<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: WordPress plugin &#8216;Tripwire&#8217; 3rd of three part security plugin set</title>
	<atom:link href="http://herselfswebtools.com/2008/06/wordpress-plugin-tripwire.html/feed" rel="self" type="application/rss+xml" />
	<link>http://herselfswebtools.com/2008/06/wordpress-plugin-tripwire.html</link>
	<description>Scripts, HowTos, Templates, Plugins, Widgets, Tips and Useful Information</description>
	<lastBuildDate>Thu, 25 Feb 2010 23:54:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: timestocome</title>
		<link>http://herselfswebtools.com/2008/06/wordpress-plugin-tripwire.html/comment-page-1#comment-370</link>
		<dc:creator>timestocome</dc:creator>
		<pubDate>Tue, 08 Sep 2009 02:01:24 +0000</pubDate>
		<guid isPermaLink="false">http://herselfswebtools.com/?p=264#comment-370</guid>
		<description>Absolutely, running your security scripts outside of WP is always a better option. 

However that option isn&#039;t available to a lot of bloggers, hence the scripts.

The 3 security plugins are intended for bloggers who don&#039;t have access or knowledge to run scripts outside of WP.

If you do have access to running scripts on your server a cron job to check the files and using .htaccess to ban problem ips/bots is a better way to go.</description>
		<content:encoded><![CDATA[<p>Absolutely, running your security scripts outside of WP is always a better option. </p>
<p>However that option isn&#8217;t available to a lot of bloggers, hence the scripts.</p>
<p>The 3 security plugins are intended for bloggers who don&#8217;t have access or knowledge to run scripts outside of WP.</p>
<p>If you do have access to running scripts on your server a cron job to check the files and using .htaccess to ban problem ips/bots is a better way to go.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gariben</title>
		<link>http://herselfswebtools.com/2008/06/wordpress-plugin-tripwire.html/comment-page-1#comment-369</link>
		<dc:creator>gariben</dc:creator>
		<pubDate>Sat, 29 Aug 2009 17:42:43 +0000</pubDate>
		<guid isPermaLink="false">http://herselfswebtools.com/?p=264#comment-369</guid>
		<description>thanks for releasing the plugin.  My sites are getting hacked and this looks useful.

But if the WordPress site gets hacked (iframe, gumblar), wouldn&#039;t the site not load making the plugin ineffective?

Maybe have a mini script outside of the WordPress framework and have a cron job running every few hours checking the files.  Would that make sense.. Not a programmer.

Thanks, Mike</description>
		<content:encoded><![CDATA[<p>thanks for releasing the plugin.  My sites are getting hacked and this looks useful.</p>
<p>But if the WordPress site gets hacked (iframe, gumblar), wouldn&#8217;t the site not load making the plugin ineffective?</p>
<p>Maybe have a mini script outside of the WordPress framework and have a cron job running every few hours checking the files.  Would that make sense.. Not a programmer.</p>
<p>Thanks, Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ljmacphee</title>
		<link>http://herselfswebtools.com/2008/06/wordpress-plugin-tripwire.html/comment-page-1#comment-269</link>
		<dc:creator>ljmacphee</dc:creator>
		<pubDate>Sun, 31 Aug 2008 23:31:42 +0000</pubDate>
		<guid isPermaLink="false">http://herselfswebtools.com/?p=264#comment-269</guid>
		<description>I asked you first thing this morning to leave a comment here, state your case and offer up something better.  I encourage public comment.  

You didn&#039;t have to threaten, I encouraged you to go public several hours ago.  Which you chose not to do.  I even offered to link to a better plugin or what ever you had to offer.

It is in all of our best interests to keep the internet safe.

It is my understanding that ctime is not available on all systems.  Also if someone can get into your file system, changed files are the least of your concerns.  This program will list all files changed by datestamp.  I think I&#039;ve made that obvious.

It is well known that timestamps can be changed.  This is not news.  This is however something the average script kiddie will be able to pull off.

If you are really concerned you will need to go far beyond ctime and run diff or something similar as well.  But always there are tradeoffs.  Diff would not be available to everyone and much more time consuming, not to mention you&#039;d need to cache copies of the files somewhere.

Please, we would all love for you to update Bad Behavior and write a better tripwire program.  I write plugins to do what I need that has not yet been done.  It is not my main interest.  I would much rather just download what I need and not have to write everything myself.

So quit your bloody whining and do something constructive. 





</description>
		<content:encoded><![CDATA[<p>I asked you first thing this morning to leave a comment here, state your case and offer up something better.  I encourage public comment.  </p>
<p>You didn&#8217;t have to threaten, I encouraged you to go public several hours ago.  Which you chose not to do.  I even offered to link to a better plugin or what ever you had to offer.</p>
<p>It is in all of our best interests to keep the internet safe.</p>
<p>It is my understanding that ctime is not available on all systems.  Also if someone can get into your file system, changed files are the least of your concerns.  This program will list all files changed by datestamp.  I think I&#8217;ve made that obvious.</p>
<p>It is well known that timestamps can be changed.  This is not news.  This is however something the average script kiddie will be able to pull off.</p>
<p>If you are really concerned you will need to go far beyond ctime and run diff or something similar as well.  But always there are tradeoffs.  Diff would not be available to everyone and much more time consuming, not to mention you&#8217;d need to cache copies of the files somewhere.</p>
<p>Please, we would all love for you to update Bad Behavior and write a better tripwire program.  I write plugins to do what I need that has not yet been done.  It is not my main interest.  I would much rather just download what I need and not have to write everything myself.</p>
<p>So quit your bloody whining and do something constructive.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
