<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WP Junkie &#187; hack</title>
	<atom:link href="http://wpjunkie.net/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpjunkie.net</link>
	<description>WordPress news for beginners and developers</description>
	<lastBuildDate>Mon, 12 Jan 2009 15:50:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Secure WordPress Scam</title>
		<link>http://wpjunkie.net/2009/01/01/secure-wordpress-scam/</link>
		<comments>http://wpjunkie.net/2009/01/01/secure-wordpress-scam/#comments</comments>
		<pubDate>Thu, 01 Jan 2009 07:30:22 +0000</pubDate>
		<dc:creator>John Tracy</dc:creator>
				<category><![CDATA[Headline]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://wpjunkie.net/?p=65</guid>
		<description><![CDATA[WordPress Hacker
I have recently come across a series of posts regarding the elusive task of securing a WordPress installation. I was curious about how this works, and wondered why this would be needed since the WordPress development community does a fantastic job of release security updates to prevent attacks on millions of blogs run by the publishing software.
In reading on this subject, I found a website called wordpresssecured.com. I thought to myself how odd it would be for millions of people to be using an unsecure code set to run ...]]></description>
			<content:encoded><![CDATA[<div id="attachment_67" class="wp-caption alignleft" style="width: 310px"><a href="http://wpjunkie.net/wp-content/uploads/2008/12/hacker.jpg"><img class="size-medium wp-image-67" title="hacker" src="http://wpjunkie.net/wp-content/uploads/2008/12/hacker-300x240.jpg" alt="WordPress Hacker" width="300" height="240" /></a><p class="wp-caption-text">WordPress Hacker</p></div>
<p>I have recently come across a series of posts regarding the elusive task of securing a WordPress installation. I was curious about how this works, and wondered why this would be needed since the WordPress development community does a fantastic job of release security updates to prevent attacks on millions of blogs run by the publishing software.</p>
<p>In reading on this subject, I found a website called <a href="http://www.wordpresssecured.com/">wordpresssecured.com</a>. I thought to myself how odd it would be for millions of people to be using an unsecure code set to run their business, or personal blog.</p>
<p>Rest assured, if you have the latest version of WordPress and keep it updated when security patches are released, you are as secure as you can be. The folks over at wordpresssecured.com are preying on the fears of many by using attacks as a means to make money.</p>
<p>They claim WordPress &#8220;as-is&#8221; is insecure and that hackers can gain access to your blog within minutes with any WordPress installation. Sure, if you have an out-of-date version of WordPress, it is true there are documented security risks and exploits to attack. However, if you are running the latest version you are safe. Here is what they are claiming they can do&#8230;</p>
<blockquote><p>Close and block all exploits that hackers know about<br />
Block unwanted BadBots from your site<br />
Stop any and all SQL injection attacks<br />
Block all folders that are open to a hacker&#8217;s attack<br />
Stop Kiddie Hackers dead in their tracks<br />
Protect your sales. Google ads and reputation</p></blockquote>
<p>They claim to have hundreds of satisfied customers and have some recommendations, but no specifics are ever given. I decided to dig a little deeper. Who is behind this site and what claims can they justify, also, what claims are they just making up?</p>
<h3>Who is making these claims?</h3>
<p>The person behind the site is James Stein. His biggest attribute to his success is simply that he has been online for more than 20 years and has been doing web development for 15.</p>
<h3>How does his secured installation work?</h3>
<p>Mr. Stein alleges that hackers know all of the code for wordpress and that any version of wordpress, be it an old version, or the version that came out yesterday are all completely vulnerable, simply because people know all of the code associated with it.</p>
<blockquote><p>Fact is updating means nothing, the code is not encrypted and hackers have access to the code just like you do..</p>
<p>If you change how wordpress functions then it is very obvious that hackers can not hack it as they will have no idea what changes you made.</p></blockquote>
<p>His installation technique is to change how WordPress functions. This is ludicrous! By changing how WordPress functions, he removes what makes WordPress powerful&#8230; an entire community of developers and users working together to make everything work together seamlessly.</p>
<h3>Separating Truth from Marketing Hype</h3>
<p>The truth behind having a secure WordPress installation is not using some customized WordPress bundle, it is simply updating it as updates become available.</p>
<p>He claims one of the biggest reasons for insecurity with WordPress is because the code is not encrypted, therefore anyone can see it. I must admit, to the untrained eye, this seems to be a valid argument, until one considers that WordPress is open source.</p>
<p>If this was the truth for all open source projects then it would assert that Linux is much less secure than Windows. Rather, the complete opposite is true! Because it is open source, more developers are available to see and edit the code than commercial programmers. This alone would make Mr. Stein&#8217;s version of WordPress much less secure than the freely available package.</p>
<h3>What People really have to say&#8230;</h3>
<p>AskApache posted a reply on <a href="http://agentgenius.com/?p=6185">agentgenius.com</a> about Mr. Stein:</p>
<blockquote><p>Clearly [Mr. Stein] lacks any knowledge/experience of auditing code to find a vulnerability, then creating a custom exploit for that vulnerability, creating an agent to carry the exploit payload across Internet Protocols recognized by the target (blog on HTTP), and finally delivering and executing the payload.</p></blockquote>
<p>I urge all of you to not fall into the marketing hype surrounding this product. I assure you, it is less secure, much more prone to attack, and will almost certaintly make you wish you didn&#8217;t spend a dime on this product. Don&#8217;t spend a dime and stick with what is free and more secure&#8230;</p>
<p>The latest version of WordPress!</p>
]]></content:encoded>
			<wfw:commentRss>http://wpjunkie.net/2009/01/01/secure-wordpress-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
