<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Improving security in WordPress plugins using Nonces</title> <atom:link href="http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/feed" rel="self" type="application/rss+xml" /><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces</link> <description>A blog by Prelovac Media CEO Vladimir Prelovac</description> <lastBuildDate>Tue, 14 Feb 2012 08:37:58 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>By: joomlaserviceprovide</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-2#comment-24586</link> <dc:creator>joomlaserviceprovide</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-24586</guid> <description>Greetings. We are pleased to announce the release of wSecure. wSecure hides your Wordpress admin URL with a special key so that only you can access. The problem with Wordpress is that anyone can tell if your site is Wordpress by simply typing in the default URL to the administration area (i.e. www.yoursite.com/wp-admin). wSecure helps you hide the fact that your website is built with Worpdress from prying eyes.</description> <content:encoded><![CDATA[<p>Greetings. We are pleased to announce the release of wSecure. wSecure hides your WordPress admin URL with a special key so that only you can access. The problem with WordPress is that anyone can tell if your site is WordPress by simply typing in the default URL to the administration area (i.e. <a
href="http://www.yoursite.com/wp-admin" rel="nofollow">http://www.yoursite.com/wp-admin</a>). wSecure helps you hide the fact that your website is built with Worpdress from prying eyes.</p> ]]></content:encoded> </item> <item><title>By: Securing Your WordPress Website &#124; TunerLabs Blog</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-2#comment-23911</link> <dc:creator>Securing Your WordPress Website &#124; TunerLabs Blog</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23911</guid> <description>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</description> <content:encoded><![CDATA[<p>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</p> ]]></content:encoded> </item> <item><title>By: Securing Your WordPress Website &#124; Web Design Course Brisbane: Next Course Sat 10th Dec 2011</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-2#comment-23897</link> <dc:creator>Securing Your WordPress Website &#124; Web Design Course Brisbane: Next Course Sat 10th Dec 2011</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23897</guid> <description>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</description> <content:encoded><![CDATA[<p>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</p> ]]></content:encoded> </item> <item><title>By: Securing Your WordPress Website &#124; Wordpress Training Course Brisbane: Next Course Thur 24th Nov 2011</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-2#comment-23896</link> <dc:creator>Securing Your WordPress Website &#124; Wordpress Training Course Brisbane: Next Course Thur 24th Nov 2011</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23896</guid> <description>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</description> <content:encoded><![CDATA[<p>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</p> ]]></content:encoded> </item> <item><title>By: Securing Your WordPress Website &#124; Remake Wordpress Theme</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-23893</link> <dc:creator>Securing Your WordPress Website &#124; Remake Wordpress Theme</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23893</guid> <description>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</description> <content:encoded><![CDATA[<p>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</p> ]]></content:encoded> </item> <item><title>By: Securing Your WordPress Website &#124; Appenheimer</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-23892</link> <dc:creator>Securing Your WordPress Website &#124; Appenheimer</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23892</guid> <description>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</description> <content:encoded><![CDATA[<p>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</p> ]]></content:encoded> </item> <item><title>By: level. graphic design boutique agency based in weymouth dorset</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-23885</link> <dc:creator>level. graphic design boutique agency based in weymouth dorset</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23885</guid> <description>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</description> <content:encoded><![CDATA[<p>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</p> ]]></content:encoded> </item> <item><title>By: Free and Premium wordpress plugins &#124; Securing Your WordPress Website</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-23884</link> <dc:creator>Free and Premium wordpress plugins &#124; Securing Your WordPress Website</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23884</guid> <description>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</description> <content:encoded><![CDATA[<p>[...] “Improving Security in WordPress Plugins Using Nonces,” Vladimir Prelovac [...]</p> ]]></content:encoded> </item> <item><title>By: GB</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-23601</link> <dc:creator>GB</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23601</guid> <description>Using this - Does the action variable need to match the name of the action in the form, or can it be anything?</description> <content:encoded><![CDATA[<p>Using this - Does the action variable need to match the name of the action in the form, or can it be anything?</p> ]]></content:encoded> </item> <item><title>By: WordPress Meta Box Tutorial - Advanced &#124; WP Roots</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-23308</link> <dc:creator>WordPress Meta Box Tutorial - Advanced &#124; WP Roots</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23308</guid> <description>[...] HTML. If you are unfamiliar with the built-in WordPress nonce functions, I would recommend reading about them in order to harden and secure your WordPress [...]</description> <content:encoded><![CDATA[<p>[...] HTML. If you are unfamiliar with the built-in WordPress nonce functions, I would recommend reading about them in order to harden and secure your WordPress [...]</p> ]]></content:encoded> </item> <item><title>By: 5 tips for using AJAX in WordPress &#124; WPsharing</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-23193</link> <dc:creator>5 tips for using AJAX in WordPress &#124; WPsharing</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-23193</guid> <description>[...] Jaquith and Vladimir Prelovac also covered Nonces and how to use them generally. Make sure you read those articles because [...]</description> <content:encoded><![CDATA[<p>[...] Jaquith and Vladimir Prelovac also covered Nonces and how to use them generally. Make sure you read those articles because [...]</p> ]]></content:encoded> </item> <item><title>By: Rumpelstintskin</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-22411</link> <dc:creator>Rumpelstintskin</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-22411</guid> <description>All reserves expressed about the mechanism proposed by Vladimir have to do with nonces being valid for 24 hours. Is that imperative by design? Why not real nonces, that is, once a request is received in the server with that token, is never to be used nor seen again? Furthermore, is never to be valid again in combination with the session where it was produced, regardless of wheter it was consumed or not. I am probably being naive here, since I just jumped on the topic, but I need to understand if this approach might work, then I would adapt it to Java.</description> <content:encoded><![CDATA[<p>All reserves expressed about the mechanism proposed by Vladimir have to do with nonces being valid for 24 hours. Is that imperative by design? Why not real nonces, that is, once a request is received in the server with that token, is never to be used nor seen again? Furthermore, is never to be valid again in combination with the session where it was produced, regardless of wheter it was consumed or not. I am probably being naive here, since I just jumped on the topic, but I need to understand if this approach might work, then I would adapt it to Java.</p> ]]></content:encoded> </item> <item><title>By: nierdz</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-22122</link> <dc:creator>nierdz</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-22122</guid> <description>Hi,
I tried to implement this in an ajax plugin but i get Call to undefined function wp_create_nonce().
Is there a way to deal with that ?
More precision, the plugin is just an ajax widget and  I use OO by extending the WP_Widget class.</description> <content:encoded><![CDATA[<p>Hi,<br
/> I tried to implement this in an ajax plugin but i get Call to undefined function wp_create_nonce().<br
/> Is there a way to deal with that ?<br
/> More precision, the plugin is just an ajax widget and  I use OO by extending the WP_Widget class.</p> ]]></content:encoded> </item> <item><title>By: Dallas</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-21798</link> <dc:creator>Dallas</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-21798</guid> <description>Like naomi asked, I am using wp 3.01 or whatever.  Does this apply to my site?</description> <content:encoded><![CDATA[<p>Like naomi asked, I am using wp 3.01 or whatever.  Does this apply to my site?</p> ]]></content:encoded> </item> <item><title>By: WordPress. Le guide definitive agli Hacks e ai Tutorial &#8212; Studio404 Web Agency</title><link>http://www.prelovac.com/vladimir/improving-security-in-wordpress-plugins-using-nonces/comment-page-1#comment-21640</link> <dc:creator>WordPress. Le guide definitive agli Hacks e ai Tutorial &#8212; Studio404 Web Agency</dc:creator> <pubDate></pubDate> <guid
isPermaLink="false">http://www.prelovac.com/vladimir/?p=803#comment-21640</guid> <description>[...] Improving security in WordPress plugins using Nonces [...]</description> <content:encoded><![CDATA[<p>[...] Improving security in WordPress plugins using Nonces [...]</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Served from: www.prelovac.com @ 2012-02-14 11:16:26 by W3 Total Cache -->
