ERIC SHEFFERMAN <DOT> COM

Blog-o-Goodness

Why I hate WordPress – Part 9,347

Seriously,

http://wordpress.org/news/2011/06/passwords-reset/

And to crap on top of it, I actually do have W3 Total Cache installed and did update it just the other day.

However, it only updated “because it’s there” — I don’t actually use it. I just never happened to delete it after I deactivated it. I guess I was hoping I’d figure out how to enable something useful like cacheing without it destroying the usability of my site.

So now I’ve had a “cleverly disguised backdoor” installed on my web site (which can thus access ALL my domains) for a few days.

Of course, I don’t even know what to look for regarding this exploit.

How could I have protected myself from this? Checking the WordPress.org news minute by minute for their latest security issues? Can I afford to ever sleep? Or maybe I just need to read through every single line of code for every single theme and plugin? Oh — but I probably have to scan the entire WordPress core as well. How long could that take?

Oh – the only solution is to buy VaultPress for ALL my domains… That makes sense. At least then I’ll be making somebody else’s monthly Corvette payment.

That’s the problem I keep running into with WordPress — it’s a bunch of very pretty cards and when you’re done… you’ve built a house of cards.

From my admin page — I gave up on even having this plugin activated in January.

Share

WordPress – Be Ready To Be Hacked Again

Ahh… the dreaded

3.0.4 Important Security Update

…a very important update to apply to your sites as soon as possible because it fixes a core security bug in our HTML sanitation library, called KSES. I would rate this release as “critical.”

Yeah. What that says to me is, “A hacker has already looked at the vulnerabilities in 3.0.3 and written a script to exploit it and deployed it on the websites he/she has already hacked so that it can go out and get access to even more web servers by simply crawling the web looking for WordPress installations that haven’t been updated yet.”

Read the rest of this entry »

Share

Getting WordPress Multisite to Work Part 4

New way to tackle this… Last night I tried to install WordPress MU instead of WordPress 3 Beta.

After all, I don’t particularly care about the exciting new features — I just want to run multiple domain names off a single WordPress install so I only have to keep one WordPress install updated and secure instead of 10 or 20 or 50.

For all the stuff I’ve seen about installing MU, I thought it was going to be difficult. It wasn’t, but…

Read the rest of this entry »

Share

Keep Up With
Eric Shefferman

Via RSS
    

Via Email Updates
Name:
Email:

Archives

The following link is not for people: I do not like it, Sam I Am.