<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Wordpress users: Disable &#8220;Guest User&#8221;</title>
	<atom:link href="http://www.thedietdiary.com/blog/lucia/1478/feed" rel="self" type="application/rss+xml" />
	<link>http://www.thedietdiary.com/blog/lucia/1478</link>
	<description></description>
	<lastBuildDate>Fri, 20 Nov 2009 10:55:27 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: lucia</title>
		<link>http://www.thedietdiary.com/blog/lucia/1478/comment-page-1#comment-10188</link>
		<dc:creator>lucia</dc:creator>
		<pubDate>Fri, 28 Jul 2006 12:04:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedietdiary.com/blog/lucia/1478#comment-10188</guid>
		<description>Checking things after codecave&#039;s blog entry:
Bugtrack seems to be here: http://seclists.org/lists/bugtraq/2006/May/ 

The upgrade from 2.0.2 to 2.0.3 seems to fix this bug:
http://seclists.org/lists/bugtraq/2006/May/0537.html

Unchecking register users seems to fix this.

I could be incorrect about this, but it appears that there is a security flaw in 2.0.2 that makes it dangereous to permit users to self register. 2.0.3 attempted to fix it. However, Dr. Dave warned us some security flaw associated with leaving self register unchecked remains in 2.0.3.

Evidently, now that the flaw has been brought to the WP team&#039;s attention, they concurs a security flaw remains.  

I think it&#039;s wise to not let new users self register-- particularly since nearly zero% of knitting blogs need this feature. If you co-blog, you&#039;re both already registered, right?</description>
		<content:encoded><![CDATA[<p>Checking things after codecave&#8217;s blog entry:<br />
Bugtrack seems to be here: <a href="http://seclists.org/lists/bugtraq/2006/May/" rel="nofollow">http://seclists.org/lists/bugtraq/2006/May/</a> </p>
<p>The upgrade from 2.0.2 to 2.0.3 seems to fix this bug:<br />
<a href="http://seclists.org/lists/bugtraq/2006/May/0537.html" rel="nofollow">http://seclists.org/lists/bugtraq/2006/May/0537.html</a></p>
<p>Unchecking register users seems to fix this.</p>
<p>I could be incorrect about this, but it appears that there is a security flaw in 2.0.2 that makes it dangereous to permit users to self register. 2.0.3 attempted to fix it. However, Dr. Dave warned us some security flaw associated with leaving self register unchecked remains in 2.0.3.</p>
<p>Evidently, now that the flaw has been brought to the WP team&#8217;s attention, they concurs a security flaw remains.  </p>
<p>I think it&#8217;s wise to not let new users self register&#8211; particularly since nearly zero% of knitting blogs need this feature. If you co-blog, you&#8217;re both already registered, right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Code Cave</title>
		<link>http://www.thedietdiary.com/blog/lucia/1478/comment-page-1#comment-10187</link>
		<dc:creator>The Code Cave</dc:creator>
		<pubDate>Fri, 28 Jul 2006 04:36:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedietdiary.com/blog/lucia/1478#comment-10187</guid>
		<description>[...] Thanks to some drastic and controversial actions taken by SpamKarma creator Dr. Dave, a large percentage of the blogging populace has been alerted to a security hole in WordPress. He even went to the effort of activating a warning message that was sent out to everyone who uses his SK2 plugin. &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] Thanks to some drastic and controversial actions taken by SpamKarma creator Dr. Dave, a large percentage of the blogging populace has been alerted to a security hole in WordPress. He even went to the effort of activating a warning message that was sent out to everyone who uses his SK2 plugin. &#8230; [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
