<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Complexity is the enemy of Security &#187; wordPress</title>
	<atom:link href="http://blog.lifeoverip.net/tag/wordpress/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.lifeoverip.net</link>
	<description>Life (Over) IP,</description>
	<lastBuildDate>Wed, 08 Sep 2010 11:00:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress&#8217;a guvenlik dopingi</title>
		<link>http://blog.lifeoverip.net/2008/05/08/wordpressa-otomatik-guncelleme-eklentisi/</link>
		<comments>http://blog.lifeoverip.net/2008/05/08/wordpressa-otomatik-guncelleme-eklentisi/#comments</comments>
		<pubDate>Thu, 08 May 2008 19:00:11 +0000</pubDate>
		<dc:creator>Huzeyfe ONAL</dc:creator>
				<category><![CDATA[Web Security]]></category>
		<category><![CDATA[wordPress]]></category>

		<guid isPermaLink="false">http://blog.lifeoverip.net/?p=444</guid>
		<description><![CDATA[WordPress, benim guvenlik cekincelerim yuzunden uzun zaman kullanmamakta israr ettigim fakat aradigim ozellikleri bulabildigim tek blog yazilimi olmasi sonucu bazi riskleri kabul ederek kullanmaya basladigim bir yazilim. Kabul ettigim riskleri en aza indirme amacli olarak WP&#8217;nin cogu bilesenini aktif olarak kullanmiyorum, bunun yaninda olabildigince guncellemeleri takip etmeye calisiyordum. Ama WP&#8217;nin sıklıkla cıkan guvenlik acikliklari bir [...]


Related posts:<ol><li><a href='http://blog.lifeoverip.net/2008/09/10/wordpress-261-de-ciddi-guvenlik-acigi/' rel='bookmark' title='Permanent Link: WordPress 2.6.1 de ciddi guvenlik acigi(!)'>WordPress 2.6.1 de ciddi guvenlik acigi(!)</a></li>
<li><a href='http://blog.lifeoverip.net/2007/05/24/wordpress-kritik-guvenlik-acigi/' rel='bookmark' title='Permanent Link: WordPress Kritik Guvenlik Acigi'>WordPress Kritik Guvenlik Acigi</a></li>
<li><a href='http://blog.lifeoverip.net/2007/05/16/freebsd-binaryikili-guncelleme/' rel='bookmark' title='Permanent Link: FreeBSD binary(ikili) guncelleme'>FreeBSD binary(ikili) guncelleme</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://netsec.lifeoverip.net/wp-content/uploads/2008/05/wordpress.png"><img class="alignnone size-medium wp-image-467 alignleft" style="float: left;" title="wordpress" src="http://blog.lifeoverip.net/wp-content/uploads/2008/05/wordpress-300x300.png" alt="" width="100" height="100" /></a>WordPress, benim guvenlik cekincelerim yuzunden uzun zaman kullanmamakta israr ettigim fakat aradigim ozellikleri bulabildigim tek blog yazilimi olmasi sonucu bazi riskleri kabul ederek kullanmaya basladigim bir yazilim.</p>
<p>Kabul ettigim riskleri en aza indirme amacli olarak WP&#8217;nin cogu bilesenini aktif olarak kullanmiyorum, bunun yaninda olabildigince guncellemeleri takip etmeye calisiyordum. Ama WP&#8217;nin sıklıkla cıkan guvenlik acikliklari bir zaman sonrazorlamaya baslayinca sunucu tarafinda cesitli onlemler alma yoluna gittim. Gecenlerde bir arastirmam sirasinda WP&#8217;nin guvenligi ile ilgili cikmis eklentilere rastladim. Aralarindan ikisi tam da istedigim isi yapiyordu.</p>
<ol>
<li>WP guncellemelerini takip edip beni uyaracak ve tek tiklama ile tum sistemi guncelleyecek bir eklenti</li>
<li>WP uzerine kurdugum, ekledigim ek kodlari, bilesenleri guvenlik taramasindan gecirerek raporlama yapacak bir bilesen.</li>
</ol>
<p><strong>WordPress otomatik guncelleme eklentisi</strong></p>
<p>Asagidaki 8 adimi uygulayarak otomatize guncelleme yapabilen bir WP&#8217;e sahip olabilirsiniz. Boylece guncelleme yaparken yedekleme vs gibi islemlerle ugrasmazsiniz.</p>
<ol>
<li>Backs up the files and makes available a link to download it.</li>
<li>Backs up the database and makes available a link to download it.</li>
<li>Downloads the latest files from <a rel="nofollow" href="http://wordpress.org/latest.zip">http://wordpress.org/latest.zip</a> and unzips it.</li>
<li>Puts the site in maintenance mode.</li>
<li>De-activates all active plugins and remembers it.</li>
<li>Upgrades wordpress files.</li>
<li>Gives you a link that will open in a new window to upgrade installation.</li>
<li>Re-activates the plugins.</li>
</ol>
<p>Ilgili eklentiyi indirmek icin: <a href="http://wordpress.org/extend/plugins/wordpress-automatic-upgrade/">http://wordpress.org/extend/plugins/wordpress-automatic-upgrade/</a></p>
<p><strong>WordPress Guvenlik Taramasi Eklentisi</strong></p>
<blockquote><p><a href="http://netsec.lifeoverip.net/wp-content/uploads/2008/05/sc1.jpg"><img class="alignnone size-full wp-image-468 alignleft" style="float: left;" title="sc1" src="http://netsec.lifeoverip.net/wp-content/uploads/2008/05/sc1.jpg" alt="" width="500" height="237" /></a></p>
<ul>
<li>-passwords</li>
<li> -file permissions</li>
<li> -database security</li>
<li> -version hiding</li>
<li> -WordPress admin protection/security</li>
</ul>
<p>-removes WP Generator META tag from core code</p></blockquote>
<p><strong>Ileriki surumlerde eklenmesi dusunulen maddeler:</strong></p>
<blockquote><p><strong></strong><br />
*one-click change file/folder permissions<br />
*test for XSS vulnerabilities<br />
*intrusion detection/prevention<br />
*lock out/log incorrect login attempts<br />
*user enumeration protection<br />
*.htaccess verification<br />
*doc links</p></blockquote>
<p>Ilgili eklentiyi indirmek icin: <a href="http://wordpress.org/extend/plugins/wp-security-scan/">http://wordpress.org/extend/plugins/wp-security-scan/</a></p>
<p><strong>Ek kaynaklar:</strong></p>
<p><em>WordPress ile ilgili cikmis tum guvenlik acikliklari ve detaylari hakkinda bilgi almak icin:</em></p>
<p><a href="http://blogsecurity.net/wordpress/blogwatch/blogwatch/">http://blogsecurity.net/wordpress/blogwatch/blogwatch/</a></p>
<p><em>WordPress&#8217;i daha guvenilir hale getirmek icin yazilmis guncel bir dokuman</em></p>
<p><a href="http://blogsecurity.net/projects/WordPress_Whitepaper_rev12.pdf">http://blogsecurity.net/projects/WordPress_Whitepaper_rev12.pdf</a></p>



Share and Enjoy:


	<a rel="nofollow"  href="http://www.printfriendly.com/print?url=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F&amp;partner=sociable" title="Print"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F&amp;title=WordPress%27a%20guvenlik%20dopingi&amp;bodytext=WordPress%2C%20benim%20guvenlik%20cekincelerim%20yuzunden%20uzun%20zaman%20kullanmamakta%20israr%20ettigim%20fakat%20aradigim%20ozellikleri%20bulabildigim%20tek%20blog%20yazilimi%20olmasi%20sonucu%20bazi%20riskleri%20kabul%20ederek%20kullanmaya%20basladigim%20bir%20yazilim.%0A%0AKabul%20ettigim%20riskleri%20en%20az" title="Digg"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F" title="Sphinn"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/sphinn.png" title="Sphinn" alt="Sphinn" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F&amp;title=WordPress%27a%20guvenlik%20dopingi&amp;notes=WordPress%2C%20benim%20guvenlik%20cekincelerim%20yuzunden%20uzun%20zaman%20kullanmamakta%20israr%20ettigim%20fakat%20aradigim%20ozellikleri%20bulabildigim%20tek%20blog%20yazilimi%20olmasi%20sonucu%20bazi%20riskleri%20kabul%20ederek%20kullanmaya%20basladigim%20bir%20yazilim.%0A%0AKabul%20ettigim%20riskleri%20en%20az" title="del.icio.us"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F&amp;t=WordPress%27a%20guvenlik%20dopingi" title="Facebook"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.mixx.com/submit?page_url=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F&amp;title=WordPress%27a%20guvenlik%20dopingi" title="Mixx"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/mixx.png" title="Mixx" alt="Mixx" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F&amp;title=WordPress%27a%20guvenlik%20dopingi&amp;annotation=WordPress%2C%20benim%20guvenlik%20cekincelerim%20yuzunden%20uzun%20zaman%20kullanmamakta%20israr%20ettigim%20fakat%20aradigim%20ozellikleri%20bulabildigim%20tek%20blog%20yazilimi%20olmasi%20sonucu%20bazi%20riskleri%20kabul%20ederek%20kullanmaya%20basladigim%20bir%20yazilim.%0A%0AKabul%20ettigim%20riskleri%20en%20az" title="Google Bookmarks"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F&amp;title=WordPress%27a%20guvenlik%20dopingi" title="StumbleUpon"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://technorati.com/faves?add=http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F" title="Technorati"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a>
	<a rel="nofollow"  href="http://twitter.com/home?status=WordPress%27a%20guvenlik%20dopingi%20-%20http%3A%2F%2Fblog.lifeoverip.net%2F2008%2F05%2F08%2Fwordpressa-otomatik-guncelleme-eklentisi%2F" title="Twitter"><img src="http://blog.lifeoverip.net/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a>


<br/><br/>

<p>Related posts:<ol><li><a href='http://blog.lifeoverip.net/2008/09/10/wordpress-261-de-ciddi-guvenlik-acigi/' rel='bookmark' title='Permanent Link: WordPress 2.6.1 de ciddi guvenlik acigi(!)'>WordPress 2.6.1 de ciddi guvenlik acigi(!)</a></li>
<li><a href='http://blog.lifeoverip.net/2007/05/24/wordpress-kritik-guvenlik-acigi/' rel='bookmark' title='Permanent Link: WordPress Kritik Guvenlik Acigi'>WordPress Kritik Guvenlik Acigi</a></li>
<li><a href='http://blog.lifeoverip.net/2007/05/16/freebsd-binaryikili-guncelleme/' rel='bookmark' title='Permanent Link: FreeBSD binary(ikili) guncelleme'>FreeBSD binary(ikili) guncelleme</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://blog.lifeoverip.net/2008/05/08/wordpressa-otomatik-guncelleme-eklentisi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
