westi on wordpress

the long forgotten diary of a wordpress developer

making the default install more secure

WordPress 2.6 will be more secure out-of-the box including better support for running the admin over SSL and changes to disable the remote publishing protocols by default.

We have choosen to disable Atom Publishing Protocol and the variety of XML-RPC protocols by default as they expose a potential to be a security risk.  So from WordPress 2.6 onwards you will need to go into the Settings->Write page and enable them individually if you want to use them.

Written by Peter Westwood

June 20, 2008 at 4:09 pm

Posted in wordpress

Tagged with ,

67 Responses

Subscribe to comments with RSS.

  1. [...] has been addopted by WordPress that decided to block XMLRPC by default in WordPress 2.6. This is not such a big deal but you’ll have to actually enable it. It [...]

  2. [...] ability to disable remote publishing for the security [...]

  3. [...] can also preview themes before you actually use it. There were a lot of updates to make your install more secure, and tons more to enhance the user experience. I wasn’t really expecting to be all this giddy [...]

  4. [...] XML RPC To Be Turned Off By Default [...]

  5. [...] セキュリティにより重きを置くためにリモートパブリッシングを無効にできる機能 [...]

  6. [...] NEW (June 20): Admin SSL support — The WordPress 2.6 admin should be able to be visited via either HTTP (normal connection) or HTTPS (encrypted connection), with the option to make admin HTTPS mandatory. [via] [...]

  7. [...] ability to disable remote publishing for the security [...]

  8. [...] ability to disable remote publishing for the security [...]

  9. [...] feathers. One of the changes that will make their appearance in WordPress 2.6 is the ability to disable remote publishing for those who are security [...]

  10. [...] starting with WordPress 2.6, access to the XMLRPC and AtomPub-based remote publishing interfaces will be disabled by default. Users who wish to use a remote client such as MarsEdit will have to go out of their way to enable [...]

  11. [...] The ability to disable remote publishing [...]

  12. [...] time to find vulnerabilities in your WordPress 2.5.1 blog. With the new version your blog will be more safe. And if you are still using more old versions, you definitely should [...]

  13. [...] WordPress Security Enhancements [...]

  14. Thanks for sharing. Disabling remote publishing by default hopefully will save a lot of headache.
    WordPress is slowly becoming a safer platform.

    Sherif

    July 22, 2008 at 2:54 am

  15. [...] отключения удаленных публикаций по соображениям [...]

  16. Takes 30 seconds or less to re-enable if needed. Can’t see the drama. Even on 2.7 – go to Settings, Writing – tick a box. Only if needed to use that feature.

    Jason

    December 5, 2008 at 11:50 pm

  17. [...] 2.6 is going to join Movable Type in discriminating against blog clients—they are going to disable XML-RPC APIs by default. Users will have to enable them manually. (Movable Type requires you to use special API key instead [...]


Comments are closed.