<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: WordPress anti-spam recipe</title>
	<atom:link href="http://docwhat.gerf.org/2007/08/rename-wp-comment-post/feed/" rel="self" type="application/rss+xml" />
	<link>http://docwhat.gerf.org/2007/08/rename-wp-comment-post/</link>
	<description>Some men are discovered; others are found out</description>
	<pubDate>Thu, 28 Aug 2008 03:28:28 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: docwhat</title>
		<link>http://docwhat.gerf.org/2007/08/rename-wp-comment-post/#comment-2217</link>
		<dc:creator>docwhat</dc:creator>
		<pubDate>Thu, 30 Aug 2007 15:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://docwhat.gerf.org/2007/08/rename-wp-comment-post/#comment-2217</guid>
		<description>So, the downside to this is that you need to add exceptions for things like &lt;a href="http://www.ttancm.com/2007/05/19/wp-amazon-for-wp-21-22/" rel="nofollow"&gt;wp-amazon (ttancm version)&lt;/a&gt;.

In addition, if you have rewrite rules for using &lt;a href="http://haris.tv/2007/04/24/admin-ssl-new-wordpress-plugin/" rel="nofollow"&gt;wp-admin-ssl&lt;/a&gt;, you'll have to modify them so that &lt;tt&gt;wp-content/plugins/wp-admin.php&lt;/tt&gt; is accessible via https.

Finally, there is a &lt;a href="http://comox.textdrive.com/pipermail/wp-hackers/2007-August/013887.html" rel="nofollow"&gt;thread&lt;/a&gt; on the wp-hackers mailing list about the idea of hiding /wp-content files.  Specifically, Otto has &lt;a href="http://comox.textdrive.com/pipermail/wp-hackers/2007-August/014076.html" rel="nofollow"&gt;several good reasons&lt;/a&gt; why hiding wp-contents makes no difference, since it hackers won't scan for a plugins, they scan for vulnerabilities.

Except for inactive plugins, it doesn't matter if someone can scan for a plugin.

Ciao!</description>
		<content:encoded><![CDATA[<p>So, the downside to this is that you need to add exceptions for things like <a href="http://www.ttancm.com/2007/05/19/wp-amazon-for-wp-21-22/"  class="extlink">wp-amazon (ttancm version)</a>.</p>
<p>In addition, if you have rewrite rules for using <a href="http://haris.tv/2007/04/24/admin-ssl-new-wordpress-plugin/"  class="extlink">wp-admin-ssl</a>, you&#8217;ll have to modify them so that <tt>wp-content/plugins/wp-admin.php</tt> is accessible via https.</p>
<p>Finally, there is a <a href="http://comox.textdrive.com/pipermail/wp-hackers/2007-August/013887.html"  class="extlink">thread</a> on the wp-hackers mailing list about the idea of hiding /wp-content files.  Specifically, Otto has <a href="http://comox.textdrive.com/pipermail/wp-hackers/2007-August/014076.html"  class="extlink">several good reasons</a> why hiding wp-contents makes no difference, since it hackers won&#8217;t scan for a plugins, they scan for vulnerabilities.</p>
<p>Except for inactive plugins, it doesn&#8217;t matter if someone can scan for a plugin.</p>
<p>Ciao!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
