<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: security hole in wordpress-admin-bar under WPMU?</title>
	<atom:link href="http://www.darcynorman.net/2009/02/23/security-hole-in-wordpress-admin-bar-under-wpmu/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darcynorman.net/2009/02/23/security-hole-in-wordpress-admin-bar-under-wpmu/</link>
	<description>apparently much happier in person</description>
	<lastBuildDate>Sat, 21 Nov 2009 17:45:12 -0700</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Steveoc</title>
		<link>http://www.darcynorman.net/2009/02/23/security-hole-in-wordpress-admin-bar-under-wpmu/#comment-194563</link>
		<dc:creator>Steveoc</dc:creator>
		<pubDate>Wed, 25 Feb 2009 15:59:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.darcynorman.net/?p=2836#comment-194563</guid>
		<description>I&#039;ll have to check--I assume it would be the case if Andrea noticed it too, but I don&#039;t see it in my installation because I am using the WPMU Menu plugin and have disabled many menus options to simplify the interface. Alternatively, you could disable the top menu bar.

Of course, your hack appears to work!

Nice job spotting that!</description>
		<content:encoded><![CDATA[<p>I&#8217;ll have to check&#8211;I assume it would be the case if Andrea noticed it too, but I don&#8217;t see it in my installation because I am using the WPMU Menu plugin and have disabled many menus options to simplify the interface. Alternatively, you could disable the top menu bar.</p>
<p>Of course, your hack appears to work!</p>
<p>Nice job spotting that!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dnorman</title>
		<link>http://www.darcynorman.net/2009/02/23/security-hole-in-wordpress-admin-bar-under-wpmu/#comment-194556</link>
		<dc:creator>dnorman</dc:creator>
		<pubDate>Tue, 24 Feb 2009 15:30:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.darcynorman.net/?p=2836#comment-194556</guid>
		<description>yeah, I figured it was probably just the plugins not calling a hook or something, but it&#039;d be safer to just yank the whole site-admin menu for non-admins, just in case a renegade plugin author forgets to do that *cough*themestatsplugin*ahem* ;-)</description>
		<content:encoded><![CDATA[<p>yeah, I figured it was probably just the plugins not calling a hook or something, but it&#8217;d be safer to just yank the whole site-admin menu for non-admins, just in case a renegade plugin author forgets to do that *cough*themestatsplugin*ahem* <img src='http://www.darcynorman.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrea_R</title>
		<link>http://www.darcynorman.net/2009/02/23/security-hole-in-wordpress-admin-bar-under-wpmu/#comment-194553</link>
		<dc:creator>Andrea_R</dc:creator>
		<pubDate>Tue, 24 Feb 2009 13:00:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.darcynorman.net/?p=2836#comment-194553</guid>
		<description>Oh, okay now I see what you mean. (I spy my theme stats plugin too, awesome.)

Oy vey. That&#039;s not good...</description>
		<content:encoded><![CDATA[<p>Oh, okay now I see what you mean. (I spy my theme stats plugin too, awesome.)</p>
<p>Oy vey. That&#8217;s not good&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
