Warning: Illegal string offset 'lang' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 353

Warning: Illegal string offset 'keywords' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 354

Warning: Illegal string offset 'description' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 356

Warning: Illegal string offset 'lang' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 353

Warning: Illegal string offset 'keywords' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 354

Warning: Illegal string offset 'description' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 356

Warning: Illegal string offset 'lang' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 353

Warning: Illegal string offset 'keywords' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 354

Warning: Illegal string offset 'description' in /home/educhalk/public_html/blog/wp-content/plugins/keyword-statistics/keyword-statistics.php on line 356

Archive

Posts Tagged ‘Security’

How to Create a Members-Only WordPress Blog & Enroll Thousands of Users

February 4th, 2012 1 comment

In the video above I demonstrate how to close a WordPress blog to the public and make it available only to members who have a username and password created for them by the blog administrator. The site I demonstrate has 49,500 members that I created and bulk uploaded in about an hour. I show the plugin I used for the bulk upload of users. I’ll create a follow-up video in a week or so demonstrating how I used Excel to create those users from a file with nothing but first and last names. If you have need for a private blog/website to share with a few people or tens of thousands of people, this should help get you started.

84 Blackboard Security Vulnerabilities — A “Research” Study?

November 10th, 2010 2 comments

A Dutch security company called Online 24 released a “research” study claiming to have found 84 security vulnerabilities in the Blackboard LMS. You can download the paper from Webwereld.

Research? Strikes me as simply a load of unsupported, extremely vague ramblings. Why would I say that? Maybe it’s due to their liberal use of “Imagine this” support in their “study”:

Imagine this situation:
“An attacker is able to gain access to files outside Blackboard’s document directory.
The attacker includes Blackboard’s access logs. These logs can be influenced by
the attacker, so exploitation would lead to a new highly dangerous vulnerability
that allows the attacker to execute custom commands on the Blackboard server.”

Categories: Uncategorized Tags: ,

WordPress Hacked — more than once — at Network Solutions

May 2nd, 2010 2 comments

Update: See comment by Network Solutions in comments area.

It seems Network Solutions and WordPress may not be playing well together and, as usual with tech geeks, they’re both pointing the finger at each other. I don’t have the time or interest to follow all the links on the net to figure this one out, but if you are hosting WP (or any other php app for that matter) on a network solutions, then you may want to do a little research on this one…here are a few links to get you started.

http://news.techworld.com/security/3221030/network-solutions-hacked-again-after-mass-wordpress-blogs-attack/

http://blog.networksolutions.com/2010/we-feel-your-pain-and-are-working-hard-to-fix-this/

Categories: WP Older Tags: ,

WordPress Security Vulnerability — Upgrade is a Must!

October 21st, 2009 No comments

There is a new WordPress security vulnerability that makes it very easy for anyone to launch a dos attack on your WordPress site. See the details here: http://seclists.org/fulldisclosure/2009/Oct/263

An upgraded version of WordPress was released today to address this problem; version 2.8.5.

This security vulnerability impacts ALL WordPress versions prior to today’s release, so if you are running WordPress an upgrade is a must.

See the following posts on this site for upgrade information:

Upgrade using auto-upgrade: http://educhalk.org/blog/how-to-upgrade-wordpress-27/

Upgrade using Cpanel: http://educhalk.org/blog/how-to-upgrade-wordpress-to-27-using-cpanel/

Categories: WP Older Tags: ,

WordPress Security Keys — No WP site should be without them

October 12th, 2009 1 comment

Note: The following is made available under GPL from http://codex.wordpress.org/GPL. It may be edited a little from its original form, but probably not a lot. There is no guarantee this information is accurate…use at your own risk.
—————————————————–
WordPress Security Keys

In WordPress 2.8 there are four  (4) security keys , AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, and NONCE_KEY that you can optionally add to your wp-config.php file to ensure better encryption of information stored in the user’s cookies. You can use the online generator to automatically generate random keys for your WordPress install…see the default wp-config-sample.php file for the url to the online generator.