Tag: security

  • Naughty Plugins Caught And Removed From Repository

    Naughty Plugins Caught And Removed From Repository

    Siobhan McKeown has published a disturbing yet not out of the ordinary article that explains how a couple of plugins were recently added to the plugin repository that were using a version of J-Query from J-Query.org which after investigation proved to be a fake website. The purported J-Query file was actually propagating sites with CPA…

  • VaultPress Now Supports WordPress Multisite

    VaultPress Now Supports WordPress Multisite

    VaultPress has announced that the latest edition of the plugin now supports WordPress Multisite. This has been a killer feature that owners of large multisite installs have been waiting for. VaultPress will automatically backup each site that is installed within the network. However, it must be noted that only the Network’s main site will have…

  • bbPress 2.0.1 Released – Fixes Anonymous Security Bug

    bbPress 2.0.1 Released – Fixes Anonymous Security Bug

    bbPress has released version 2.0.1 which is considered a maintenance release. However, if you have anonymous posting enabled, you’ll want to upgrade as soon as possible as this release addresses an issue where anonymous posters could potentially be able to edit topics and replies. If upgrading from 2.0, try upgrading through the dashboard as you…

  • The Aftermath Of The TimThumb Vulnerability

    The Aftermath Of The TimThumb Vulnerability

    Sucuri Security has a great post that begins to review the aftermath of the massive exploitation of the TimThumb image re sizer script. According to their calculations, about a million pages have been compromised by the script but when filtering down their results for the past thirty days, there were over 200,000 results. The exploitation…

  • WordPress Not The Choice For Multinational Search

    WordPress Not The Choice For Multinational Search

    Chris Liversidge of Search Engine Land gives an explanation as to why WordPress is not his platform of choice when it comes to multinational search. I was with him up until the point he discussed security where he states that WordPress is plagued by frequent security updates. This is not true. Security within WordPress has…

  • Four Common Sense Ways To Improve Security On Your WordPress Powered Site

    Four Common Sense Ways To Improve Security On Your WordPress Powered Site

    Generally common sense material listed in the article but it’s always good to remind people about these techniques. As far as I’m concerned, just being in the know and having the awareness of what’s going on is half the battle. On a final note, while website security can seem daunting and intimidating, it’s something that…

  • See If You’re Secure With The Timthumb Vulnerability Scanner

    See If You’re Secure With The Timthumb Vulnerability Scanner

    Not sure if any of the plugins or themes you have installed within your WP-Content directory contain the outdated version of TimThumb? Good news, there is a simple plugin that not only scans your content directory for the outdated version of the script, but also provides a link to quickly upgrade to the newer version.…

  • What’s The Best Way To Be Notified Of Theme And Plugin Updates?

    What’s The Best Way To Be Notified Of Theme And Plugin Updates?

    Joost de Valk who is pretty popular these days, especially after the release of his Yoast SEO Plugin tells us the story of how one of his sites was hacked because a theme containing the TimThumb vulnerability was not updated. If that were not interesting enough, Joost shares a statistic that doesn’t surprise me one…

  • Protecting WordPress Login Credentials From FireSheep

    Protecting WordPress Login Credentials From FireSheep

    There’s been a lot of hype around a new tool that was released not too long ago called FireSheep. In a nutshell, FireSheep is an extension for FireFox that monitors the airwaves of public Wi-Fi to sniff out login credentials to popular websites such as WordPress.com, self-hosted WordPress installations, Twitter, Facebook, and more. Once those…

  • GoDaddy Hacks Due To Old Software – Bad Passwords

    GoDaddy Hacks Due To Old Software – Bad Passwords

    Over the weekend, numerous users on GoDaddy shared webhosting accounts reported that their sites had been hacked with injected malware. Neowin.net was able to get a hold of GoDaddy’s security expert Todd Redfoot who explained what happened: GoDaddy reassures customers that the attack was via WordPress and not an attack on the GoDaddy servers themselves.…

  • Review Of The Limit Login Attempts Plugin

    Review Of The Limit Login Attempts Plugin

    Time and time again, when I would read an article about WordPress security or how to harden an install, I would see mentions of limiting the amount of times someone can try to log into an account. I’ve never put much thought into the idea but I’ve finally installed a plugin to help lessen the…

  • Does WordPress Need A Native Security Suite?

    Does WordPress Need A Native Security Suite?

    April has been a troubling time for a couple of well known web-hosts security wise. Ipstenu wrote a post on the various hacks that took place this month and I thought it was a well written piece that explains the variables that needed to happen for those events to occur. I’m not sure if she…

  • Sucks To Be A Network Solutions Customer Right Now

    Sucks To Be A Network Solutions Customer Right Now

    If I were operating Network Solutions right now, I’d be on my knees begging for mercy. Browsing through my feedreader today, I came across a post on ComputerWorld.com mentioning that customers hosted on Network Solutions.com have been attacked again. This time, it’s not targeted at WordPress users. Sucuri Security Labs has the most detailed information…

  • Who’s Right? Network Solutions Or Matt

    Who’s Right? Network Solutions Or Matt

    I haven’t had the time to write about much WordPress news lately but after reading the post published on the WordPress developer blog regarding Network Solutions, it might have been for the best. There have been a number of WordPress based sites hosted on Network Solutions that have had their databases compromised but overall, the…

  • WordPress 2.9.2 Released – Security Fix

    WordPress 2.9.2 Released – Security Fix

    WordPress 2.9.2 was released just a few minutes ago to address a security problem dealing with the Trash feature. When WordPress implemented the new feature they failed to change the permissions granted when the post is in the trash. This means that an unauthenticated user cannot see the post, however an authenticated user can no…