<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Boschmans Account &#187; wordpress upgrade</title>
	<atom:link href="http://www.boschmans.net/tag/wordpress-upgrade/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.boschmans.net</link>
	<description>A collection of interests and happenings...</description>
	<lastBuildDate>Wed, 01 Feb 2012 22:21:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>WordPress automatic upgrade plugin &#8211; security hole ?</title>
		<link>http://www.boschmans.net/2008/09/20/wordpress-automatic-upgrade-plugin/</link>
		<comments>http://www.boschmans.net/2008/09/20/wordpress-automatic-upgrade-plugin/#comments</comments>
		<pubDate>Sat, 20 Sep 2008 10:09:52 +0000</pubDate>
		<dc:creator>alex</dc:creator>
				<category><![CDATA[Blog News]]></category>
		<category><![CDATA[wordpress upgrade]]></category>

		<guid isPermaLink="false">http://www.boschmans.net/?p=401</guid>
		<description><![CDATA[I just found out about a new plugin for WordPress that allows you to upgrade your wordpress installation semi-automatically. The plugin is a regular wordpress plugin that you need to install into the plugins directory in your WordPress installation, and &#8230; <a href="http://www.boschmans.net/2008/09/20/wordpress-automatic-upgrade-plugin/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I just found out about a new plugin for WordPress that allows you to <a title="WP upgrade automatically" href="http://techie-buzz.com/wordpress-plugins/wordpress-automatic-upgrade-plugin.html" target="_blank">upgrade your wordpress installation</a> semi-automatically.</p>
<p>The plugin is a regular wordpress plugin that you need to install into the plugins directory in your WordPress installation, and can then be used either completely automatically or semi-automatic (by clicking on &#8220;next&#8221; for each step) to upgrade your wordpress to the latest version.</p>
<p>It is still in beta, but it seems to do the trick.</p>
<p>However, a glaring security loophole is that it will backup your current wordpress installation files <span style="text-decoration: underline;">and</span> your database and copy them all in a folder in the root directory (called wpau-backup). It&#8217;s up to you to clean them afterwards by clicking a &#8220;clean&#8221; button.</p>
<p>If you do not do this or something goes wrong, a file containing all your sql data, plus the config files of your server are all there for the taking of anybody searching for it !!!</p>
<p>I can understand for the plugin to provide you with a backup, but the folder should be either automatically emptied at the end of upgrade, or not done at all. This certainly leaves a trace that this plugin is installed, even if the folder is empty and Google is also indexing these folders.</p>
<p>An alternative would be to zip up these backups with a password that the user must give when activating the backup. It would provide a least a measure of security, and zipped files at least won&#8217;t be so easy to read without the password. Also the plugin could set the directory to not to be indexed by Google.</p>
<p>A quick <a title="WPAU-BACKUP google search" href="http://www.google.be/search?q=wpau-backup&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=org.mozilla:en-US:official" target="_blank">Google search</a> for the words &#8220;wpau-backup&#8221; in blogs shows up a disturbing amount of sites that have this folder in their root path. Also a few messages about peope being linked to from these backup folders, leading them to question if either the plugin or the backup had been hacked.</p>
<p>Also, quite a few of those have apparently either been hacked or have badly configured their apache webserver, as you can simply click on parent directory and go up to the root of the server.</p>
<p>I&#8217;m thinking hacked, because I find pieces of wordpress installations all over, but nothing like any index.php file. A few of them have heaps of directories that link to other servers or other dns names, that seem to want to show you adverts.</p>
<p>I&#8217;m quite happy that my <a title="NoScript firefox plugin" href="http://noscript.net/">NoScript plugin</a> was working, I don&#8217;t trust any of these sites&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.boschmans.net/2008/09/20/wordpress-automatic-upgrade-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

