<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/1.5.1-alpha" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Did you know&#8230;</title>
	<link>http://deadbeef.blogsome.com/2005/08/29/did-you-know/</link>
	<description>Sating the digital medium with semi-intelligible filler.</description>
	<pubDate>Thu, 03 Dec 2009 16:25:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=1.5.1-alpha</generator>

	<item>
		<title>by: Scott Hughes</title>
		<link>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-39</link>
		<pubDate>Wed, 31 Aug 2005 16:02:19 +0100</pubDate>
		<guid>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-39</guid>
					<description>It just occured to me why blogsome is 'over-escaping' everything.  The xmlrpc.php is, apparently, a favorite entry point for crackers (not crusty white folks, but script kids).  So, to be on the safe side, they just over escape.  Keeps you from doing:

username = &quot;\&quot;; drop table *;\&quot;&quot;

Where their sql query might be:

SELECT * FROM tblUsers WHERE Username=&quot;$username&quot;</description>
		<content:encoded><![CDATA[	<p>It just occured to me why blogsome is &#8216;over-escaping&#8217; everything.  The xmlrpc.php is, apparently, a favorite entry point for crackers (not crusty white folks, but script kids).  So, to be on the safe side, they just over escape.  Keeps you from doing:</p>
	<p>username = &#8220;\&#8221;; drop table *;\&#8221;"</p>
	<p>Where their sql query might be:</p>
	<p>SELECT * FROM tblUsers WHERE Username=&#8221;$username&#8221;
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Scott Hughes</title>
		<link>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-37</link>
		<pubDate>Mon, 29 Aug 2005 21:58:41 +0100</pubDate>
		<guid>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-37</guid>
					<description>Just noticed that &quot;Wordpress&quot; is an option now..  when I set mine up, There wasn't a choice for wordpress.  So, either Wordpress needs to be configured to stop escaping, or Flickr does.  Since you can just re-set it up on Flickr, I would do that.</description>
		<content:encoded><![CDATA[	<p>Just noticed that &#8220;Wordpress&#8221; is an option now..  when I set mine up, There wasn&#8217;t a choice for wordpress.  So, either Wordpress needs to be configured to stop escaping, or Flickr does.  Since you can just re-set it up on Flickr, I would do that.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Scott Hughes</title>
		<link>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-36</link>
		<pubDate>Mon, 29 Aug 2005 21:56:09 +0100</pubDate>
		<guid>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-36</guid>
					<description>Maybe you botched the setup.  I posted plenty of pictures to my blogsome account from Flickr, with no problems.

For reference, here's my setup (for blogsome):

Blog Type/Service:  	MetaWeblogAPI
Endpoint: 	http://shughes.blogsome.com/xmlrpc.php
</description>
		<content:encoded><![CDATA[	<p>Maybe you botched the setup.  I posted plenty of pictures to my blogsome account from Flickr, with no problems.</p>
	<p>For reference, here&#8217;s my setup (for blogsome):</p>
	<p>Blog Type/Service:  	MetaWeblogAPI<br />
Endpoint: 	<a href='http://shughes.blogsome.com/xmlrpc.php' rel='nofollow'>http://shughes.blogsome.com/xmlrpc.php</a>
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Administrator</title>
		<link>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-35</link>
		<pubDate>Mon, 29 Aug 2005 19:21:24 +0100</pubDate>
		<guid>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-35</guid>
					<description>So this &quot;service&quot; is really not all that useful is Worpdress is going to fark it up so bad that I have  to hand edit it everytime I post. I might as well not post it then, or wait until I'm at a computer I can upload the image and then edit the entry from. </description>
		<content:encoded><![CDATA[	<p>So this &#8220;service&#8221; is really not all that useful is Worpdress is going to fark it up so bad that I have  to hand edit it everytime I post. I might as well not post it then, or wait until I&#8217;m at a computer I can upload the image and then edit the entry from.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Administrator</title>
		<link>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-34</link>
		<pubDate>Mon, 29 Aug 2005 19:20:01 +0100</pubDate>
		<guid>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-34</guid>
					<description>The problem is that the Flickr posting service or the Wordpress API escaped every single quote mark and double quote mark (even the ones in the HTML) and added a break for every newline and new feed.</description>
		<content:encoded><![CDATA[	<p>The problem is that the Flickr posting service or the Wordpress API escaped every single quote mark and double quote mark (even the ones in the HTML) and added a break for every newline and new feed.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Administrator</title>
		<link>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-33</link>
		<pubDate>Mon, 29 Aug 2005 19:15:58 +0100</pubDate>
		<guid>http://deadbeef.blogsome.com/2005/08/29/did-you-know/#comment-33</guid>
					<description>Wow, that was horrible! The formatting is all wrong and the picture didn't even come through! Ack!</description>
		<content:encoded><![CDATA[	<p>Wow, that was horrible! The formatting is all wrong and the picture didn&#8217;t even come through! Ack!
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
