April 2008 Most Popular Articles

Below you will find the most popular articles of the past month. Check them out to make sure you have not missed any.


Partner: MakeUseOf.com Amazing Websites and Tools you Never Knew About

Comments Off

April 2008 Most Popular Articles

Below you will find the most popular articles of the past month. Check them out to make sure you have not missed any.


Partner: MakeUseOf.com Amazing Websites and Tools you Never Knew About

Comments Off

Make Sure Your WordPress is Not Hacked

Lately there there seems to be a hacking spree around old versions of WordPress. Most of the times the hacker will edit your theme files to insert spam links. One of my older and non-active blogs got that problem, and I had several friends complaining to me about it as well when chatting over IM.

I would therefore recommend that all of you run a quick check on your WordPress to make sure it has not being compromised.

How do I find if I have been hacked?

The easiest way to identify the spam links is to open your website on a browser and take a look at the source code. Pay particular attention to the header and footer of your HTML, and check if they are links there that were not supposed to be (usually they are related to pharmacy, drugs, credit cards and related).

page source spam links

If you use Firefox you can also click on “Tools,” then “Page Info,” and then “Links.” This window will show all the outgoing links from the current web page that you are visiting.

firefox page info

Finally, you should also examine all your theme files and your WordPress installation for any file or piece of code that looks suspicious.

How do I fix the problem?

Most of the blogs that get hacked are older versions of WordPress that still have several security bugs open, so the first line of defense that you have is to stay updated with the newer versions. If you have been procrastinating your update to WordPress 2.5 make sure to check the Automatic Upgrade plugin, it makes the process really a piece of cake.

Secondly, you should also secure your WP-Admin folder by allowing access only to certain IP addresses. You can do that by creating a .htaccess file (a simple text file named that way) and by dropping it inside your WP-Admin folder with the code found on the article 3 Must Apply Security Tips for WordPress.

Thirdly, you should also disable the navigation of directories on your whole website, so that people can not view what plugins you are using or other sensitive data. You can do this easily by adding the following line to the .htaccess file located on your root directory:

Options -Indexes

Finally, if for some reason you can’t upgrade your WordPress or secure the access to the WP-Admin folder only to certain IPs, you can still delete your theme-editor.php file from the WP-Admin folder. This solution is far from the optimal, but it should help in protecting your blog from people trying to add spam links to your theme files.

Ah, and don’t forget to change your passwords regularly as well!


Partner: MakeUseOf.com Amazing Websites and Tools you Never Knew About

Comments Off

Public Service Announcement: Version Six Launched

It’s finally here! And not I’m not only talking about my redesign; but I have also updated my blog to now run WordPress 2.5! This has been a while coming - even though I only launched V5 a month or so ago, I was never happy with it and this design is thus an attempt to improve on all my previous work.

Suffice to say, I’ve never been as perfectionistic about a design before and I truly believe that you will appreciate the small details that I have included in the design. I’ve pretty much spent the whole day finishing this up and I now need a bit of a break (read: red wine, chocolate, movies and some time with my fiancee).

That means, I will only be writing a post-op about all of my thoughts on the redesign in the morning. Until then: sit back and admire the view! )

(Image by ~xnapflyice)


Comments Off

One less thing to worry about…

As with the online apps that I use, my one criteria for anything that I pay for / use on a daily basis, is that needs to be one less thing that I worry about. If there’s one thing that I hate, it’s when I need to do someone else’s job for them (since they are ineffective), whilst still paying them to do it.

I did a lecture on the attention economy, blogging and & legal issues related to these, at a conference called Nomadic Marketing today and the topic of web hosting service providers came up. Through the discussion (and sharing of frustrations by the delegates of the course), I got thinking about the total lack of issues I have my web host - Fused Network. Since I’ve switched over to their servers last year (they sponsor my hosting), I’ve not had one problem that hasn’t been dealt with in a matter of a few hours (it is inevitable that problems will arise - the important thing is how quickly and efficiently problems are sorted out).

I know that not every web hosting experience (that you might tell me about) will have been as positive as mine has been with Fused Network - but why shouldn’t it have been? Why should you settle for second best when you’re paying for a service? In my opinion, everyone should have access to top-notch service when they’re paying a premium price…

Just to throw a further spanner in the works - Fused Network is actually willing to handle your migration from your current web server all by themselves if you’re willing to switch over to their service (they did this for me)…

Any thoughts?


Comments Off