PHP flaw hits bloggers…
Turn off XMl-RPC function
A number of popular content management and blogging systems based on the PHP scripting language are vulnerable to a flaw in PHP’s handling of XML commands.
The security advisory service Secunia said the vulnerability, discovered by researcher James Bercegay of GulfTech Security Research, could be exploited remotely using a specially crafted XML document.
Network services company Netcraft said the vulnerability was present in popular applications such as PostNuke, WordPress, Drupal, Serendipity, phpAdsNew, phpWiki and phpMyFAQ.
The flaw affects a function called XML-RPC, a simple protocol used to make remote procedure requests to internet-based servers. Among other things, XML-RPC is used to notify directories such as Yahoo!, which use RSS feeds to obtain updates. These directories can then post the latest headlines from content generators.
When messages come to a web server that is vulnerable, the data that arrives is not checked properly.
Netcraft said the discovery of the flaw posed a problem for people running affected applications but did not have the necessary administrative rights on hosting machines to update the applications. Turning off the XMl-RPC function has been suggested as a work-around.
By Sam Varghese
July 5, 2005 - 12:10PM
More Related Articles From This Website...
- Living High On The Blog
- What Direction For My Blog
- Bloggers Learn Price Of Telling Too Much
- Computer Break-in Artists Convention
- Google and Yahoo go toe to toe…
- Hardcore Womens Porn
- Dating Predators : There Really Out There
- Dating Predators…
By Sam Varghese When Melburnian Darren Rowse began his first experiment in blogging a little over two-and-a-half years ago, he was part of a group starting a new church and merely wanted to keep a record of what was being done. Darren Rowse: "People... want and need spaces to interact with others....
I know what I want... BUT!!! Guess I must be at the stage all bloggers reach... am I doing it right?. Have lots of ideas in my head but still searching for the one that clicks for me. What I do know is that at the end of the day, my....
CHICAGO : Blogs are everywhere... Increasingly, they are the place where young people go to bare their souls, to vent, to gossip. And often they do so with unabashed fervor and little self-editing, before posting their innermost thoughts. There is a freedom in it, as 23-year-old Allison Martin attests: "Since the people....
Hackers demonstrate there skills in Vegas… LAS VEGAS - Even the ATM machines were suspect at this year's Defcon conference, where hackers play intrusion games at the bleeding edge of computer security.With some of the world's best digital break-in artists pecking away at their laptops, sending email or answering mobile phones....
Snap Happy By Fran MolloyJune 25, 2005. Photo: Jessica Hromas Yahoo! and Google are going toe-to-toe again - this time offering free online photo sharing services. Yahoo!'s new Photomail integrates with Yahoo! Photo online albums and Image Search, letting users insert dozens of pictures into the body of a web-based email without exceeding attachment....
Ladies, Start Your VCRs…A womens view by Miriam Axel-Lute Feminist porn an oxymoron, or a revolution?My first experience attempting to rent porn was a miserable failure. In the windowless backroom of a suburban fetish shop my boyfriend had brought me to, next to floor-to-ceiling racks of videotapes, I asked the diminutive....
Todays Don Juan male comes in all shapes, sizes and disguises. Ted Taylor, research writer for Dating Survival Guide takes a tongue in cheek look at the types of macho male (and not so macho) predators out there, and is designed to give you some understanding of the many camaflague....
Todays Don Juan male comes in all shapes, sizes and disguises. Ted Taylor, research writer for Dating Survival Guide takes a tongue in cheek look at the types of macho male (and not so macho) predators that are out there, and is designed to give you some understanding of the....
The largest Adult Sex Personals dating website in Australia is Adult Matchmaker. Membership is free and allows access to over 700,000 members: Join for free!
Membership to Adult Friend Finder is free so join today and never be lonely again. They have members in every State of Australia waiting to meet you. Join for free!
FANTASTIC - is just one of the words that comes to mind when describing all of the fantastic services that are available to members. Click here to visit Red Hot Pie
Aussie Matchmaker
One of the fastest growing Dating websites in Australia is Aussie Matchmaker Best for long term relationships rather than just one night stands. Join for free!
Adult Friend Finder Webcams
Join now and explore your exhibitionist or voyeuristic side. Chat with other members while you watch them, they watch you, or both – don’t be shy! Click here to join!
Gay Matchmaker is the largest, and most popular online Gay dating site in Australia to-day. Over 90,000 horny members are currently registered... Gay Matchmaker
Trackback URL for this post:
http://www.sexpersonals.com.au/rss/php-flaw-hits-bloggers/107/trackback/








