<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: WordPress 2.0.3: Nonces</title>
	<atom:link href="http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/feed/" rel="self" type="application/rss+xml" />
	<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/</link>
	<description>WordPress puts food on my table.</description>
	<pubDate>Fri, 18 Jul 2008 23:32:13 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
		<item>
		<title>By: Nerdaphernalia &#187; JavaScript Pull-Quotes 2.0</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-89337</link>
		<dc:creator>Nerdaphernalia &#187; JavaScript Pull-Quotes 2.0</dc:creator>
		<pubDate>Mon, 09 Jun 2008 03:09:30 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-89337</guid>
		<description>[...] Improved security via nonces [...]</description>
		<content:encoded><![CDATA[<p>[...] Improved security via nonces [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: More Thought on numbers used ounce(i.e. nounce) &#124; wehuberconsultingllc.com</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88934</link>
		<dc:creator>More Thought on numbers used ounce(i.e. nounce) &#124; wehuberconsultingllc.com</dc:creator>
		<pubDate>Mon, 28 Apr 2008 00:39:28 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88934</guid>
		<description>[...] Upgrade plugin is an unnecessary precaution, I am puzzled why it did not work.&#160; According to Mark&#8217;s post on nounces, it sounds like in theory this &#34;number use ounce&#34; should still be valid if you [...]</description>
		<content:encoded><![CDATA[<p>[...] Upgrade plugin is an unnecessary precaution, I am puzzled why it did not work.&#160; According to Mark&#8217;s post on nounces, it sounds like in theory this &quot;number use ounce&quot; should still be valid if you [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CSRF Slides &#171; Mark on WordPress</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88735</link>
		<dc:creator>CSRF Slides &#171; Mark on WordPress</dc:creator>
		<pubDate>Tue, 15 Apr 2008 03:08:44 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88735</guid>
		<description>[...] Cross-Site Request Forgeries (CSRF).  We tackled this security issue in WordPress two years ago.  I wrote an article about the issue that still holds true (plugin authors should definitely give it a read if any of [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross-Site Request Forgeries (CSRF).  We tackled this security issue in WordPress two years ago.  I wrote an article about the issue that still holds true (plugin authors should definitely give it a read if any of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FreeMoby &#187; Blog Archive &#187; Wordpress Plugin: Cookie Timeout</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88591</link>
		<dc:creator>FreeMoby &#187; Blog Archive &#187; Wordpress Plugin: Cookie Timeout</dc:creator>
		<pubDate>Sat, 22 Mar 2008 23:10:53 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88591</guid>
		<description>[...] Added nonce security. [...]</description>
		<content:encoded><![CDATA[<p>[...] Added nonce security. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CSRF Attack on WordPress &#183; Pressed Words</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88384</link>
		<dc:creator>CSRF Attack on WordPress &#183; Pressed Words</dc:creator>
		<pubDate>Wed, 13 Feb 2008 16:47:22 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88384</guid>
		<description>[...] guards against CSRF attacks in general by confirming actions that don&#8217;t seem quite right (i.e. when the nonces don&#8217;t check out), but this attack hides all of the confirmation message except the approval button, which appears [...]</description>
		<content:encoded><![CDATA[<p>[...] guards against CSRF attacks in general by confirming actions that don&#8217;t seem quite right (i.e. when the nonces don&#8217;t check out), but this attack hides all of the confirmation message except the approval button, which appears [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Plugin Sicherheitsmöglichkeiten &#124; bueltge.de [by:ltge.de]</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88257</link>
		<dc:creator>WordPress Plugin Sicherheitsmöglichkeiten &#124; bueltge.de [by:ltge.de]</dc:creator>
		<pubDate>Thu, 31 Jan 2008 13:01:32 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88257</guid>
		<description>[...] WordPress 2.0.3: Nonces         Artikel #539, 31. Januar 2008 &#183; Code, PHP, Tipps, WordPress &#183; 0 Kommentare  Tags: Code, Entwicklung, PHP, Plugin, Sicherheit, WordPress, WP  Gelesen: 6 &#183; heute: 6 &#183; zuletzt: 31. Jan 08, 14:00  Kommentar-Feed zum Artikel, TrackBack URL  Hinzuf&#252;gen zu: Technorati, del.icio.us, Mr. Wong, LinkARENA, SEOigg [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress 2.0.3: Nonces         Artikel #539, 31. Januar 2008 &middot; Code, PHP, Tipps, WordPress &middot; 0 Kommentare  Tags: Code, Entwicklung, PHP, Plugin, Sicherheit, WordPress, WP  Gelesen: 6 &middot; heute: 6 &middot; zuletzt: 31. Jan 08, 14:00  Kommentar-Feed zum Artikel, TrackBack URL  Hinzuf&uuml;gen zu: Technorati, del.icio.us, Mr. Wong, LinkARENA, SEOigg [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: g30rg3 Blog &#187; XSRF bajo Dean&#8217;s Permalinks Migration 1.0</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88060</link>
		<dc:creator>g30rg3 Blog &#187; XSRF bajo Dean&#8217;s Permalinks Migration 1.0</dc:creator>
		<pubDate>Mon, 21 Jan 2008 08:14:29 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-88060</guid>
		<description>[...] Explicación Debido a la falta de sanitización de la variable: &#8220;dean_pm_config[&#8217;oldstructure&#8217;]&#8221; es posible inyectar código malicioso (XSS), aunque esta cuenta con unos filtros estos no están ni por un poco preparados para sanitizar de manera adecuada la información que se piensa guardar, lo cual nos lleva a la posibilidad de inyectar código malicioso (XSS) dentro de esta misma. Sin embargo para que esto funcione se requiere que el usuario inyecte el código malicioso (XSS), lo cual se puede lograr diseñando una pagina maliciosa para hacer que el usuario realice esta acción sin darse darse cuenta (XSRF) el cual es posible debido a que el plugin no hace uso de las funciones para proteger formularios incluidas en WordPress (WP-Nonces). [...]</description>
		<content:encoded><![CDATA[<p>[...] Explicación Debido a la falta de sanitización de la variable: &#8220;dean_pm_config[&#8217;oldstructure&#8217;]&#8221; es posible inyectar código malicioso (XSS), aunque esta cuenta con unos filtros estos no están ni por un poco preparados para sanitizar de manera adecuada la información que se piensa guardar, lo cual nos lleva a la posibilidad de inyectar código malicioso (XSS) dentro de esta misma. Sin embargo para que esto funcione se requiere que el usuario inyecte el código malicioso (XSS), lo cual se puede lograr diseñando una pagina maliciosa para hacer que el usuario realice esta acción sin darse darse cuenta (XSRF) el cual es posible debido a que el plugin no hace uso de las funciones para proteger formularios incluidas en WordPress (WP-Nonces). [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan From Internet Marketing Blog</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-86595</link>
		<dc:creator>Ryan From Internet Marketing Blog</dc:creator>
		<pubDate>Sat, 05 Jan 2008 22:59:49 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-86595</guid>
		<description>You should write another post like this about the newest Wordpress release.


Ryan</description>
		<content:encoded><![CDATA[<p>You should write another post like this about the newest WordPress release.</p>
<p>Ryan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ruvoqxox</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-73310</link>
		<dc:creator>Ruvoqxox</dc:creator>
		<pubDate>Mon, 15 Oct 2007 16:52:09 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-73310</guid>
		<description>generic l441 xanax
 &lt;a href="http://xa2.freehostia.com/1/generic-l441-xanax.php " rel="nofollow"&gt;  generic l441 xanax&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>generic l441 xanax<br />
 <a href="http://xa2.freehostia.com/1/generic-l441-xanax.php " rel="nofollow">  generic l441 xanax</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: List Draft Posts: a WordPress plugin : Losing it[1]</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-73260</link>
		<dc:creator>List Draft Posts: a WordPress plugin : Losing it[1]</dc:creator>
		<pubDate>Mon, 15 Oct 2007 06:44:04 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-73260</guid>
		<description>[...] really nice article by Leonid Mamchenkov on how to make options pages for WordPress plugins, and this piece by Mark Jaquith on how to make such things more [...]</description>
		<content:encoded><![CDATA[<p>[...] really nice article by Leonid Mamchenkov on how to make options pages for WordPress plugins, and this piece by Mark Jaquith on how to make such things more [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cavojpop</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-71710</link>
		<dc:creator>Cavojpop</dc:creator>
		<pubDate>Fri, 05 Oct 2007 18:08:18 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-71710</guid>
		<description>no rx valium
 &lt;a href="http://v33.freehostia.com/v11/no-rx-valium.html " rel="nofollow"&gt;no rx valium&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>no rx valium<br />
 <a href="http://v33.freehostia.com/v11/no-rx-valium.html " rel="nofollow">no rx valium</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pharmamaster</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-71677</link>
		<dc:creator>pharmamaster</dc:creator>
		<pubDate>Fri, 05 Oct 2007 12:49:32 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-71677</guid>
		<description>Great post!!!
Im using wordpress 2.2.3
http://soundproducer.blogspot.com/</description>
		<content:encoded><![CDATA[<p>Great post!!!<br />
Im using wordpress 2.2.3<br />
<a href="http://soundproducer.blogspot.com/" rel="nofollow">http://soundproducer.blogspot.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lyhouxox</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-71589</link>
		<dc:creator>Lyhouxox</dc:creator>
		<pubDate>Fri, 05 Oct 2007 03:11:06 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-71589</guid>
		<description>big pizza sausage trinity
 &lt;a href="http://qe.freehostia.com/pizz/big-pizza-sausage-trinity.html " rel="nofollow"&gt;big pizza sausage trinity&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>big pizza sausage trinity<br />
 <a href="http://qe.freehostia.com/pizz/big-pizza-sausage-trinity.html " rel="nofollow">big pizza sausage trinity</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Writing Secure WordPress Plugins - Using attribute_escape and wp_nonce functions</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-62438</link>
		<dc:creator>Writing Secure WordPress Plugins - Using attribute_escape and wp_nonce functions</dc:creator>
		<pubDate>Mon, 20 Aug 2007 17:02:15 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-62438</guid>
		<description>[...] http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/ http://www.wordpress.com [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/" rel="nofollow">http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/</a> <a href="http://www.wordpress.com" rel="nofollow">http://www.wordpress.com</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cross Site Scripting (XSS) &#124; bueltge.de [by:ltge.de]</title>
		<link>http://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-59367</link>
		<dc:creator>Cross Site Scripting (XSS) &#124; bueltge.de [by:ltge.de]</dc:creator>
		<pubDate>Thu, 09 Aug 2007 11:49:20 +0000</pubDate>
		<guid isPermaLink="false">https://markjaquith.wordpress.com/2006/06/02/wordpress-203-nonces/#comment-59367</guid>
		<description>[...] WordPress Nonces [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress Nonces [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
