<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress Admin Password can be Reset by Anyone (Fix Provided)</title>
	<atom:link href="http://www.hostscope.com/templature/wordpress-admin-password-can-be-reset-by-anyone-fix-provided/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hostscope.com/templature/wordpress-admin-password-can-be-reset-by-anyone-fix-provided/</link>
	<description>WordPress is the new LAMP.</description>
	<lastBuildDate>Wed, 26 May 2010 08:18:21 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: jrrl</title>
		<link>http://www.hostscope.com/templature/wordpress-admin-password-can-be-reset-by-anyone-fix-provided/comment-page-1/#comment-5503</link>
		<dc:creator>jrrl</dc:creator>
		<pubDate>Wed, 12 Aug 2009 01:29:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.hostscope.com/?p=363#comment-5503</guid>
		<description>The exploit should work with any user name that is allowed to reset their password.  If reset requires admin approval, then nada will happen (although you won&#039;t be able to tell the real resets from the fake in your admin email).  If your administrator account (or accounts) have a different user name, it will require the bad guy to figure out those user names.

Yet another reason to use a user name other than &quot;admin&quot;, although I am all too guilty of sticking with &quot;admin&quot; on some of my sites (but I patched them all :-P).</description>
		<content:encoded><![CDATA[<p>The exploit should work with any user name that is allowed to reset their password.  If reset requires admin approval, then nada will happen (although you won&#8217;t be able to tell the real resets from the fake in your admin email).  If your administrator account (or accounts) have a different user name, it will require the bad guy to figure out those user names.</p>
<p>Yet another reason to use a user name other than &#8220;admin&#8221;, although I am all too guilty of sticking with &#8220;admin&#8221; on some of my sites (but I patched them all <img src='http://www.hostscope.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> ).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jason</title>
		<link>http://www.hostscope.com/templature/wordpress-admin-password-can-be-reset-by-anyone-fix-provided/comment-page-1/#comment-5502</link>
		<dc:creator>Jason</dc:creator>
		<pubDate>Wed, 12 Aug 2009 01:18:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.hostscope.com/?p=363#comment-5502</guid>
		<description>Does the exploit work if the admin user has been deleted and other users not named &quot;admin&quot; are Administrators? i.e. can they sniff that out? then the question is, would they bother?</description>
		<content:encoded><![CDATA[<p>Does the exploit work if the admin user has been deleted and other users not named &#8220;admin&#8221; are Administrators? i.e. can they sniff that out? then the question is, would they bother?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jrrl</title>
		<link>http://www.hostscope.com/templature/wordpress-admin-password-can-be-reset-by-anyone-fix-provided/comment-page-1/#comment-5499</link>
		<dc:creator>jrrl</dc:creator>
		<pubDate>Wed, 12 Aug 2009 00:01:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.hostscope.com/?p=363#comment-5499</guid>
		<description>It stops the reset if the reset key (the long string of gibberish in your email if you ask for a reset) is an array.  The old method just checked to make sure the value wasn&#039;t empty.  The exploit tricks the wp-login script by tweaking the arguments to wp-login.php (in the URL) to make the key into an array.</description>
		<content:encoded><![CDATA[<p>It stops the reset if the reset key (the long string of gibberish in your email if you ask for a reset) is an array.  The old method just checked to make sure the value wasn&#8217;t empty.  The exploit tricks the wp-login script by tweaking the arguments to wp-login.php (in the URL) to make the key into an array.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary Stephen Callaghan</title>
		<link>http://www.hostscope.com/templature/wordpress-admin-password-can-be-reset-by-anyone-fix-provided/comment-page-1/#comment-5498</link>
		<dc:creator>Gary Stephen Callaghan</dc:creator>
		<pubDate>Tue, 11 Aug 2009 23:55:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.hostscope.com/?p=363#comment-5498</guid>
		<description>&lt;strong&gt;Thanks for posting this, this really will save alot of annoyance. What exactly does this new line of code do ? &lt;/strong&gt;</description>
		<content:encoded><![CDATA[<p><strong>Thanks for posting this, this really will save alot of annoyance. What exactly does this new line of code do ? </strong></p>
]]></content:encoded>
	</item>
</channel>
</rss>

