<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cozmoslabs forums</title>
	<atom:link href="http://www.cozmoslabs.com/2009/12/14/cozmoslabs-forums/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cozmoslabs.com/2009/12/14/cozmoslabs-forums/</link>
	<description>Web design and development experiment.</description>
	<lastBuildDate>Sat, 31 Jul 2010 00:55:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Diana</title>
		<link>http://www.cozmoslabs.com/2009/12/14/cozmoslabs-forums/comment-page-1/#comment-2577</link>
		<dc:creator>Diana</dc:creator>
		<pubDate>Wed, 16 Dec 2009 20:08:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.cozmoslabs.com/?p=788#comment-2577</guid>
		<description>sorry</description>
		<content:encoded><![CDATA[<p>sorry</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cristian</title>
		<link>http://www.cozmoslabs.com/2009/12/14/cozmoslabs-forums/comment-page-1/#comment-2574</link>
		<dc:creator>Cristian</dc:creator>
		<pubDate>Wed, 16 Dec 2009 08:47:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.cozmoslabs.com/?p=788#comment-2574</guid>
		<description>To be honest I think this is a permissions problem. I doubt it&#039;s any exploit at work here, just that somethings probably changed in GoDaddy&#039;s server settings.

Try to give 777 ftp permissions to the upload folder, the 2009 folder and the 12 folder inside wp-content. DO NOT give 777 permissions on anything else except the upload, 2009 and 12 folders on the server. 

Here is a really extensive tutorial about file permissions: &lt;a href=&quot;http://www.interspire.com/content/articles/12/1/FTP-and-Understanding-File-Permissions&quot; rel=&quot;nofollow&quot;&gt; File Permissions Tutorial&lt;/a&gt;

Also as a side note, when I said post this on the forums, I meant this &lt;a href=&quot;http://www.cozmoslabs.com/forums/&quot; rel=&quot;nofollow&quot;&gt;LINK&lt;/a&gt;. Here is just a post announcing the new forums, not the forums them self! :)</description>
		<content:encoded><![CDATA[<p>To be honest I think this is a permissions problem. I doubt it&#8217;s any exploit at work here, just that somethings probably changed in GoDaddy&#8217;s server settings.</p>
<p>Try to give 777 ftp permissions to the upload folder, the 2009 folder and the 12 folder inside wp-content. DO NOT give 777 permissions on anything else except the upload, 2009 and 12 folders on the server. </p>
<p>Here is a really extensive tutorial about file permissions: <a href="http://www.interspire.com/content/articles/12/1/FTP-and-Understanding-File-Permissions" rel="nofollow"> File Permissions Tutorial</a></p>
<p>Also as a side note, when I said post this on the forums, I meant this <a href="http://www.cozmoslabs.com/forums/" rel="nofollow">LINK</a>. Here is just a post announcing the new forums, not the forums them self! <img src='http://www.cozmoslabs.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diana</title>
		<link>http://www.cozmoslabs.com/2009/12/14/cozmoslabs-forums/comment-page-1/#comment-2572</link>
		<dc:creator>Diana</dc:creator>
		<pubDate>Wed, 16 Dec 2009 00:25:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.cozmoslabs.com/?p=788#comment-2572</guid>
		<description>Hope this is okay.
_______________________________________________________
Ed invictatrader.com
Posted December 15, 2009 at 10:51 pm &#124; Permalink

@Diana have you tried to move the files manually? That might resolve the issue or help in getting to the bottom of it.
______________________________________________________
Diana curativeenergy.com
Posted December 16, 2009 at 1:17 am &#124; Permalink

I believe I started another topic somewhere on here. I am able to upload images to my server, I think I can manually enter the html to put them in my pages and posts, not sure yet, but I found by searching around that there seems to be a problem. 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution has made my files accessible to whatever may have written into them.

Thanks for your reply.

___________________________________
So, now that I&#039;ve tried adding images by uploading them to my GoDaddy database and then planting them in my posts through html, I&#039;m finding it doesn&#039;t work.  Or, that I&#039;m not able to make it work.</description>
		<content:encoded><![CDATA[<p>Hope this is okay.<br />
_______________________________________________________<br />
Ed invictatrader.com<br />
Posted December 15, 2009 at 10:51 pm | Permalink</p>
<p>@Diana have you tried to move the files manually? That might resolve the issue or help in getting to the bottom of it.<br />
______________________________________________________<br />
Diana curativeenergy.com<br />
Posted December 16, 2009 at 1:17 am | Permalink</p>
<p>I believe I started another topic somewhere on here. I am able to upload images to my server, I think I can manually enter the html to put them in my pages and posts, not sure yet, but I found by searching around that there seems to be a problem. 2.8.5 Unrestricted File Upload Arbitrary PHP Code Execution has made my files accessible to whatever may have written into them.</p>
<p>Thanks for your reply.</p>
<p>___________________________________<br />
So, now that I&#8217;ve tried adding images by uploading them to my GoDaddy database and then planting them in my posts through html, I&#8217;m finding it doesn&#8217;t work.  Or, that I&#8217;m not able to make it work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Diana</title>
		<link>http://www.cozmoslabs.com/2009/12/14/cozmoslabs-forums/comment-page-1/#comment-2569</link>
		<dc:creator>Diana</dc:creator>
		<pubDate>Tue, 15 Dec 2009 16:34:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.cozmoslabs.com/?p=788#comment-2569</guid>
		<description>My Wordpress browser and flash image uploaders both say: The uploaded file could not be moved to D:\Hosting\3056829\html/wp-content/uploads/2009/12.

I&#039;ve since found this information.  http://tweetycoaster.wordpress.com/2009/11/15/full-disclosure-wordpress-2-8-5-unrestricted-file-upload-arbitrary-php-code-execution/

How do I find where line 260 is?  Does this fix actually work anyway? 

Also, if I were to figure how to restore from my backup made a couple of weeks back, does anyone think that would remove any extra .php files that may be installed?

When 2.9 comes out, will that automatically remove any &quot;bad&quot; stuff that&#039;s already on my server?

Should each of these questions be a different topic?

Feel the appreciation!</description>
		<content:encoded><![CDATA[<p>My WordPress browser and flash image uploaders both say: The uploaded file could not be moved to D:\Hosting\3056829\html/wp-content/uploads/2009/12.</p>
<p>I&#8217;ve since found this information.  <a href="http://tweetycoaster.wordpress.com/2009/11/15/full-disclosure-wordpress-2-8-5-unrestricted-file-upload-arbitrary-php-code-execution/" rel="nofollow">http://tweetycoaster.wordpress.com/2009/11/15/full-disclosure-wordpress-2-8-5-unrestricted-file-upload-arbitrary-php-code-execution/</a></p>
<p>How do I find where line 260 is?  Does this fix actually work anyway? </p>
<p>Also, if I were to figure how to restore from my backup made a couple of weeks back, does anyone think that would remove any extra .php files that may be installed?</p>
<p>When 2.9 comes out, will that automatically remove any &#8220;bad&#8221; stuff that&#8217;s already on my server?</p>
<p>Should each of these questions be a different topic?</p>
<p>Feel the appreciation!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Database Caching 6/17 queries in 0.003 seconds using disk

Served from: www.cozmoslabs.com @ 2010-07-31 02:10:45 -->