<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>metalpig&#039;s blog &#187; WP Upgrade</title>
	<atom:link href="http://metalpigs.com/tag/wp-upgrade/feed/" rel="self" type="application/rss+xml" />
	<link>http://metalpigs.com</link>
	<description>Business Cards &#124; Paper Bags &#124; Graphic &#124; Logo Design &#124; Templates</description>
	<lastBuildDate>Wed, 28 Jul 2010 15:52:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>WordPress 2.8.5: Security Hardening Release</title>
		<link>http://metalpigs.com/wordpress-2-8-5-security-hardening-release/</link>
		<comments>http://metalpigs.com/wordpress-2-8-5-security-hardening-release/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 11:38:38 +0000</pubDate>
		<dc:creator>metalpig</dc:creator>
				<category><![CDATA[metalpig]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[Security Release]]></category>
		<category><![CDATA[WordPress 2.8.5]]></category>
		<category><![CDATA[WordPress 2.8.6]]></category>
		<category><![CDATA[Wordpress Update]]></category>
		<category><![CDATA[WP Upgrade]]></category>

		<guid isPermaLink="false">http://metalpigs.com/?p=105</guid>
		<description><![CDATA[WordPress recommend that all sites must upgrade to WP 2.8.5 version, to ensure the best security protection of your site. Below are the highlights of the said 2.8.5 update. * A fix for the Trackback Denial-of-Service attack that is currently being seen. * Removal of areas within the code where php code in variables was [...]]]></description>
			<content:encoded><![CDATA[<!--CusAds1--><p><a rel="attachment wp-att-109" href="http://metalpigs.com/wordpress-2-8-5-security-hardening-release/wordpress2-8-5-blue-xl/"><img class="alignnone size-full wp-image-109" title="wordpress2.8.5 blue-xl" src="http://metalpigs.com/wp-content/uploads/2009/10/wordpress2.8.5-blue-xl.png" alt="wordpress2.8.5 blue-xl" width="250" height="250" /></a></p>
<p><strong>WordPress</strong> recommend that all sites must upgrade to <strong>WP 2.8.5</strong> version, to ensure the best security protection of your site.</p>
<p>Below are the highlights of the said 2.8.5 update.</p>
<blockquote><p><em><strong><span style="color: #008000;">* A fix for the Trackback Denial-of-Service attack that is currently being seen.</span></strong></em></p>
<p><em><strong><span style="color: #008000;"><br />
* Removal of areas within the code where php code in variables was evaluated.</span></strong></em></p>
<p><em><strong><span style="color: #008000;"><br />
* Switched the file upload functionality to be whitelisted for all users including Admins.</span></strong></em></p>
<p><em><strong><span style="color: #008000;"><br />
* Retiring of the two importers of Tag data from old plugins.</span></strong></em></p></blockquote>
<p>Meanwhile, the <strong>WordPress</strong> camp are also working on the new features for the coming of WordPress 2.9.</p>
<p>For more info about <strong>WordPress 2.5.8 update</strong>, please visit <a class="wp-caption-dd" title="wordpress 2.8.5 hardening release" href="http://wordpress.org/" target="_blank">WordPress.org</a>.</p>
<p><span style="color: #008000;"><em><strong>&gt;&gt; Updates:</strong></em></span></p>
<p>While automatically updating my other WordPress site<span id="more-105"></span>(not this one) via Dashboard, I encountered the problem below;</p>
<p>Unpacking the update.</p>
<p>Verifying the unpacked files</p>
<p>Installing the latest version</p>
<p>Could not copy file: /public_html/wp-content/upgrade/wordpress-2.8.5/wordpress/wp-comments-post.php</p>
<p>Installation Failed</p>
<p>I&#8217;d sign out and re-start my computer thinking that maybe it&#8217;s only a small problem and all it need is to re-start. Then, I login again, clicking the update automatically, but the same problem occurs.</p>
<p><span style="color: #008000;"><em><strong>The solution:</strong></em></span></p>
<p>I&#8217;d tried the simplest solution, <strong>deactivate all my plug-ins</strong> including Akismet&#8230; then Viola!</p>
<p><a rel="attachment wp-att-124" href="http://metalpigs.com/wordpress-2-8-5-security-hardening-release/wordpress-2-8-5_metalpigs-2/"><img class="alignnone size-full wp-image-124" title="wordpress-2.8.5_metalpigs" src="http://metalpigs.com/wp-content/uploads/2009/10/wordpress-2.8.5_metalpigs1.jpg" alt="wordpress-2.8.5_metalpigs" width="397" height="200" /></a></p>
<p>Smooth.. <img src='http://metalpigs.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><span style="color: #008000;"><em><strong>Security Release Update:</strong></em></span></p>
<h3><a class="wp-caption-dd" title="WordPress 2.8.6 Security Release" href="http://wordpress.org/development/2009/11/wordpress-2-8-6-security-release/" target="_blank">WordPress 2.8.6 Security Release</a></h3>
<p><strong>WordPress</strong> released updates to <strong>WP 2.8.6</strong> and available for download. The newly released fixes two security problems that can be exploited by registered, logged in users who have posting privileges. So, if your site or blog had many authors, then <strong>upgrading</strong> to <strong>2.8.6</strong> is a must.</p>
<p>Below are the 2 security problems that are fixed in this update;</p>
<p>*  An <em><strong>XSS vulnerability in Press This</strong></em>, discovered by Benjamin Flesch.</p>
<p>*  An issue with sanitizing uploaded file names that can be exploited in certain <em><strong>Apache configurations</strong></em>, discovered by Dawid Golunski,</p>
<p>Many thanks to Benjamin and Dawid for finding and reporting the said problems.</p>
<p>You can automatically update <strong>WP 2.8.6 </strong>on your Dashboard, or you can download <strong>WordPress 2.8.6 <a class="wp-caption-dd" title="WordPress 2.8.6 Security Release" href="http://wordpress.org/download/" target="_blank">here</a></strong>.</p>

<!-- Quick Adsense WordPress Plugin: http://techmilieu.com/quick-adsense -->
<div style="float:none;margin:10px 0 10px 0;text-align:center;">
<script type="text/javascript"><!--
google_ad_client = "pub-5213711803660471";
/* 468x60, created 10/20/09 */
google_ad_slot = "4322359457";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script>
</div>

<div style="font-size:0px;height:0px;line-height:0px;margin:0;padding:0;clear:both"></div>]]></content:encoded>
			<wfw:commentRss>http://metalpigs.com/wordpress-2-8-5-security-hardening-release/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>
