Archiv für das Tag "Security"

Advice for Companies Fighting Ad Blockers - TJ van Toll

(…) Publishers that believe they can convince ad blocker users to turn off a tool that protects their privacy and data plans need to realize they’re on the wrong side of history. Respect your users or you’ll lose them.

WordPress 4.5.3 Security Release


Gestern abend ist eine neue Version mit Sicherheits- und Wartungsfixes erschienen. Bei den diversen Installationen, in die ich involviert bin, hat sich das automatisch aktualisiert, auch bei älteren Versionen als 4.5.2, wie gehabt gibt es die Source aber auch zum Download auf

WordPress versions 4.5.2 and earlier are affected by several security issues: redirect bypass in the customizer, reported by Yassine Aboukir; two different XSS problems via attachment names, reported by Jouko Pynnönen and Divyesh Prajapati; revision history information disclosure, reported independently by John Blackbourn from the WordPress security


WordPress 4.5.2 Security Update


Heute Nacht ist ein neues Sicherheitsupdate für WordPress erschienen und hat sich hier bei mir auch auf diversen Seiten selbst aktualisiert:

WordPress versions 4.5.1 and earlier are affected by a SOME vulnerability through Plupload, the third-party library WordPress uses for uploading files. WordPress versions 4.2 through 4.5.1 are vulnerable to reflected XSS using specially crafted URIs through MediaElement.js, the third-party library used for media players. MediaElement.js and Plupload have also released updates fixing these issues.

Mathias Bynens - Front-End Performance: The Dark Side

Vimeo direct link

Watch this 20 minute talk by @mathias at @fronteers and get a glimpse on how the execution time of functions can be used to reveal data about what your browser has in store about you to third parties.

Apple "Customer Letter" regarding US authorities asking to build a backdoor to the iPhone

This moment calls for public discussion, and we want our customers and people around the country to understand what is at stake.

Wow. I think this is huge:

[…] now the U.S. government has asked us for something we simply do not have, and something we consider too dangerous to create. They have asked us to build a backdoor to the iPhone.

Specifically, the FBI wants us to make a new version of the iPhone operating system, circumventing several important security features, and install it on an iPhone recovered during the investigation. In the wrong hands, this software — which


WordPress 4.4.2 Security Update


Vor ein paar Stunden ist ein neues Wartungs- und Sicherheitsupdate erschienen, und offenbar (meint mein Maileingang) läuft der automatische Roll-Out auch schon und auch bei älteren Versionen.

This is a security release for all previous versions and we strongly encourage you to update your sites immediately.

WordPress versions 4.4.1 and earlier are affected by two security issues: a possible SSRF for certain local URIs […]
In addition to the security issues above, WordPress 4.4.2 fixes 17 bugs from 4.4 and 4.4.1. For more information, see the release notes or consult the


WordPress 4.4.1 Security Update


Ein Update für die kürzlich erschienene 4.4er Version ist erschienen

WordPress 4.4.1 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.4 and earlier are affected by a cross-site scripting vulnerability that could allow a site to be compromised.

Husch, husch, ran an den Aktualisierungsspeck.

WordPress 4.2.4 Security Update


Vor vier Tage wurde ein Sicherheitsupdate des Blogmotors veröffentlicht, und weil das mittlerweile bei den meisten WP Installationen hier im Bloghüttenhaushalt automatisch im Hintergrund passiert, wäre mir fast durchgerutscht, darauf hinzuweisen, sorry.

This release addresses six issues, including three cross-site scripting vulnerabilities and a potential SQL injection that could be used to compromise a site, which were discovered by Marc-Alexandre Montpas of Sucuri, Helen Hou-Sandí of the WordPress security team, Netanel Rubin of Check Point, and Ivan Grigorov. It also includes a fix for a potential timing side-channel attack, discovered by Johannes Schmitt of Scrutinizer, and prevents an attacker


WordPress 4.2.2 Security Update

Und schon wieder gibt es ein Sicherheitsupdate für WordPress:

WordPress 4.2.2 is now available. This is a critical security release for all previous versions and we strongly encourage you to update your sites immediately.

Die WP Entwickler sind echt fleissig, und dank des Auto-Updates muss man, sofern aktiviert, auch gar nicht mehr selbst runter in den Keller… aber nachschauen und kontrollieren, ob noch alles läuft, muss man halt trotzdem. Hoffentlich halten die Backups im Fall der Fälle. Ihr macht doch regelmässig Backups, gell.

The design, the code, 1860 texts, the illustrations, and some photos are made by me.

Motorisiert durch WordPress