<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blackhat SEO &#187; 0day</title>
	<atom:link href="http://blackhat-seo.feifei.us/category/0day/feed/" rel="self" type="application/rss+xml" />
	<link>http://blackhat-seo.feifei.us</link>
	<description>For all the bad ideas I have...</description>
	<lastBuildDate>Sat, 19 Jan 2008 22:10:51 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Wordpress Vulnerable to Worm</title>
		<link>http://blackhat-seo.feifei.us/13/wordpress-vulnerable-to-worm/</link>
		<comments>http://blackhat-seo.feifei.us/13/wordpress-vulnerable-to-worm/#comments</comments>
		<pubDate>Sun, 05 Aug 2007 04:40:47 +0000</pubDate>
		<dc:creator>Elliott Back</dc:creator>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://blackhat-seo.feifei.us/13/wordpress-vulnerable-to-worm/</guid>
		<description><![CDATA[Benjamin Flesch points out seven Wordpress XSS exploits that could be used partially or en totalis to create a 0day Wordpress worm that could:

Spread automatically around the blogosphere
Inject a payload into Wordpress

In the blackhat world, the best target would be to find a Wordpress.com XSS exploit.  Then you could easily write a script looking [...]]]></description>
			<content:encoded><![CDATA[<p>Benjamin Flesch points out <a href="http://mybeni.rootzilla.de/mybeNi/2007/wordpress_zeroday_vulnerability_roundhouse_kick_and_why_i_nearly_wrote_the_first_blog_worm/">seven Wordpress XSS exploits</a> that could be used partially or <em>en totalis</em> to create a 0day Wordpress worm that could:</p>
<ol>
<li>Spread automatically around the blogosphere</li>
<li>Inject a payload into Wordpress</li>
</ol>
<p>In the blackhat world, the best target would be to find a <a href="http://Wordpress.com" title="http://Wordpress.com" target="_blank">Wordpress.com</a> XSS exploit.  Then you could easily write a script looking for high-PR blogs and inject a hidden link for yourself, probably without too many people noticing.  If you were careful and acted slowly you&#8217;d have the most powerful Web 2.0 botnet before anyone noticed!</p>
<p>#2 has been shown to be easy.  However, none of the exploits seem to offer #1, that is the spread of a true worm.  The <a href="http://mybeni.rootzilla.de/mybeNi/2007/this_is_the_first_weblog_xss_worm/">author&#8217;s worm</a> cannot spread unless you follow a complicated self-commenting procedure.  So for now at least, there will be no Wordpress 0day firestorm.</p>
]]></content:encoded>
			<wfw:commentRss>http://blackhat-seo.feifei.us/13/wordpress-vulnerable-to-worm/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
