<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: More About IFrame Injections</title>
	<atom:link href="http://www.memwg.com/more-about-iframe-injections/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.memwg.com/more-about-iframe-injections/</link>
	<description>Eric Giguere&#039;s AdSense Tips</description>
	<lastBuildDate>Mon, 02 Jan 2012 15:55:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Johnny</title>
		<link>http://www.memwg.com/more-about-iframe-injections/comment-page-1/#comment-5100</link>
		<dc:creator>Johnny</dc:creator>
		<pubDate>Tue, 03 Jun 2008 15:33:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.memwg.com/?p=1368#comment-5100</guid>
		<description>Eric,

THANK YOU for the additional security info.

But, one more thing...

How do you prevent it from happening in the first place?

Do you just validate your incoming (form?) data by (1)parsing strings for evil commands and (2)checking to make sure that data comes from your site and not a fake page set up by a hacker? (There must be a PHP environment variable that can tell you what page a form&#039;s data was submitted from, right?)

Or are hackers somehow just exploiting WordPress security holes?

Regards,
Johnny</description>
		<content:encoded><![CDATA[<p>Eric,</p>
<p>THANK YOU for the additional security info.</p>
<p>But, one more thing&#8230;</p>
<p>How do you prevent it from happening in the first place?</p>
<p>Do you just validate your incoming (form?) data by (1)parsing strings for evil commands and (2)checking to make sure that data comes from your site and not a fake page set up by a hacker? (There must be a PHP environment variable that can tell you what page a form&#8217;s data was submitted from, right?)</p>
<p>Or are hackers somehow just exploiting WordPress security holes?</p>
<p>Regards,<br />
Johnny</p>
]]></content:encoded>
	</item>
</channel>
</rss>

