<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: GNUCITIZEN Wordpress Plugins</title>
	<atom:link href="http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Thu, 11 Mar 2010 22:49:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: WordPress World: 50+ excellent WordPress Plugins, articles and resources - Stalkk.ed</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-126992</link>
		<dc:creator>WordPress World: 50+ excellent WordPress Plugins, articles and resources - Stalkk.ed</dc:creator>
		<pubDate>Mon, 11 May 2009 18:36:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-126992</guid>
		<description>[...] WordPress IPS - The WordPress IPS is probably one of the lightest plugins you will ever encounter but its power is immense and incomparable to anything else seen. The plugin is designed to simply block malicious requests before being processed by the WordPress engine and therefore secure against common and well known attack vectors. [...]</description>
		<content:encoded><![CDATA[<p>[...] WordPress IPS &#8211; The WordPress IPS is probably one of the lightest plugins you will ever encounter but its power is immense and incomparable to anything else seen. The plugin is designed to simply block malicious requests before being processed by the WordPress engine and therefore secure against common and well known attack vectors. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-126441</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Fri, 03 Apr 2009 08:56:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-126441</guid>
		<description>Dan, this is quite easy to do but of course quite insecure. You can code a very simply plugin just for this purpose but I wont recommend it.</description>
		<content:encoded><![CDATA[<p>Dan, this is quite easy to do but of course quite insecure. You can code a very simply plugin just for this purpose but I wont recommend it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-126440</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Fri, 03 Apr 2009 00:52:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-126440</guid>
		<description>Hmm, I like the direction of the app gateway plugin. However I was wondering how straight forward it might be to modify its code to automatically enter google account information for more automation when users sign up? eg. my wordpress mu install and google mail share the  same domain... so if users are created with the same username as their googlemail username, could it automatically sign them in? (obviously the passwords would have to match)

Cheers
Dan</description>
		<content:encoded><![CDATA[<p>Hmm, I like the direction of the app gateway plugin. However I was wondering how straight forward it might be to modify its code to automatically enter google account information for more automation when users sign up? eg. my wordpress mu install and google mail share the  same domain&#8230; so if users are created with the same username as their googlemail username, could it automatically sign them in? (obviously the passwords would have to match)</p>
<p>Cheers<br />
Dan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cameron</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122545</link>
		<dc:creator>Cameron</dc:creator>
		<pubDate>Wed, 18 Jun 2008 16:42:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122545</guid>
		<description>If you could do this, to would open a whole world of possibilities for Google Apps for domains users.

I would love to use Word Press as a gateway to host a number of online applications I wish to integrate with our Google Apps for domains system.  It&#039;s simple enough to embed a Wordpress site into the new  Google Sites -but securing the site and integrating it with existing Google Apps (for domains) user&#039;s logins is the barrier to doing this. 

Such a plugin would allow admins to integrate Quickbooks, Zoho Creator, or a number of other applications right inside google sites.</description>
		<content:encoded><![CDATA[<p>If you could do this, to would open a whole world of possibilities for Google Apps for domains users.</p>
<p>I would love to use Word Press as a gateway to host a number of online applications I wish to integrate with our Google Apps for domains system.  It&#8217;s simple enough to embed a Wordpress site into the new  Google Sites -but securing the site and integrating it with existing Google Apps (for domains) user&#8217;s logins is the barrier to doing this. </p>
<p>Such a plugin would allow admins to integrate Quickbooks, Zoho Creator, or a number of other applications right inside google sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122539</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 18 Jun 2008 08:47:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122539</guid>
		<description>hello Cameron, I might end up writing such a plugin. thanks for the idea.</description>
		<content:encoded><![CDATA[<p>hello Cameron, I might end up writing such a plugin. thanks for the idea.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Cameron</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122536</link>
		<dc:creator>Cameron</dc:creator>
		<pubDate>Tue, 17 Jun 2008 23:33:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122536</guid>
		<description>pdp,

I&#039;m looking for a way to secure my wordpress site using the same credentials my users are using in Google apps for domains.

Will this plugin allow people logged into Google apps for domains to seemlessly access my wordpress site?</description>
		<content:encoded><![CDATA[<p>pdp,</p>
<p>I&#8217;m looking for a way to secure my wordpress site using the same credentials my users are using in Google apps for domains.</p>
<p>Will this plugin allow people logged into Google apps for domains to seemlessly access my wordpress site?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prima prova. -- TRUEMILKDOTORG</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122278</link>
		<dc:creator>Prima prova. -- TRUEMILKDOTORG</dc:creator>
		<pubDate>Mon, 26 May 2008 20:48:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122278</guid>
		<description>[...] altra cosetta. Nel frattempo si ringraziano cordialmente Flisterz per il tema e Gnucitizen per i plugins.         &#171; Hello [...]</description>
		<content:encoded><![CDATA[<p>[...] altra cosetta. Nel frattempo si ringraziano cordialmente Flisterz per il tema e Gnucitizen per i plugins.         &laquo; Hello [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prasannah</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122243</link>
		<dc:creator>Prasannah</dc:creator>
		<pubDate>Sun, 25 May 2008 06:15:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122243</guid>
		<description>I&#039;ve added the details and it works. But in my settings section it always shows:

&lt;pre&gt;&lt;code&gt;Applications
Storage not loaded!

Designer
Storage not loaded!&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>I&#8217;ve added the details and it works. But in my settings section it always shows:</p>
<pre><code>Applications
Storage not loaded!

Designer
Storage not loaded!</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122242</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 25 May 2008 06:11:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122242</guid>
		<description>you have to configure the plugin first but yes.</description>
		<content:encoded><![CDATA[<p>you have to configure the plugin first but yes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prasannah</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122241</link>
		<dc:creator>Prasannah</dc:creator>
		<pubDate>Sun, 25 May 2008 06:02:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122241</guid>
		<description>So that is, if I&#039;m logged in to Wordpress and if I use the same login details for gmail, I&#039;ll be taken to Gmail without asking for the login details is it?</description>
		<content:encoded><![CDATA[<p>So that is, if I&#8217;m logged in to Wordpress and if I use the same login details for gmail, I&#8217;ll be taken to Gmail without asking for the login details is it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122240</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 25 May 2008 05:58:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122240</guid>
		<description>all this plugin will do is to allow you to use your wordpress to authenticated with your google mail account, so you don&#039;t have to login twice. your gmail credentials are locked with a master key which means that if somebody manages to crack into your wordpress account they still need to guess the master key in order to login into your other accounts. so, if you are planning to use it make sure that you choose significantly complicated key of at least 12 characters.</description>
		<content:encoded><![CDATA[<p>all this plugin will do is to allow you to use your wordpress to authenticated with your google mail account, so you don&#8217;t have to login twice. your gmail credentials are locked with a master key which means that if somebody manages to crack into your wordpress account they still need to guess the master key in order to login into your other accounts. so, if you are planning to use it make sure that you choose significantly complicated key of at least 12 characters.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Prasannah</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-122238</link>
		<dc:creator>Prasannah</dc:creator>
		<pubDate>Sun, 25 May 2008 05:01:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-122238</guid>
		<description>I&#039;m kinda new to this whole gateway concept? I am primarily looking for a way for my users to be able to use Google Apps directly if they are logged in to my Wordpress site. Can this plugin help me do this?</description>
		<content:encoded><![CDATA[<p>I&#8217;m kinda new to this whole gateway concept? I am primarily looking for a way for my users to be able to use Google Apps directly if they are logged in to my Wordpress site. Can this plugin help me do this?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-119279</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 21 Apr 2008 08:52:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-119279</guid>
		<description>I am glad that you find them useful. Newer versions of the plugs will be released soon.</description>
		<content:encoded><![CDATA[<p>I am glad that you find them useful. Newer versions of the plugs will be released soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adieska</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-119176</link>
		<dc:creator>Adieska</dc:creator>
		<pubDate>Sun, 20 Apr 2008 16:14:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-119176</guid>
		<description>Thanks for sharing. I&#039;m a newbie in wordpress. Before I migrate to WP, I&#039;m using free Blogspot blog. Once again thanks.</description>
		<content:encoded><![CDATA[<p>Thanks for sharing. I&#8217;m a newbie in wordpress. Before I migrate to WP, I&#8217;m using free Blogspot blog. Once again thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stevens</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-117768</link>
		<dc:creator>Stevens</dc:creator>
		<pubDate>Wed, 02 Apr 2008 13:28:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-117768</guid>
		<description>cool plugin for Wordpress. I&#039;ve been waiting for more plugin. Usefull and it&#039;s great. Good job</description>
		<content:encoded><![CDATA[<p>cool plugin for Wordpress. I&#8217;ve been waiting for more plugin. Usefull and it&#8217;s great. Good job</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Greenberg</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-115746</link>
		<dc:creator>Ben Greenberg</dc:creator>
		<pubDate>Fri, 29 Feb 2008 17:00:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-115746</guid>
		<description>Thanks for your reply! This looks quite doable. I&#039;m looking forward to experimenting with this. My scheme here is to have an internal work blog that I&#039;ve set up be the gateway to other information like a communications planning calendar. Might be a week or two before I&#039;m able to work on this further. I&#039;ll let you know how it goes.</description>
		<content:encoded><![CDATA[<p>Thanks for your reply! This looks quite doable. I&#8217;m looking forward to experimenting with this. My scheme here is to have an internal work blog that I&#8217;ve set up be the gateway to other information like a communications planning calendar. Might be a week or two before I&#8217;m able to work on this further. I&#8217;ll let you know how it goes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-115740</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 29 Feb 2008 09:58:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-115740</guid>
		<description>Ben, thanks. We have dozens more plugins to release to the public and we will do that as soon as possible. Let me answer your question here:

The App gateway currently supports GMail only. But it is very easy to make it support whatever else you want. Within the folder of the plugin, you will find a file called &lt;code&gt;gc-app-gateway-catalog.jsn&lt;/code&gt;.

Notice the &lt;code&gt;gmail&lt;/code&gt; branch. In order to add a new application, you have add a new branch. For example you can call it &lt;code&gt;facebook&lt;/code&gt;. For the &lt;code&gt;template&lt;/code&gt; parameter you have to specify the code that will be rendered within a new frame which will perform a CSRF request against the login form.

Just follow the syntax in this file and you will quickly get the grip of it. There is a security reason why we choose this model instead of storing that kind of things in the database. I might add some more applications soon but if you can do that and help us expand on this wonderful plugin, it will be even better.</description>
		<content:encoded><![CDATA[<p>Ben, thanks. We have dozens more plugins to release to the public and we will do that as soon as possible. Let me answer your question here:</p>
<p>The App gateway currently supports GMail only. But it is very easy to make it support whatever else you want. Within the folder of the plugin, you will find a file called <code>gc-app-gateway-catalog.jsn</code>.</p>
<p>Notice the <code>gmail</code> branch. In order to add a new application, you have add a new branch. For example you can call it <code>facebook</code>. For the <code>template</code> parameter you have to specify the code that will be rendered within a new frame which will perform a CSRF request against the login form.</p>
<p>Just follow the syntax in this file and you will quickly get the grip of it. There is a security reason why we choose this model instead of storing that kind of things in the database. I might add some more applications soon but if you can do that and help us expand on this wonderful plugin, it will be even better.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Greenberg</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-115738</link>
		<dc:creator>Ben Greenberg</dc:creator>
		<pubDate>Thu, 28 Feb 2008 21:34:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-115738</guid>
		<description>This is a nice collection of plugins. I just installed App Gateway in a Wordpress MU installation (v. 1.25) that I&#039;ve got set up at work. When I use the Designer on the App Gateway options page, the only option available in the type pull down is gmail. I want to use this plugin for google apps under my own domain. So I want to be able to configure accordingly. Can you give my any pointers?

Many thanks!</description>
		<content:encoded><![CDATA[<p>This is a nice collection of plugins. I just installed App Gateway in a Wordpress MU installation (v. 1.25) that I&#8217;ve got set up at work. When I use the Designer on the App Gateway options page, the only option available in the type pull down is gmail. I want to use this plugin for google apps under my own domain. So I want to be able to configure accordingly. Can you give my any pointers?</p>
<p>Many thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: holotone.net</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-108801</link>
		<dc:creator>holotone.net</dc:creator>
		<pubDate>Mon, 04 Feb 2008 00:30:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-108801</guid>
		<description>[...] GNUCITIZEN Wordpress Plugins &#124; GNUCITIZEN [...]</description>
		<content:encoded><![CDATA[<p>[...] GNUCITIZEN Wordpress Plugins | GNUCITIZEN [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins/comment-page-1/#comment-104544</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 27 Jan 2008 22:08:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/gnucitizen-wordpress-plugins#comment-104544</guid>
		<description>Joe,

I think that we&#039;ve tested a few Analytics plugins and they all seamed to have at least one security problem. The one that we used to use, forgot the name but it should be the most popular plugin that does the job, has problems with quotes. Because the plugin automatically adds some JavaScript trickery for each anchor tag and because the author failed to sanitize single quotes, and because all Wordpress tags use single quotes for the tag attributes, it is possible to break out of the XSS protection mechanisms and persistently store JavaScript within the comment. This was in particular quite nasty but I failed to report the problem due to the fact that I didn&#039;t have much time back then. That was like 2-3 months ago. The plugin might be still very vulnerable.</description>
		<content:encoded><![CDATA[<p>Joe,</p>
<p>I think that we&#8217;ve tested a few Analytics plugins and they all seamed to have at least one security problem. The one that we used to use, forgot the name but it should be the most popular plugin that does the job, has problems with quotes. Because the plugin automatically adds some JavaScript trickery for each anchor tag and because the author failed to sanitize single quotes, and because all Wordpress tags use single quotes for the tag attributes, it is possible to break out of the XSS protection mechanisms and persistently store JavaScript within the comment. This was in particular quite nasty but I failed to report the problem due to the fact that I didn&#8217;t have much time back then. That was like 2-3 months ago. The plugin might be still very vulnerable.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
