downloaded here: <a href='http://blog.ftwr.co.uk/wp-content/dropbox/pjw_wp_version_monitor.0.80.zip'>pjw_wp_version_monitor.0.80.zip</a></p>
<img src="http://blog.ftwr.co.uk/9538f80a/266bbf64/CCBot/1.0 (+http://www.commoncrawl.org/bot.html).gif" />]]></content:encoded>
			<wfw:commentRss>http://blog.ftwr.co.uk/archives/2005/07/09/wordpress-version-check-080/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>WordPress Version Check</title>
		<link>http://blog.ftwr.co.uk/archives/2005/06/27/wordpress-version-check/</link>
		<comments>http://blog.ftwr.co.uk/archives/2005/06/27/wordpress-version-check/#comments</comments>
		<pubDate>Mon, 27 Jun 2005 22:02:53 +0000</pubDate>
		<dc:creator>westi</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[plugin]]></category>

		<guid isPermaLink="false">http://blog.ftwr.co.uk/?p=77</guid>
		<description><![CDATA[Recently a lot of people have been hit by a wordpress security vulnerability that was fixed with an hour of it being reported about a month ago. Why have they fallen prey to this vulnerability &#8211; because they failed to update to the latest version for one of many possible reasons: Laziness. They failed to [...]]]></description>
			<content:encoded><![CDATA[<p>Recently a lot of people have been hit by a wordpress security vulnerability that was fixed with an hour of it being reported about a month ago.  Why have they fallen prey to this vulnerability &#8211; because they failed to update to the latest version for one of many possible reasons:</p>
<ol>
<li>Laziness.</li>
<li>They failed to notice the post on the <a href="http://wordpress.org/development/2005/05/security-update/" onclick="pageTracker._trackPageview('/outgoing/wordpress.org/development/2005/05/security-update/?referer=');">dev blog</a> in their wordpress dashboard.</li>
<li>They failed to notice the number of people blogging about having upgraded.</li>
<li>etc</li>
</ol>
<p>To help alleviate this problem in the future I have crafted a simple wordpress plugin which takes a simple approach to get the users attention.  Once activated the plugin checks an XML-RPC webservice for update news displaying a message at the top of every page in the wordpress admin user-interface.  The plugin will check for an update to the message every 15 mins with an additional check being kicked off if the installed wordpress version changes so as to give instant feedback on upgrades.<br />
<span id="more-77"></span></p>
<p>The following images show three of the different responses returned by the current web-service and how they are displayed:</p>
<p class="standalone"><img src='http://blog.ftwr.co.uk/wp-content/dropbox/thumb-wp_ver_check_1.5.1.1.JPG' alt='Response for 1.5.1.1' /><br />Response for 1.5.1.1</p>
<p class="standalone"><img src='http://blog.ftwr.co.uk/wp-content/dropbox/thumb-wp_ver_check_1.5.1.2.JPG' alt='Response for 1.5.1.2' /><br />Response for 1.5.1.2</p>
<p class="standalone"><img src='http://blog.ftwr.co.uk/wp-content/dropbox/thumb-wp_ver_check_1.6alpha.JPG' alt='Response for 1.6-alpha-do-not-use' /><br />Response for 1.6-alpha-do-not-use</p>
<p><del datetime="2005-07-15T06:12:37+00:00">The plugin may be downloaded here: <a href='http://blog.ftwr.co.uk/wp-content/dropbox/pjw_wp_version_monitor.php.0.75.zip'>pjw_wp_version_monitor.php.0.75.zip</a></del><br />
<ins datetime="2005-07-15T06:12:37+00:00">An updated version is now available see: <a href="http://blog.ftwr.co.uk/wordpress/wp-version-check/">http://blog.ftwr.co.uk/wordpress/wp-version-check/</a></ins></p>
<p>Please leave any feedback and suggestions in the comments below.</p>
<img src="http://blog.ftwr.co.uk/9538f80a/266bbf64/CCBot/1.0 (+http://www.commoncrawl.org/bot.html).gif" />]]></content:encoded>
			<wfw:commentRss>http://blog.ftwr.co.uk/archives/2005/06/27/wordpress-version-check/feed/</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
	</channel>
</rss>
