Kevin Hatfield's Blog

Kevin's blurry train of thought……

Archive for February, 2008

WordPress 2.3.3 Update – Security Vulnerability

Tuesday, February 5th, 2008

If you are on many different web hosts that have one-click installations. Either Dreamhost, with one-click installs or Fantastico/Installatron – they are not updated with the newest version yet. I would highly recommend to manually install this security fix. Download the ‘xmlrpc.php’ and replace your current xmlrpc.php in your wordpress installations directory.

Download Link: http://trac.wordpress.org/browser/tags/2.3.3/xmlrpc.php?format=raw

WordPress 2.3.3 is an urgent security release. If you have registration enabled a flaw was found in the XML-RPC implementation such that a specially crafted request would allow a user to edit posts of other users on that blog. In addition to fixing this security flaw, 2.3.3 fixes a few minor bugs. If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can get the entire release here.

Also, there is a vulnerability in the WP-Forum plugin that is being actively exploited right now. If you are using this plugin, please remove it until an update is available from its author.

Since we are talking security, remember to use strong passwords and change them regularly. While you’re updating WP and your plugins, consider refreshing your passwords.

Funny Videos :)

Monday, February 4th, 2008

Family Guy! – Best Moments

Best Moments 2

Will Ferrell Super Bowl

FedEx Superbowl 2008

Matt Damon being funny…I ran across these earlier and thought it was worthwhile to share: