<?xml version="1.0" encoding="iso-8859-1"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: do you trust all wordpress plugins?</title>
	<atom:link href="http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/</link>
	<description>unzusammenhaengende, durch die wirklichkeit nicht gestuetzte aussagen - die konfabulierten inhalte werden von hipslu gewoehnlich für wahr gehalten</description>
	<lastBuildDate>Mon, 10 Aug 2009 14:24:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Robert</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-33353</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Sat, 11 Aug 2007 04:49:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-33353</guid>
		<description>Excellent exercise in exposing the true flaws in *trusting* open source plugins.

As to the worries about the community keeping their cool, I&#039;m more worried about the potential harm that could always be done by a malicious coder.

Still, it is interesting that few instances have appeared like this.  There are a few plugin providers, however, that *have* put self-serving code in their offerings.  Not so much malicious, as they were invisible and not revealed on the developer&#039;s download/FAQ pages.</description>
		<content:encoded><![CDATA[<p>Excellent exercise in exposing the true flaws in *trusting* open source plugins.</p>
<p>As to the worries about the community keeping their cool, I&#8217;m more worried about the potential harm that could always be done by a malicious coder.</p>
<p>Still, it is interesting that few instances have appeared like this.  There are a few plugin providers, however, that *have* put self-serving code in their offerings.  Not so much malicious, as they were invisible and not revealed on the developer&#8217;s download/FAQ pages.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jens</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-32125</link>
		<dc:creator>Jens</dc:creator>
		<pubDate>Tue, 31 Jul 2007 15:20:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-32125</guid>
		<description>The security problem is clear... it would be fine, to have a central website, which certifies every plugin after checking. But this would cost hours, so they have to earn a lot of money by advertisment to kepp the project alive. :-)</description>
		<content:encoded><![CDATA[<p>The security problem is clear&#8230; it would be fine, to have a central website, which certifies every plugin after checking. But this would cost hours, so they have to earn a lot of money by advertisment to kepp the project alive. <img src='http://www.konfabulieren.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andres J,</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-31583</link>
		<dc:creator>Andres J,</dc:creator>
		<pubDate>Thu, 26 Jul 2007 23:42:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-31583</guid>
		<description>no english?  :sad:</description>
		<content:encoded><![CDATA[<p>no english?  <img src='http://www.konfabulieren.com/wp-includes/images/smilies/icon_sad.gif' alt=':sad:' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hipslu</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-19354</link>
		<dc:creator>hipslu</dc:creator>
		<pubDate>Wed, 25 Apr 2007 13:04:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-19354</guid>
		<description>i absolutely agree - but what i wanted to say is that i am sure, that most of the wordpress users do not think about that...</description>
		<content:encoded><![CDATA[<p>i absolutely agree &#8211; but what i wanted to say is that i am sure, that most of the wordpress users do not think about that&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rirath</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-19353</link>
		<dc:creator>Rirath</dc:creator>
		<pubDate>Wed, 25 Apr 2007 12:53:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-19353</guid>
		<description>&quot;This could panic the entire community&quot;

Surely you all realize this is nothing new what so ever and every &quot;plugin&quot; across every application / web app has had this exact same possibility?

Come on folks.  Nobody can protect you from yourself.  &quot;Don&#039;t download suspicious plug-ins from suspicious places.&quot; is the obvious solution.</description>
		<content:encoded><![CDATA[<p>&#8220;This could panic the entire community&#8221;</p>
<p>Surely you all realize this is nothing new what so ever and every &#8220;plugin&#8221; across every application / web app has had this exact same possibility?</p>
<p>Come on folks.  Nobody can protect you from yourself.  &#8220;Don&#8217;t download suspicious plug-ins from suspicious places.&#8221; is the obvious solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sabo</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-18940</link>
		<dc:creator>Sabo</dc:creator>
		<pubDate>Sun, 22 Apr 2007 21:35:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-18940</guid>
		<description>I understand, I will check for now and on every plugin source code, one short advice could be &quot;donīt download and install plugins from supicious sources&quot;, you know something like that.

And about your question, I donīt really understand it, or I donīt want to understand it maybe, it scares me a little. I canīt tell if this is theorical or somebody is doing it right now and nobody knows about it. How can we know?

Do you remember Sub7? the trojan horse, the owner wrote some code inside the application so it can search for a specific ICQ number and if the application was installed in a computer that has that ICQ profile installed, the Sub7 was made to destroy that computer using the &quot;Hard Disk Killer&quot; progam.

I donīt know, the sky is the limit for a person with PHP skills, if you let it enter to your server, giving him read, write, erase and execution permission.

This could panic the entire community, I hope everybody can keep it cool. :sad:

Regards!</description>
		<content:encoded><![CDATA[<p>I understand, I will check for now and on every plugin source code, one short advice could be &#8220;donīt download and install plugins from supicious sources&#8221;, you know something like that.</p>
<p>And about your question, I donīt really understand it, or I donīt want to understand it maybe, it scares me a little. I canīt tell if this is theorical or somebody is doing it right now and nobody knows about it. How can we know?</p>
<p>Do you remember Sub7? the trojan horse, the owner wrote some code inside the application so it can search for a specific ICQ number and if the application was installed in a computer that has that ICQ profile installed, the Sub7 was made to destroy that computer using the &#8220;Hard Disk Killer&#8221; progam.</p>
<p>I donīt know, the sky is the limit for a person with PHP skills, if you let it enter to your server, giving him read, write, erase and execution permission.</p>
<p>This could panic the entire community, I hope everybody can keep it cool. <img src='http://www.konfabulieren.com/wp-includes/images/smilies/icon_sad.gif' alt=':sad:' class='wp-smiley' /> </p>
<p>Regards!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hipslu</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-18879</link>
		<dc:creator>hipslu</dc:creator>
		<pubDate>Sun, 22 Apr 2007 13:13:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-18879</guid>
		<description>i think due to the power of php and the power of the wordpress plugin mechanism it would be very difficult to automatically find out which plugin contains &quot;evil code&quot;. in fact everybody has to check the plugin code himself; but: not anybody has php skills... the question is: do you think that this risk is just theoretically?</description>
		<content:encoded><![CDATA[<p>i think due to the power of php and the power of the wordpress plugin mechanism it would be very difficult to automatically find out which plugin contains &#8220;evil code&#8221;. in fact everybody has to check the plugin code himself; but: not anybody has php skills&#8230; the question is: do you think that this risk is just theoretically?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sabo</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-18850</link>
		<dc:creator>Sabo</dc:creator>
		<pubDate>Sun, 22 Apr 2007 08:02:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-18850</guid>
		<description>:shock:  WTF! no, I donīt always check all the plugins I download and install, but this one give us a clear example of what can a &quot;script kiddie&quot; can do to fuck an entire community.

Thank you very much for this clear example of weakness. Is there a way you can advice Wordpress developers about how can we protect agains malicious plugins?

Somebody should do a Anti-malicious Plugin, that protects our information from going out to an external source or e-mail.

Regards!</description>
		<content:encoded><![CDATA[<p> <img src='http://www.konfabulieren.com/wp-includes/images/smilies/icon_eek.gif' alt=':shock:' class='wp-smiley' />   WTF! no, I donīt always check all the plugins I download and install, but this one give us a clear example of what can a &#8220;script kiddie&#8221; can do to fuck an entire community.</p>
<p>Thank you very much for this clear example of weakness. Is there a way you can advice Wordpress developers about how can we protect agains malicious plugins?</p>
<p>Somebody should do a Anti-malicious Plugin, that protects our information from going out to an external source or e-mail.</p>
<p>Regards!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: michl</title>
		<link>http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/comment-page-1/#comment-18774</link>
		<dc:creator>michl</dc:creator>
		<pubDate>Sat, 21 Apr 2007 09:06:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.konfabulieren.com/2007/04/18/do-you-trust-all-wordpress-plugins/#comment-18774</guid>
		<description>... das war mir nicht bewusst, auch wenn es eigentlich logisch ist; ich werde also in zukunft vorher mal einen blick in das plugin werden  :shock:</description>
		<content:encoded><![CDATA[<p>&#8230; das war mir nicht bewusst, auch wenn es eigentlich logisch ist; ich werde also in zukunft vorher mal einen blick in das plugin werden  <img src='http://www.konfabulieren.com/wp-includes/images/smilies/icon_eek.gif' alt=':shock:' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
