<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MinhMoc&#039;s Blog &#187; wordpress</title>
	<atom:link href="http://www.minhmoc.com/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.minhmoc.com</link>
	<description>Sống là phải sống thật với bản thân mình</description>
	<lastBuildDate>Thu, 13 May 2010 14:45:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>WordPress 2.6.5</title>
		<link>http://www.minhmoc.com/2008/12/02/wordpress-265/</link>
		<comments>http://www.minhmoc.com/2008/12/02/wordpress-265/#comments</comments>
		<pubDate>Tue, 02 Dec 2008 03:04:16 +0000</pubDate>
		<dc:creator>MinhMoc</dc:creator>
				<category><![CDATA[Web Development]]></category>
		<category><![CDATA[minhmoc]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.minhmoc.com/?p=90</guid>
		<description><![CDATA[WordPress 2.6.5 is immediately available and fixes one security problem and three bugs. We recommend everyone upgrade to this release.<a href="http://www.minhmoc.com/2008/12/02/wordpress-265/" class="searchmore">Read the Rest...</a><div class="clr"></div>]]></description>
			<content:encoded><![CDATA[<p><a href="http://wordpress.org/download/" target="_blank"><img class="alignleft" style="margin: 5px;" title="WordPress" src="http://s.wordpress.org/images/org-iphonebutton.png" alt="" width="67" height="96" />WordPress 2.6.5 is immediately available and fixes one security problem and three bugs</a>. We recommend everyone upgrade to this release.</p>
<p>The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2.x. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.</p>
<p>2.6.5 contains three other small fixes in addition to the XSS fix. The first prevents accidentally saving post meta information to a revision. The second prevents XML-RPC from fetching incorrect post types. The third adds some user ID sanitization during bulk delete requests. For a list of changed files, consult the <a href="http://trac.wordpress.org/changeset?old_path=tags%2F2.6.3&amp;old=&amp;new_path=tags%2F2.6.5&amp;new=" target="_blank">full changeset</a> between 2.6.3 and 2.6.5.</p>
<p>Note that we are skipping version 2.6.4 and jumping from 2.6.3 to 2.6.5 to avoid confusion with a fake 2.6.4 release that made the rounds. There is not and never will be a version 2.6.4.</p>
<p><a href="http://wordpress.org/download/" target="_blank">Get WordPress 2.6.5</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.minhmoc.com/2008/12/02/wordpress-265/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.6.3</title>
		<link>http://www.minhmoc.com/2008/11/12/wordpress-263/</link>
		<comments>http://www.minhmoc.com/2008/11/12/wordpress-263/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 03:38:25 +0000</pubDate>
		<dc:creator>MinhMoc</dc:creator>
				<category><![CDATA[Web Development]]></category>
		<category><![CDATA[minhmoc]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.minhmoc.com/?p=82</guid>
		<description><![CDATA[WordPress is a state-of-the-art publishing platform with a focus on aesthetics, web standards, and usability. WordPress is both free and<a href="http://www.minhmoc.com/2008/11/12/wordpress-263/" class="searchmore">Read the Rest...</a><div class="clr"></div>]]></description>
			<content:encoded><![CDATA[<p>WordPress is a state-of-the-art publishing platform with a focus on aesthetics, web standards, and usability. WordPress is both free and priceless at the same time.</p>
<p>WordPress đã phát hành phiên bản 2.6.3. Các bạn có thể download tại đây <a href="http://wordpress.org/download/" target="_blank">http://wordpress.org/download/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.minhmoc.com/2008/11/12/wordpress-263/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.6.2</title>
		<link>http://www.minhmoc.com/2008/09/09/wordpress-262/</link>
		<comments>http://www.minhmoc.com/2008/09/09/wordpress-262/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 02:37:00 +0000</pubDate>
		<dc:creator>MinhMoc</dc:creator>
				<category><![CDATA[Web Development]]></category>
		<category><![CDATA[minhmoc]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.minhmoc.com/?p=56</guid>
		<description><![CDATA[Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand().  With his help<a href="http://www.minhmoc.com/2008/09/09/wordpress-262/" class="searchmore">Read the Rest...</a><div class="clr"></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="alignnone" title="wordpress" src="http://www.minhmoc.com/wp-admin/images/logo-login.gif" alt="" width="290" height="66" /></p>
<p><a href="http://www.suspekt.org/" target="_blank">Stefan Esser</a> recently warned developers of the dangers of <a href="http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/" target="_blank">SQL Column Truncation</a> and the <a href="http://www.suspekt.org/2008/08/17/mt_srand-and-not-so-random-numbers/" target="_blank">weakness of mt_rand()</a>.  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.  Stefan Esser will release details of the complete attack shortly.  The attack is difficult to accomplish,  but its mere possibility means we recommend upgrading to 2.6.2.</p>
<p><span id="more-56"></span>Other PHP apps are susceptible to this class of attack.  To protect all of your apps, grab the <a href="http://www.suspekt.org/2008/08/22/suhosin-0926-improved-randomness/" target="_blank">latest version of Suhosin</a>.  If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit.  You should still upgrade to 2.6.2 if you allow open user registration so as to prevent the possibility of passwords being randomized.</p>
<p>2.6.2 also contains a <a href="http://trac.wordpress.org/query?status=closed&amp;milestone=2.6.2&amp;resolution=fixed&amp;order=priority" target="_blank">handful of bug fixes</a>.  Check out the <a href="http://trac.wordpress.org/changeset?old_path=tags%2F2.6.1&amp;old=8849&amp;new_path=tags%2F2.6.2&amp;new=8849" target="_blank">full changeset and list of changed files</a>.</p>
<p>You can <a href="http://wordpress.org/download/" target="_blank">download WordPress 2.6.2 here</a>.</p>
<p><em>(Source <a href="http://wordpress.org/development/2008/09/wordpress-262/" target="_blank">http://wordpress.org/development/2008/09/wordpress-262/</a> )</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.minhmoc.com/2008/09/09/wordpress-262/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
