<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>banane - Latest Comments in WordPress Exploits and Patches</title><link>http://banane.disqus.com/</link><description>I write about SF, writing, and technology.</description><language>en</language><lastBuildDate>Sun, 16 Dec 2007 00:04:25 -0000</lastBuildDate><item><title>Re: WordPress Exploits and Patches</title><link>http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/#comment-4733534</link><description>Oh- thanks Matt! It's not in the footer, but at the end of a post, the individual post content, which users can't see, you can only see if you "view code" in the interface. I will change the db password, seems like the best idea.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">banane</dc:creator><pubDate>Sun, 16 Dec 2007 00:04:25 -0000</pubDate></item><item><title>Re: WordPress Exploits and Patches</title><link>http://www.banane.com/2007/12/14/wordpress-exploits-and-patches/#comment-4733535</link><description>If there is spammy HTML in the footer.php of a theme, it's unlikely that it has anything to do with the cookie thing, it's more likely file permissions and/or an old XML-RPC problem. The cookie thing only applies to you if they've already read your database directly, which is not possible if you're on a secure version, and changing your password protects you if they have. I wouldn't attempt to apply the phpass patch by hand.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt</dc:creator><pubDate>Sat, 15 Dec 2007 21:28:52 -0000</pubDate></item></channel></rss>