<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Albertech.net &#187; security</title>
	<atom:link href="http://albertech.net/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://albertech.net</link>
	<description>Guides and Reviews for WordPress, PHP, MySQL, Apache, CMS Systems, jQuery, and other Technologies</description>
	<lastBuildDate>Fri, 11 May 2012 23:39:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>PHP 5.4.3 and PHP 5.3.13 released &#8211; important security fix for php cgi</title>
		<link>http://albertech.net/2012/05/php-5-4-3-and-php-5-3-13-released-important-security-fix-for-php-cgi/</link>
		<comments>http://albertech.net/2012/05/php-5-4-3-and-php-5-3-13-released-important-security-fix-for-php-cgi/#comments</comments>
		<pubDate>Fri, 11 May 2012 22:45:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[php cgi]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://albertech.net/?p=1018</guid>
		<description><![CDATA[If you are running<strong> php-cgi</strong>, there is a <a href="http://www.php.net/archive/2012.php#id2012-05-03-1" target="_blank">major vulnerability</a> that will allow attackers to view and run <strong>PHP source code</strong> on your site.

<strong>Resources on the vulnerability:</strong>
<a href="http://blog.spiderlabs.com/2012/05/honeypot-alert-active-exploit-attempts-for-php-cgi-vuln.html" target="_blank">http://blog.spiderlabs.com/2012/05/honeypot-alert-active-exploit-attempts-for-php-cgi-vuln.html</a>
<a href="http://blog.sucuri.net/2012/05/php-cgi-vulnerability-exploited-in-the-wild.html" target="_blank">http://blog.sucuri.net/2012/05/php-cgi-vulnerability-exploited-in-the-wild.html
</a><a href="http://blog.sucuri.net/2012/05/php-cgi-vulnerability-exploited-in-the-wild.html" target="_blank">http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/ </a>
<ul>
	<li><strong>Many nginx setups use php-cgi</strong>, so it is critical to patch PHP to the latest version or apply the recommended fixes through Apache Rewrite.</li>
	<li><strong>Mod_php and php-fpm systems are not vulnerable to this attack</strong>. Most Apache web server setups use the mod_php method for PHP.</li>
</ul>
<span id="more-1018"></span>

If you are running an older version of PHP and cannot update to 5.3, you can try using Apache rewrite rules. Here's ... ]]></description>
		<wfw:commentRss>http://albertech.net/2012/05/php-5-4-3-and-php-5-3-13-released-important-security-fix-for-php-cgi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CodeIgniter 1.7.2 Security Patch</title>
		<link>http://albertech.net/2010/08/codeigniter-1-7-2-patch/</link>
		<comments>http://albertech.net/2010/08/codeigniter-1-7-2-patch/#comments</comments>
		<pubDate>Sat, 14 Aug 2010 06:33:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Frameworks]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[codeigniter]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://albertech.net/?p=440</guid>
		<description><![CDATA[If you are running CodeIgniter 1.7.2, there is a security flaw with the file upload class. (fixed on July 12, 2010)  The easiest way to install the patch is to use the standalone patch <a href="http://codeigniter.com/download_files/CI_1.7.2_201007_sec_patch.zip">http://codeigniter.com/download_files/CI_1.7.2_201007_sec_patch.zip</a> and unzip the file to the Code Igniter system/libraries folder.]]></description>
		<wfw:commentRss>http://albertech.net/2010/08/codeigniter-1-7-2-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VMWARE Server 2.02 Update</title>
		<link>http://albertech.net/2009/11/vmware-server-2-02-update/</link>
		<comments>http://albertech.net/2009/11/vmware-server-2-02-update/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 19:29:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[VMWARE]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vmware server]]></category>

		<guid isPermaLink="false">http://albertech.net/?p=317</guid>
		<description><![CDATA[VMWARE Server 2.02 has been released October 27, 2009. It includes a few important security updates for VMWARE Server. If you are running a Linux server with VMWARE server 2.01, I strongly suggest to upgrade due to the "Directory Traversal Vulnerability" -- which may allow for remote retrieval of any file from the host system.]]></description>
		<wfw:commentRss>http://albertech.net/2009/11/vmware-server-2-02-update/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress 2.8.2 Released</title>
		<link>http://albertech.net/2009/07/wordpress-2-8-2-released/</link>
		<comments>http://albertech.net/2009/07/wordpress-2-8-2-released/#comments</comments>
		<pubDate>Wed, 22 Jul 2009 17:11:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PHP]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://albertech.net/?p=220</guid>
		<description><![CDATA[<strong>WordPress 2.8.2 has been released. This affects both WordPress and WordPress MU. I recommend upgrading your current version since it contains a security fix. </strong>
<blockquote>WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site.</blockquote>
<strong>For more details, visit:</strong>
<a href="http://wordpress.org/development/2009/07/wordpress-2-8-2/" target="_blank">http://wordpress.org/development/2009/07/wordpress-2-8-2/
</a>
You can automatically upgrade WordPress within your control panel, or manually upgrade via:
<a href="http://wordpress.org/download/" target="_blank">http://wordpress.org/download/</a>

WordPress MU download:<a href=" http://mu.wordpress.org/download/" target="_blank">
http://mu.wordpress.org/download/</a>]]></description>
		<wfw:commentRss>http://albertech.net/2009/07/wordpress-2-8-2-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

