<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress TinyMCE Hack Will Kill Your Blog</title>
	<atom:link href="http://wpcoop.org/wordpress-tinymce-hack-will-kill-your-blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpcoop.org/wordpress-tinymce-hack-will-kill-your-blog/</link>
	<description>Global Association of Wordpress Professionals</description>
	<lastBuildDate>Mon, 07 Feb 2011 19:29:37 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Sam</title>
		<link>http://wpcoop.org/wordpress-tinymce-hack-will-kill-your-blog/comment-page-1/#comment-158</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Wed, 20 Oct 2010 08:24:34 +0000</pubDate>
		<guid isPermaLink="false">http://wpcoop.org/?p=732#comment-158</guid>
		<description>I have noticed many queries sniffing for tinymce. It is very likely that there is a hole hackers are sniffing for.

-Sam</description>
		<content:encoded><![CDATA[<p>I have noticed many queries sniffing for tinymce. It is very likely that there is a hole hackers are sniffing for.</p>
<p>-Sam</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://wpcoop.org/wordpress-tinymce-hack-will-kill-your-blog/comment-page-1/#comment-156</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Wed, 29 Sep 2010 09:44:40 +0000</pubDate>
		<guid isPermaLink="false">http://wpcoop.org/?p=732#comment-156</guid>
		<description>I don&#039;t think you understand, TinyMCE is pure JavaScript, unless you have installed something &quot;custom&quot;, there are plenty of vulnerabilities in 3rd party TinyMCE plugins.

With pure Javascript, I mean that the exact same &quot;exploit&quot; could be done even with Javascript turned off in the browser.

If you Google a bit, you will see that there are virtually no reported issues with the Wordpress versions you mention (other than actually ISP hosts being hacked).

So the question becomes, what is different on your installs compared to a normal Wordpress install?

Can you post the execution line you mentioned here?</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think you understand, TinyMCE is pure JavaScript, unless you have installed something &#8220;custom&#8221;, there are plenty of vulnerabilities in 3rd party TinyMCE plugins.</p>
<p>With pure Javascript, I mean that the exact same &#8220;exploit&#8221; could be done even with Javascript turned off in the browser.</p>
<p>If you Google a bit, you will see that there are virtually no reported issues with the Wordpress versions you mention (other than actually ISP hosts being hacked).</p>
<p>So the question becomes, what is different on your installs compared to a normal Wordpress install?</p>
<p>Can you post the execution line you mentioned here?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jumile</title>
		<link>http://wpcoop.org/wordpress-tinymce-hack-will-kill-your-blog/comment-page-1/#comment-150</link>
		<dc:creator>Jumile</dc:creator>
		<pubDate>Mon, 28 Jun 2010 19:53:26 +0000</pubDate>
		<guid isPermaLink="false">http://wpcoop.org/?p=732#comment-150</guid>
		<description>FWIW, I&#039;m seeing a lot of persistent, direct browse attempts to &quot;/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/tinybrowser.php?type=file&amp;folder=&quot; on my blogs (always from Russian IPs, it seems). I really only noticed because of a &#039;who&#039;s online&#039; type plugin I installed recently.

There&#039;s little doubt that these URLs are deliberate, and TinyMCE does have a history of being an attack vector (e.g. the Joomla version back in 2008 with its example page). So, in short, TinyMCE *was* a vector in the past and may well be again, &#039;just javascript&#039; or not.</description>
		<content:encoded><![CDATA[<p>FWIW, I&#8217;m seeing a lot of persistent, direct browse attempts to &#8220;/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/tinybrowser.php?type=file&amp;folder=&#8221; on my blogs (always from Russian IPs, it seems). I really only noticed because of a &#8216;who&#8217;s online&#8217; type plugin I installed recently.</p>
<p>There&#8217;s little doubt that these URLs are deliberate, and TinyMCE does have a history of being an attack vector (e.g. the Joomla version back in 2008 with its example page). So, in short, TinyMCE *was* a vector in the past and may well be again, &#8216;just javascript&#8217; or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: felix</title>
		<link>http://wpcoop.org/wordpress-tinymce-hack-will-kill-your-blog/comment-page-1/#comment-148</link>
		<dc:creator>felix</dc:creator>
		<pubDate>Mon, 14 Jun 2010 14:59:22 +0000</pubDate>
		<guid isPermaLink="false">http://wpcoop.org/?p=732#comment-148</guid>
		<description>implementing tinymce forces security holes that the developers would rather you not know about</description>
		<content:encoded><![CDATA[<p>implementing tinymce forces security holes that the developers would rather you not know about</p>
]]></content:encoded>
	</item>
</channel>
</rss>

