<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Build A Better Blog Host Week 5 &#8211; Security</title>
	<atom:link href="http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/</link>
	<description>WordPress multisite how to - making sense of the network feature from what was wordpress mu</description>
	<lastBuildDate>Thu, 26 Jan 2012 22:51:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Erin</title>
		<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/#comment-3084</link>
		<dc:creator>Erin</dc:creator>
		<pubDate>Wed, 25 Nov 2009 14:15:41 +0000</pubDate>
		<guid isPermaLink="false">http://wpmututorials.com/?p=249#comment-3084</guid>
		<description>Hi Andrea, 

I have a theme I would like to use (news-magazine-theme-640) and it uses $wpdb, presumably to store the many options and objects it creates (thumbnails, etc.).  Can you elaborate on why it&#039;s not secure for themes to use $wpdb, so I can make a decision on whether or not to use this theme in my WPMU site.

Thanks for the great resource. I come back to this post frequently.</description>
		<content:encoded><![CDATA[<p>Hi Andrea, </p>
<p>I have a theme I would like to use (news-magazine-theme-640) and it uses $wpdb, presumably to store the many options and objects it creates (thumbnails, etc.).  Can you elaborate on why it&#8217;s not secure for themes to use $wpdb, so I can make a decision on whether or not to use this theme in my WPMU site.</p>
<p>Thanks for the great resource. I come back to this post frequently.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Some guy</title>
		<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/#comment-1035</link>
		<dc:creator>Some guy</dc:creator>
		<pubDate>Fri, 31 Jul 2009 20:41:09 +0000</pubDate>
		<guid isPermaLink="false">http://wpmututorials.com/?p=249#comment-1035</guid>
		<description>thanks for good post which is full of knowledge and practical ideas.
thanks for post.</description>
		<content:encoded><![CDATA[<p>thanks for good post which is full of knowledge and practical ideas.<br />
thanks for post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andrea</title>
		<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/#comment-1012</link>
		<dc:creator>andrea</dc:creator>
		<pubDate>Tue, 28 Jul 2009 15:05:29 +0000</pubDate>
		<guid isPermaLink="false">http://wpmututorials.com/?p=249#comment-1012</guid>
		<description>It was an unsecure server as I was on shared hosting at the time. Permissions were correct on the file, so the only way they could have got in, was via the server.</description>
		<content:encoded><![CDATA[<p>It was an unsecure server as I was on shared hosting at the time. Permissions were correct on the file, so the only way they could have got in, was via the server.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam Diamond</title>
		<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/#comment-1011</link>
		<dc:creator>Sam Diamond</dc:creator>
		<pubDate>Tue, 28 Jul 2009 14:42:38 +0000</pubDate>
		<guid isPermaLink="false">http://wpmututorials.com/?p=249#comment-1011</guid>
		<description>The hacker was thankfully a nice person, and just left an index.html file on the server to let me know I’d been breached. How’d he do it? He managed to download or read my wp-config file (even though it had the right permissions) and get the database user password… which was the same as the cpanel password.&quot;

How were they able to exploit this? I am more afraid of this scenario than a password brute force scenario.</description>
		<content:encoded><![CDATA[<p>The hacker was thankfully a nice person, and just left an index.html file on the server to let me know I’d been breached. How’d he do it? He managed to download or read my wp-config file (even though it had the right permissions) and get the database user password… which was the same as the cpanel password.&#8221;</p>
<p>How were they able to exploit this? I am more afraid of this scenario than a password brute force scenario.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: itslalala</title>
		<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/#comment-991</link>
		<dc:creator>itslalala</dc:creator>
		<pubDate>Mon, 20 Jul 2009 20:43:00 +0000</pubDate>
		<guid isPermaLink="false">http://wpmututorials.com/?p=249#comment-991</guid>
		<description>I just wanted to thank you for this series and this site! I&#039;m learning so much and I am so excited about my next projects!</description>
		<content:encoded><![CDATA[<p>I just wanted to thank you for this series and this site! I&#8217;m learning so much and I am so excited about my next projects!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: andrea</title>
		<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/#comment-979</link>
		<dc:creator>andrea</dc:creator>
		<pubDate>Fri, 17 Jul 2009 23:40:19 +0000</pubDate>
		<guid isPermaLink="false">http://wpmututorials.com/?p=249#comment-979</guid>
		<description>Yeah, that sounds cool. :)

Ron does hexidecimal conversions in his head, the crazy guy.</description>
		<content:encoded><![CDATA[<p>Yeah, that sounds cool. <img src='http://wpmututorials.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Ron does hexidecimal conversions in his head, the crazy guy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: curtismchale</title>
		<link>http://wpmututorials.com/how-to/build-a-better-blog-host-week-5-security/#comment-978</link>
		<dc:creator>curtismchale</dc:creator>
		<pubDate>Fri, 17 Jul 2009 22:00:34 +0000</pubDate>
		<guid isPermaLink="false">http://wpmututorials.com/?p=249#comment-978</guid>
		<description>For passwords I use Keepass and KeepassX depending on the OS I am on. It&#039;s like 1Password for the Mac. You generate one password that you can remember and then use the software to build your other passwords. Since it&#039;s cross platform I use Dropbox to sync the Database between computers. 

If you want to make sure you have a backup copy (dropbox keeps versions anyway) you can export the XML file and lock it up in a truecrypt vault on a machine. 

I will never manually generate passwords and remember them again. I even use it to track my software license information.
.-= curtismchale&#180;s last blog ..&lt;a href=&quot;http://feedproxy.google.com/~r/Sfnaim/~3/NWBbkFRBkj8/&quot; rel=&quot;nofollow&quot;&gt;You Might Need a Redsign If&lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>For passwords I use Keepass and KeepassX depending on the OS I am on. It&#8217;s like 1Password for the Mac. You generate one password that you can remember and then use the software to build your other passwords. Since it&#8217;s cross platform I use Dropbox to sync the Database between computers. </p>
<p>If you want to make sure you have a backup copy (dropbox keeps versions anyway) you can export the XML file and lock it up in a truecrypt vault on a machine. </p>
<p>I will never manually generate passwords and remember them again. I even use it to track my software license information.<br />
.-= curtismchale&#180;s last blog ..<a href="http://feedproxy.google.com/~r/Sfnaim/~3/NWBbkFRBkj8/" rel="nofollow">You Might Need a Redsign If</a> =-.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

