<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="bbPress/1.0.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Support Forum - Tag: vulnerability - Recent Posts</title>
		<link>http://www.kriesi.at/support/tags/vulnerability</link>
		<description>Support Forum - Tag: vulnerability - Recent Posts</description>
		<language>en-US</language>
		<pubDate>Sat, 25 May 2013 14:04:20 +0000</pubDate>
		<generator>http://bbpress.org/?v=1.0.2</generator>
		<textInput>
			<title><![CDATA[Search]]></title>
			<description><![CDATA[Search all topics from these forums.]]></description>
			<name>q</name>
			<link>http://www.kriesi.at/support/search.php</link>
		</textInput>
		<atom:link href="http://www.kriesi.at/support/rss/tags/vulnerability" rel="self" type="application/rss+xml" />

		<item>
			<title>Devin on "Serious issues in original CORONA theme files - hacked WP installation"</title>
			<link>http://www.kriesi.at/support/topic/serious-issues-in-original-corona-theme-files-hacked-wp-installation#post-89271</link>
			<pubDate>Fri, 21 Dec 2012 19:21:11 +0000</pubDate>
			<dc:creator>Devin</dc:creator>
			<guid isPermaLink="false">89271@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi colorit2,&#60;/p&#62;
&#60;p&#62;The dst_store is a file created by apple. Since Kriesi compiles and works on a Mac it gets added in. See: &#60;a href=&#34;http://en.wikipedia.org/wiki/.DS_Store&#34; rel=&#34;nofollow&#34;&#62;http://en.wikipedia.org/wiki/.DS_Store&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;There was a security fix in the most recent version of corona (1.4) so you should definitely download it and update. You can do so by re-downloading the theme from themeforest and then installing the theme in the same way you first installed it.&#60;/p&#62;
&#60;p&#62;Regards,&#60;/p&#62;
&#60;p&#62;Devin
&#60;/p&#62;</description>
		</item>
		<item>
			<title>colorit2 on "Serious issues in original CORONA theme files - hacked WP installation"</title>
			<link>http://www.kriesi.at/support/topic/serious-issues-in-original-corona-theme-files-hacked-wp-installation#post-89242</link>
			<pubDate>Fri, 21 Dec 2012 13:35:35 +0000</pubDate>
			<dc:creator>colorit2</dc:creator>
			<guid isPermaLink="false">89242@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Here is a PDF (600 kB) made with Fireshot of this theme check:&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;https://www.dropbox.com/s/n0ug942le2z5kmk/ThemeCheck-Corona-Original.pdf&#34; rel=&#34;nofollow&#34;&#62;https://www.dropbox.com/s/n0ug942le2z5kmk/ThemeCheck-Corona-Original.pdf&#60;/a&#62;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>colorit2 on "Serious issues in original CORONA theme files - hacked WP installation"</title>
			<link>http://www.kriesi.at/support/topic/serious-issues-in-original-corona-theme-files-hacked-wp-installation#post-89240</link>
			<pubDate>Fri, 21 Dec 2012 13:29:31 +0000</pubDate>
			<dc:creator>colorit2</dc:creator>
			<guid isPermaLink="false">89240@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi,&#60;/p&#62;
&#60;p&#62;due to some security issues at my WP installation I have made beside other things a theme check with this plugin: &#60;a href=&#34;http://wordpress.org/extend/plugins/theme-check/&#34; rel=&#34;nofollow&#34;&#62;http://wordpress.org/extend/plugins/theme-check/&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;And there are obviously a lot of issues with CORONA; I'm mostly concerned about the red &#34;warnings&#34; like&#60;/p&#62;
&#60;p&#62;&#60;code&#62; ... base64_encode ... &#60;/code&#62;&#60;/p&#62;
&#60;p&#62;in avia-export-class.php for example, fopen, fclose, and why is there a &#60;strong&#62;hidden file/folder &#34;.ds_store&#34;&#60;/strong&#62;??&#60;br /&#62;
It is in the original CORONA files, freshly downloaded at Themeforest.&#60;/p&#62;
&#60;p&#62;What is there to do with all these issues concerning the security?&#60;br /&#62;
(my WP has been hacked by the &#34;pharma hack&#34; --&#38;gt; &#60;a href=&#34;http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php&#34; rel=&#34;nofollow&#34;&#62;http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;And this although I have installed Antivirus, Limit Login Attempts-plugin, several WP security plugins, using strong passwords, having no &#34;admin&#34; user, protecting wp-admin and wp-config.php with .htaccess and having the wp-config.php moved above the WP installation folder etc.&#60;/p&#62;
&#60;p&#62;So I'm currently checking all security vulnerabilities in my network - and therefor I'm worried about the &#34;theme check&#34; of CORONA.&#60;/p&#62;
&#60;p&#62;Any suggestions for this?&#60;br /&#62;
Thanks a lot!
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54644</link>
			<pubDate>Fri, 04 May 2012 13:02:01 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54644@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;You're a star Dude - thanks
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Kriesi on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54643</link>
			<pubDate>Fri, 04 May 2012 13:00:43 +0000</pubDate>
			<dc:creator>Kriesi</dc:creator>
			<guid isPermaLink="false">54643@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi! &#60;/p&#62;
&#60;p&#62; You can already get the update at themeforest, yes.&#60;/p&#62;
&#60;p&#62;Updating this preview-shortcode-external.php and the dialog.php file within the shortcode folder is sufficient :) &#60;/p&#62;
&#60;p&#62; Regards,&#60;br /&#62;
Kriesi
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54567</link>
			<pubDate>Thu, 03 May 2012 20:32:13 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54567@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;and one more question... can we pick up the updated themes from themeforest?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54565</link>
			<pubDate>Thu, 03 May 2012 20:24:17 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54565@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Thats great news Kriesi - thanks for update... can you confirm if it's just the file 'preview-shortcode-external.php' that needs replacing or the whole framework folder?
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Kriesi on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54548</link>
			<pubDate>Thu, 03 May 2012 18:27:36 +0000</pubDate>
			<dc:creator>Kriesi</dc:creator>
			<guid isPermaLink="false">54548@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Ok guys!&#60;/p&#62;
&#60;p&#62;I have released a patch for all framework themes. I am still not sure if the issue WooThemes is having is directly related to this file but I figured it wouldnt be bad adding some additional security. the files now stops executing is the user is not logged in and doesnt have the capability to edit code.&#60;/p&#62;
&#60;p&#62;That should fix any holes in the preview system ;)&#60;/p&#62;
&#60;p&#62;As always you can download the latest version of the themes on themeforest
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54401</link>
			<pubDate>Wed, 02 May 2012 19:46:50 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54401@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Yeah! I wouldn't want to be in the woothemes office this week!
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Kriesi on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54310</link>
			<pubDate>Wed, 02 May 2012 14:00:31 +0000</pubDate>
			<dc:creator>Kriesi</dc:creator>
			<guid isPermaLink="false">54310@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey! &#60;/p&#62;
&#60;p&#62; Will do :)&#60;br /&#62;
Since the downtime of woothemes those guys are really busy it seems, so it might be a few more hours until I get an answer from the framework developer :) &#60;/p&#62;
&#60;p&#62; Best regards,&#60;br /&#62;
Kriesi
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54276</link>
			<pubDate>Wed, 02 May 2012 08:11:51 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54276@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Thanks for the update Kriesi - please keep us posted on developments.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Kriesi on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54272</link>
			<pubDate>Wed, 02 May 2012 07:44:02 +0000</pubDate>
			<dc:creator>Kriesi</dc:creator>
			<guid isPermaLink="false">54272@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hey Guys! I am currently in contact with woothemes to get some more knowledge on the issue, and I let you know as soons as I know more. In the meantime If you are afraid of the exploit open your themefolder with an ftp tool and remove the &#60;/p&#62;
&#60;p&#62;&#34;framework/php/avia_shortcodes/preview-shortcode-external.php&#34; file&#60;/p&#62;
&#60;p&#62;the file is not necessary for the theme to work, the only functionality lost will be the shortcode previews when you create a new one.&#60;/p&#62;
&#60;p&#62;I'll keep you posted!&#60;br /&#62;
Cheers&#60;/p&#62;
&#60;p&#62;Kriesi
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54216</link>
			<pubDate>Tue, 01 May 2012 20:59:37 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54216@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Must admit, it makes me a little nervous too - from what I can tell of the woothemes issue, it's very easy to add shortcode to a site with the hack. &#60;/p&#62;
&#60;p&#62;would like to see a 'this is absolutely not an issue for our themes' kinda response.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>littlepackage on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54155</link>
			<pubDate>Tue, 01 May 2012 15:25:38 +0000</pubDate>
			<dc:creator>littlepackage</dc:creator>
			<guid isPermaLink="false">54155@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;I dunno about this - I'm &#60;em&#62;nervous&#60;/em&#62; because it has to do with the Shortcode Exploit that was found 4/23. I'd LOVE to see this addressed ASAP, because the patch is a *theme* patch. I know the code is different in these themes, it would still be nice to have eyes on it and some reassurance. &#60;strong&#62;Thank you!!&#60;/strong&#62;&#60;br /&#62;
&#60;hr /&#62;&#60;br /&#62;
&#60;a href=&#34;https://gist.github.com/2523147&#34;&#62;https://gist.github.com/2523147&#60;/a&#62;&#60;/p&#62;
&#60;p&#62;&#60;a href=&#34;http://www.woothemes.com/2012/04/framework-shortcode-exploit-has-been-fixed/&#34;&#62;http://www.woothemes.com/2012/04/framework-shortcode-exploit-has-been-fixed/&#60;/a&#62;
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Devin on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54033</link>
			<pubDate>Mon, 30 Apr 2012 21:13:56 +0000</pubDate>
			<dc:creator>Devin</dc:creator>
			<guid isPermaLink="false">54033@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;It doesn't look like it will be a big issue and to be honest I don't *think* it will effect the themes at all. Definitely keep WooCommerce up to date in the coming weeks just in case.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54025</link>
			<pubDate>Mon, 30 Apr 2012 20:59:27 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54025@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Cheers Devin, good advice and probably worth doing as a precaution until the issue is resolved.&#60;/p&#62;
&#60;p&#62;Hopefully get a full answer from Kriesi pretty soon.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>Devin on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54021</link>
			<pubDate>Mon, 30 Apr 2012 20:53:19 +0000</pubDate>
			<dc:creator>Devin</dc:creator>
			<guid isPermaLink="false">54021@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi eddygame,&#60;/p&#62;
&#60;p&#62;I'm not sure about that. I'll talk to Kriesi as I'm sure hes been busy checking into this since he makes such intimate use of WooCommerce.&#60;/p&#62;
&#60;p&#62;In the meantime, You can always make a quick backup of the theme then delete the file and test for any functionality concerns. Off hand, you will definitely not be able to use the pop up shortcode generator but you could still use the shortcodes in the actual pages.&#60;/p&#62;
&#60;p&#62;Regards,&#60;/p&#62;
&#60;p&#62;Devin
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54015</link>
			<pubDate>Mon, 30 Apr 2012 20:08:40 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54015@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;I think Vaultpress is flagging this up as the file names of both the woothemes 'preview-shortcode-external.php' and ShoutBox 'preview-shortcode-external.php' files are the same? the code looks very different.
&#60;/p&#62;</description>
		</item>
		<item>
			<title>eddygame on "Security Waring"</title>
			<link>http://www.kriesi.at/support/topic/security-waring#post-54006</link>
			<pubDate>Mon, 30 Apr 2012 18:55:51 +0000</pubDate>
			<dc:creator>eddygame</dc:creator>
			<guid isPermaLink="false">54006@http://www.kriesi.at/support/</guid>
			<description>&#60;p&#62;Hi Guys,&#60;/p&#62;
&#60;p&#62;I have Vaultpress on one of my sites and today it's started giving a warning about the file:&#60;br /&#62;
'preview-shortcode-external.php'  in themes: /shoutbox/framework/php/avia_shortcodes/&#60;/p&#62;
&#60;p&#62;I think this is related to the recent woothemes exploit - any idea if this affects 'ShoutBox' or other Kriesi themes? Vaultpress is recommending I delete - preview-shortcode-external.php   is it safe to do that? will it cause any problems with short codes?&#60;/p&#62;
&#60;p&#62;Here is some more about the exploit &#60;a href=&#34;http://blog.sucuri.net/2012/04/new-woothemes-vulnerability-patched-update-framework-now.html&#34; rel=&#34;nofollow&#34;&#62;http://blog.sucuri.net/2012/04/new-woothemes-vulnerability-patched-update-framework-now.html&#60;/a&#62;
&#60;/p&#62;</description>
		</item>

	</channel>
</rss>
