<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>*﹎♡我愛小提琴♬·۰•●不為帕格尼尼♨ &#187; 升级</title>
	<atom:link href="http://www.didisama.com/tag/%e5%8d%87%e7%ba%a7/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.didisama.com</link>
	<description>我们都生活在一个叫做青春的梦里~梦总有一天会醒来，而回忆将一直闪耀……</description>
	<lastBuildDate>Mon, 22 Mar 2010 12:45:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress升级至2.8.4</title>
		<link>http://www.didisama.com/2009/08/12/wordpress284/</link>
		<comments>http://www.didisama.com/2009/08/12/wordpress284/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 02:14:18 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/2009/08/12/wordpress284/</guid>
		<description><![CDATA[又又又又……升了！还是安全方面的漏洞吧..官方还是用的“强烈建议”这个词，So，更新吧~
Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a secur... ]]></description>
			<content:encoded><![CDATA[<p>又又又又……升了！还是安全方面的漏洞吧..官方还是用的“强烈建议”这个词，So，更新吧~</p>
<blockquote><p>Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner. This doesn’t allow remote access, but it is very annoying.</p>
<p>We fixed this problem last night and have been testing the fixes and looking for other problems since then. <a href="http://wordpress.org/download/">Version 2.8.4 which fixes all known problems is now available for download</a> and is highly recommended for all users of WordPress.</p>
</blockquote>
<p>大概意思是，昨天检查出一个漏洞，攻击者可以通过一个特定的网址绕过安全检查，验证用户并且重设密码。结果会导致数据库中第一个账户（通常是管理员帐户）的密码被重置，并且一个新的密码会被电邮至帐户所有者。这并不允许远程访问，不过也是很讨厌的。昨晚我们已经修复了这个问题，并且不断测试其他可能会出现的情况。现在提供的WordPress2.8.4已经修复了所有已知的问题，强烈建议所有WordPress用户更新。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2009/08/12/wordpress284/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>WordPress升级至2.8.3</title>
		<link>http://www.didisama.com/2009/08/11/wordpress283/</link>
		<comments>http://www.didisama.com/2009/08/11/wordpress283/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 00:39:50 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/2009/08/11/wordpress283/</guid>
		<description><![CDATA[WordPress为修复漏洞又升级了 = =&#124; 然后又升级到2.8.3咯
Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1.&#160; Luckily, the entire WordPress community has our backs.&#160; Several folks in the c... ]]></description>
			<content:encoded><![CDATA[<p>WordPress为修复漏洞又升级了 = =| 然后又升级到2.8.3咯</p>
<blockquote><p>Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1.&#160; Luckily, the entire WordPress community has our backs.&#160; Several folks in the community dug deeper and discovered areas that were overlooked.&#160; With their help, the remaining issues are fixed in 2.8.3.&#160; Since this is a security release, upgrading is highly recommended.&#160; <a href="http://wordpress.org/download/">Download</a> 2.8.3, or upgrade automatically from your admin.</p>
</blockquote>
<p>也就是修复了个权限升级的问题吧，这是作者在2.8.1中遗漏的，既然是安全更新，建议大家实时跟进。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2009/08/11/wordpress283/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>WordPress升级至2.8.2</title>
		<link>http://www.didisama.com/2009/07/24/wordpress282/</link>
		<comments>http://www.didisama.com/2009/07/24/wordpress282/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 01:56:48 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/2009/07/24/wordpress282/</guid>
		<description><![CDATA[转眼WordPress又更新到2.8.2咯，我记得半个月貌似才更新的2.8.1嘛..还没用安稳又升了= =&#124;
WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be expl... ]]></description>
			<content:encoded><![CDATA[<p>转眼WordPress又更新到2.8.2咯，我记得半个月貌似才更新的2.8.1嘛..还没用安稳又升了= =|</p>
<blockquote><p>WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site.&#160; <a href="http://wordpress.org/download/">Download</a> 2.8.2 or automatically upgrade from the Tools-&gt;Upgrade page of your blog’s admin.</p>
</blockquote>
<p>WordPress修补了一个XSS漏洞，评论作者的网址如果没有经过完全审查便显示在管理页面时，很可能让你从管理页面跳转到另外的网址。虽然没有遇到过这样的情况，看了下大家，基本上都升级了，所以~还是建议没升级的去下载或者是自动升级吧！（当然是选自动啦，多方便，hoho）</p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2009/07/24/wordpress282/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>WordPress升级至2.8.1</title>
		<link>http://www.didisama.com/2009/07/13/wordpress281/</link>
		<comments>http://www.didisama.com/2009/07/13/wordpress281/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 04:02:19 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/2009/07/13/wordpress281/</guid>
		<description><![CDATA[WordPress2.8.1的版本又出来啦~反正是自动升级么，我点点点~
WordPress 2.8.1 fixes many bugs and tightens security for plugin administration pages. Core Security Technologies notified us that admin pages added by certain plugins could be ... ]]></description>
			<content:encoded><![CDATA[<p>WordPress2.8.1的版本又出来啦~反正是自动升级么，我点点点~</p>
<blockquote><p>WordPress 2.8.1 fixes <a href="http://core.trac.wordpress.org/query?status=closed&amp;group=resolution&amp;order=priority&amp;milestone=2.8.1&amp;resolution=fixed">many bugs</a> and tightens security for plugin administration pages. <a href="http://corelabs.coresecurity.com/index.php?module=FrontEndMod&amp;action=list&amp;type=advisory">Core Security Technologies</a> notified us that admin pages added by certain plugins could be viewed by unprivileged users, resulting in information being leaked. Not all plugins are vulnerable to this problem, but we advise upgrading to 2.8.1 to be safe</p>
</blockquote>
<p>这是官方的升级说明，大概翻译过来就是：</p>
<p>WordPress的2.8.1修正了许多bug，加强了插件管理页面的安全性。Core Security Technologies通知官方，管理页面添加某些插件可以被认为是无特权的用户而导致信息泄漏。虽然并不是所有的插件都会遇到这个问题，但建议升级到2.8.1来保证安全。</p>
<p>官方都这么建议了，所以~大家还是与时俱进吧~hoho</p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2009/07/13/wordpress281/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>WordPress升级至2.7.1</title>
		<link>http://www.didisama.com/2009/02/12/wordpress271/</link>
		<comments>http://www.didisama.com/2009/02/12/wordpress271/#comments</comments>
		<pubDate>Thu, 12 Feb 2009 00:40:31 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/2009/02/12/wordpress%e5%8d%87%e7%ba%a7%e8%87%b3271/</guid>
		<description><![CDATA[昨天WordPress后台提示能升级了，新版本是2.7.1，主要是修复了一些Bug。本想先去论坛看看大家的评论再决定是否升级，手一快还是点了那个自动升级按钮~ （就没考虑会不会出问题吗？抽）
呆了... ]]></description>
			<content:encoded><![CDATA[<p>昨天WordPress后台提示能升级了，新版本是2.7.1，主要是修复了一些Bug。本想先去论坛看看大家的评论再决定是否升级，手一快还是点了那个自动升级按钮~ （就没考虑会不会出问题吗？抽）</p>
<p>呆了数秒后提示我升级成功了~ 这期间我一直张大嘴巴看着..囧（没想到自动升级这么方便）</p>
<p>印象中我只修改了主题文件，所以如果你对WP文件修改比较多的话，建议还是暂时别升，或者备份好你修改过的文件后再升级..</p>
<p><a href="http://wordpress.org/development/2009/02/wordpress-271/" target="_blank">猛点我去官方看更新日志</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2009/02/12/wordpress271/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>WordPress升级至2.6.5</title>
		<link>http://www.didisama.com/2008/11/27/wordpress265/</link>
		<comments>http://www.didisama.com/2008/11/27/wordpress265/#comments</comments>
		<pubDate>Thu, 27 Nov 2008 08:26:00 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/2008/11/27/wordpress%e5%8d%87%e7%ba%a7%e8%87%b3265-2/</guid>
		<description><![CDATA[今早一来发现WordPress2.6.5发布了~

WordPress 2.6.5 修正了一个可能会引发跨站攻击的 Bug。幸运的是，这个Bug 只影响运行 Apache 2.x 的基于 IP 的虚拟主机。除此之外，另有以下三处改进：

防止日志元... ]]></description>
			<content:encoded><![CDATA[<p>今早一来发现<a href="http://wordpress.org.cn/thread-24996-1-1.html" target="_blank">WordPress2.6.5发布了</a>~</p>
<blockquote><p><br/>
<p>WordPress 2.6.5 修正了一个可能会引发跨站攻击的 Bug。幸运的是，这个Bug 只影响运行 Apache 2.x 的基于 IP 的虚拟主机。<br/>除此之外，另有以下三处改进：<br/></p>
<ul type="1">
<li>防止日志元信息意外地写入到修订版本之中</li>
<li>防止 XML-RPC 获取错误的日志类型</li>
<li>在批量删除前对用户 ID 进行检查过滤</li>
</ul>
<p>WordPress 2.6.4 已经被跳过。语言包无变化，可沿用 WordPress 2.6.2 的语言包。</p>
</blockquote>
<ul>
<li><a href="http://wordpress.org/wordpress-2.6.5.zip" target="_blank">WordPress2.6.5完整压缩包</a></li>
<li><a href="http://wpcn.googlecode.com/files/diff-from-tags_2.6.3-r9870-to-tags_2.6.5-r9870.zip" target="_blank">WordPress 2.6.3 到 2.6.5 的升级补丁</a></li>
<li><a href="http://wpcn.googlecode.com/files/WordPress.MU.v2.6.2.Simp.Chinese.pack.only.v1-wpcng.zip" target="_blank">WordPress 2.6.5 语言包</a></li>
</ul>
<p>下载后解压缩，上传覆盖旧文件，OK~<br/></p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2008/11/27/wordpress265/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>WordPress升级至2.6.3</title>
		<link>http://www.didisama.com/2008/10/27/wordpress263/</link>
		<comments>http://www.didisama.com/2008/10/27/wordpress263/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 00:44:11 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/2008/10/27/wordpress%e5%8d%87%e7%ba%a7%e8%87%b3263/</guid>
		<description><![CDATA[早上一来就看到WordPress更新到2.6.3了，改动很少，只是一个小的安全更新补丁~
如果是从2.6.2升级的话，只需要下载升级包后上传覆盖即可，升级包内含有三个文件：
wordpresswp-includes目录下的class... ]]></description>
			<content:encoded><![CDATA[<p>早上一来就看到WordPress更新到2.6.3了，改动很少，只是一个小的安全更新补丁~</p>
<p>如果是从2.6.2升级的话，只需要下载<a href="http://wpcn.googlecode.com/files/wordpress-2.6.2to2.6.3.zip" target="_blank">升级包</a>后上传覆盖即可，升级包内含有三个文件：</p>
<p>wordpresswp-includes目录下的class-snoopy.php、version.php，wordpresswp-adminincludes目录下的media.php</p>
<p>顺便期待下WordPress2.7早日发布~</p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2008/10/27/wordpress263/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>升级到WordPress2.6.2</title>
		<link>http://www.didisama.com/2008/09/09/wordpress262/</link>
		<comments>http://www.didisama.com/2008/09/09/wordpress262/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 07:26:26 +0000</pubDate>
		<dc:creator>DiDi</dc:creator>
				<category><![CDATA[计算机与Internet]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[升级]]></category>

		<guid isPermaLink="false">http://www.didisama.com/?p=124</guid>
		<description><![CDATA[今天打开后台提示有新版本2.6.2出来了，论坛速度很快，已经发出了简体中文版的下载~
WordPress 中文团队也已经根据官方的压缩包制作出了简体中文版。
本次更新，主要是修正了一些 Bug，并且... ]]></description>
			<content:encoded><![CDATA[<p>今天打开后台提示有新版本2.6.2出来了，<a href="http://wordpress.org.cn/thread-20002-1-1.html" target="_blank">论坛</a>速度很快，已经发出了简体中文版的<a href="http://code.google.com/p/wpcn/downloads/list" target="_blank">下载</a>~</p>
<blockquote><p>WordPress 中文团队也已经根据官方的压缩包制作出了简体中文版。</p>
<p>本次更新，主要是修正了一些 Bug，并且排除了多处安全隐患。所以，如果您使用的是 WordPress 2.6.1 或更老的版本，强烈建议您进行升级。</p></blockquote>
<p>下载覆盖上传完毕，居然不需要运行upgrade.php..哈&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.didisama.com/2008/09/09/wordpress262/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
