<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rich Sharples&#039; Blog &#187; wordpress</title>
	<atom:link href="http://blog.softwhere.org/tag/wordpress/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.softwhere.org</link>
	<description>Musings on the world of software from the sharp end of the long tail</description>
	<lastBuildDate>Thu, 10 Jun 2010 13:26:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>WordPress Hacked</title>
		<link>http://blog.softwhere.org/archives/758</link>
		<comments>http://blog.softwhere.org/archives/758#comments</comments>
		<pubDate>Wed, 25 Feb 2009 02:43:22 +0000</pubDate>
		<dc:creator>sharps</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.softwhere.org/?p=758</guid>
		<description><![CDATA[I noticed earlier today that this blog had disappeared from Google&#8217;s search index. I only check my stats. infrequently so don&#8217;t know when it happened but I quickly confirmed with : And after a bit of Googling I arrived at the conclusion that my blog had been purposely removed from the Google Index due to [...]]]></description>
			<content:encoded><![CDATA[<p>I noticed earlier today that this blog had disappeared from Google&#8217;s search index. I only check my stats. infrequently so don&#8217;t know when it happened but I quickly confirmed with :</p>
<p><a rel="attachment wp-att-755" href="http://blog.softwhere.org/?attachment_id=755"><img class="alignnone size-full wp-image-755" title="screenshot1" src="http://blog.softwhere.org/wp-content/uploads/2009/02/screenshot1.png" alt="screenshot1" width="498" height="233" /></a></p>
<p>And after a bit of Googling I arrived at the conclusion that my blog had been purposely removed from the Google Index due to a violation of <a href="http://www.google.com/support/webmasters/bin/answer.py?answer=35769&amp;hl=en">Google&#8217;s Quality Guidelines</a> and <a href="https://www.google.com/webmasters/tools">Google&#8217;s WebMaster Tools</a> confirmed this with the explanation that my site had some dubious hidden links. Viewing the source showed a block of hidden links pointing to some shity web-sites advertising all the usual shity stuff that no-one gives a shit about. I trawled through the Word Press templates and found some suspect base64 encoded script in the footer which I deleted and quickly confirmed was the culprit.</p>
<p>So that was a waste of 10 mins. or so and I&#8217;ve wasted at least another hour researching Word Press security and analysing my site to make sure nothing else was compromised; then patching things up. To save you some time I&#8217;ve included some quick things you can do to make your WordPress Installation less hackable :</p>
<p>1. Give your admin user a really tough password or better yet drop into MySQL and delete the admin user completely (assuming you have another admin user already)</p>
<p>2. Run your site through <a href="http://blogsecurity.net/wordpress/tools/wp-scanner">wp-scanner</a> &#8211; it will highlight common potential exploits.</p>
<p>3. Make sure WordPress is up to date. Plugins too.</p>
<p>4. Change the default MySQL table pre-fix (remember to backup first).</p>
<p>I still don&#8217;t know how / when my site was hacked or by whom &#8211; I really can&#8217;t be bothered to trawl through the Apache logs to find out and really don&#8217;t want to give the cock-sucking spam hacking time-vampires any more of my time.</p>
<p>It&#8217;s interesting to note that this particular exploit is really pointless &#8211; if Google pulls the hacked site from their Index &#8211; it serves no purpose.</p>
<p>Hope this helps, leave a comment if there are any other good tips for securing WordPress.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fblog.softwhere.org%2Farchives%2F758&amp;linkname=WordPress%20Hacked"><img src="http://blog.softwhere.org/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.softwhere.org/archives/758/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Hello blogs.sun.com ?</title>
		<link>http://blog.softwhere.org/archives/24</link>
		<comments>http://blog.softwhere.org/archives/24#comments</comments>
		<pubDate>Thu, 28 Feb 2008 16:34:39 +0000</pubDate>
		<dc:creator>sharps</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[sun]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.softwhere.org/?p=24</guid>
		<description><![CDATA[If all went well (and Linda pulled the right levers) this entry should be included on the front page of blogs.sun.com. As I mentioned &#8211; after 4 happy years, I&#8217;ve deprecated my blog at Sun in favour of my own hosted WordPress blog.]]></description>
			<content:encoded><![CDATA[<p>If all went well (and <a href="http://blogs.sun.com/lskrocki/">Linda</a> pulled the right levers) this entry should be included on the front page of <a href="http://blogs.sun.com/">blogs.sun.com</a>. <a href="http://blogs.sun.com/sharps/entry/301_moved_permanently">As I mentioned</a> &#8211; after 4 happy years, I&#8217;ve deprecated my blog at Sun in favour of my own <a href="http://blog.softwhere.org/">hosted WordPress blog</a>.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fblog.softwhere.org%2Farchives%2F24&amp;linkname=Hello%20blogs.sun.com%20%3F"><img src="http://blog.softwhere.org/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.softwhere.org/archives/24/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ecto Test</title>
		<link>http://blog.softwhere.org/archives/12</link>
		<comments>http://blog.softwhere.org/archives/12#comments</comments>
		<pubDate>Thu, 28 Feb 2008 04:00:46 +0000</pubDate>
		<dc:creator>sharps</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[ecto]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.softwhere.org/blog/?p=12</guid>
		<description><![CDATA[Every Mac / Blogger I know raves about Ecto &#8211; I&#8217;m surprised it&#8217;s taken me so long to give it a try. There&#8217;s very little wrong with the WordPress native editor but sometimes (I know it&#8217;s hard to believe) you&#8217;re not online when you have the inspiration. I&#8217;ll try it for a week and if [...]]]></description>
			<content:encoded><![CDATA[<p>Every Mac / Blogger I know raves about <a href="http://infinite-sushi.com/software/ecto">Ecto</a> &#8211; I&#8217;m surprised it&#8217;s taken me so long to give it a try. There&#8217;s very little wrong with the WordPress native editor but sometimes (I know it&#8217;s hard to believe) you&#8217;re not online when you have the inspiration.</p>
<p>I&#8217;ll try it for a week and if all works as expected &#8211; I&#8217;d be happy to shell out twenty buck or so (which IMO is a reasonable price for a piece of software like this.)</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fblog.softwhere.org%2Farchives%2F12&amp;linkname=Ecto%20Test"><img src="http://blog.softwhere.org/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.softwhere.org/archives/12/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hello World Part II</title>
		<link>http://blog.softwhere.org/archives/10</link>
		<comments>http://blog.softwhere.org/archives/10#comments</comments>
		<pubDate>Thu, 28 Feb 2008 04:00:08 +0000</pubDate>
		<dc:creator>sharps</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[roller]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.softwhere.org/blog/?p=10</guid>
		<description><![CDATA[OK, looks like everything is working. This is the new home of my blog. My previous blog was hosted by my employer (Sun Microsystems) and used Roller. At some point I&#8217;ll post in some detail the differences between Roller and WordPress.]]></description>
			<content:encoded><![CDATA[<p>OK, looks like everything is working. This is the new home of my blog. My <a href="http://blogs.sun.com/sharps/">previous blog</a> was hosted by my employer (<a href="http://www.sun.com">Sun Microsystems</a>) and used <a href="http://rollerweblogger.org/project/">Roller</a>. At some point I&#8217;ll post in some detail the differences between Roller and WordPress.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fblog.softwhere.org%2Farchives%2F10&amp;linkname=Hello%20World%20Part%20II"><img src="http://blog.softwhere.org/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.softwhere.org/archives/10/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
