Posts Tagged ‘security’

WordPress 2.6.2

Monday, September 8th, 2008

Stefan Esser recently warned developers of the dangers of SQL Column Truncation and the weakness of mt_rand() .  With his help we worked around these problems and are now releasing WordPress 2.6.2.  If you allow open registration on your blog, you should definitely upgrade.  With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.  Stefan Esser will release details of the complete attack shortly.  The attack is difficult to accomplish,  but its mere possibility means we recommend upgrading to 2.6.2. Other PHP apps are susceptible to this class of attack.  To protect all of your apps, grab the latest version of Suhosin .  If you’ve already updated Suhosin, your existing WordPress install is already protected from the full exploit.  You should still upgrade to 2.6.2 if you allow open user registration so as to prevent the possibility of passwords being randomized. 2.6.2 also contains a handful of bug fixes .  Check out the full changeset and list of changed files

Read more:
WordPress 2.6.2

Display Flickr Images in Wordpress

Monday, September 1st, 2008

Now lets say you got your own Flickr group and want to show it of on your website but you don’t know how! Well stop what you are doing right now and read this tutorial because this is the answer you where looking for!

Read more:
Display Flickr Images in Wordpress

Wordpress Wednesdays: Widgetized Front Page

Wednesday, August 27th, 2008

For the full tutorial and a little help on how to set up a widgetized home page, check out the original post at Rob Malon dot Com. Possible Related Posts.

More here: Wordpress Wednesdays: Widgetized Front Page

Most Desired WordPress Hacks: 11 Common Requests and Fixes

Tuesday, August 26th, 2008

Other great Solutions. WordPress Custom Fields: Adding Images To Posts- This tutorial will explain how to add images to your posts using WordPress custom fields. Avoiding Duplicate Content

Continue here: Most Desired WordPress Hacks: 11 Common Requests and Fixes

WordPress Plugin Requests

Monday, August 25th, 2008

Possible Related Posts. WordPress Plugin Requests WordPress Plugin Requests Small Business Brief WordPress Plugin – Beta DealDotCom WordPress Plugin – Beta WordPress Plugin Tutorial – Hello World.

See more here:
WordPress Plugin Requests

Top 5 Wordpress Premium Theme Websites

Monday, August 18th, 2008

… themes available for Wordpress at the moment and combined with the power of Wordpress 2.6 there is no better time to switch to this oustanding open source CMS. Here is our list of favourite websites to download premium themes .

More here: Top 5 Wordpress Premium Theme Websites

Wordpress 2.6 – Screencast Tutorial – Writing Articles

Monday, August 18th, 2008

effectiveclassywebsites.com This 27 minute Screencast Training goes into depth, and will show you how to post articles and pages in Wordpress 2.6. Includes HTML buttons guide, uploading images and making files downloadable.This tutorial …

Continue here: Wordpress 2.6 – Screencast Tutorial – Writing Articles

WordPress Premium Theme – BobV3-v3.0

Friday, August 15th, 2008

BobV3 is a Premium WordPress theme suitable for any blogger who wants to take his or her blog to the next level. The theme boasts a unique design not found anywhere on the Internet. This is a light-weighted, fully-loaded WordPress 2.5 …

Read more:
WordPress Premium Theme – BobV3-v3.0