Archive for the 'WordPress' Category

Wordpress 2.3.3 is not safe anymore - upgrade NOW! (link injection vulnerability)

Tuesday, June 3rd, 2008

A few days ago I was recommending to people not to upgrade to version 2.5 of WordPress, because at the time I believed WP 2.3.3 to be as stable and safe as the new 2.5 series. Besides, I liked (and still like) the old, ‘classic’, 2.3.x admin interface much more…

OK, I must take my words back and confirm that WordPress 2.3.3, the last stable release before the new WordPress 2.5 branch was released, is not safe anymore, and you can become a victim of the link injection hack (vulnerability).

What happened?

In one of the blogs, which I support (luckily, not my personal blog, which I have upgraded to 2.5/2.5.1 long ago), I have found ‘hidden’ links (code: <u style="display: none">[ bunch of spam links inserted here ]</u>) in one of the regular posts there.

(more…)

WordPress 2.5: Give me back part of the 2.3 Classic interface, please!

Saturday, April 5th, 2008

Yesterday I made an upgrade from WP 2.3.3 to WP 2.5 (with full backup of MySQL database and files before that, of course). Looks like everything works fine:)

First, about the good things in WP 2.5:

  1. Editing tags is now built-in feature, which is great;
  2. A better visual editor (Rich Text Editor) — I don’t use it, but they claim it’s better;
  3. Fixed an old bug, which didn’t allow you to specify a directory for uploading files, which is one or more levels higher than the current WP directory (I just had to dig in deep, just to find that you have to fill correctly both fields in Settings → Misc ["Store uploads in this folder..." & "Full URL path to files (optional)..."], or this won’t work);
  4. A better Image Uploader;
  5. Possibility to automatically update plugins, with just one click (nice!).

There a lot of others, but these I noticed at first glance.

And now some rant from my part:

(more…)

WordPress plugin to show Moon Phases

Thursday, October 11th, 2007

Yovko showed me, from where I can get a little plugin for WordPress, which shows the Moon phases in the sidebar of the blog.

MoonPhase Plugin for WordPress

I’ll test it one of these days…

UPDATE: With WordPress 2.2.1: plugin works!:-) With WP 2.3 I still don’t know, I’ll know soon, after I upgrade my current WordPress version…

How to prevent Google from indexing WordPress RSS feeds

Tuesday, September 18th, 2007

I love to optimize my WordPress-based blog. The only problem is, I rarely have enough time to do it — and still, there are some small improvements, which may take less than 5 minutes of your time, and yet have a tangible impact on your overall blog optimization.

One of these things is how we can prevent Google (and other search engines) from indexing (searching) the WordPress RSS feeds.

The next few lines will be dedicated to this problem (and how we can solve it).

Where to start?

I remember that some time ago I was checking which pages of optimiced.com are indexed in Google.

I was puzzled by the fact that, beside the blog posts, I have found a lot of RSS feeds, which were also indexed.

Why you do not need Google to index/spider the RSS feeds?

First of all, the indexed (searched) content is duplicated - the last 10 posts or the last comments, available via RSS, can be read on the blog itself. Second point, RSS is meant to be used with an RSS reader, not to be read in the browser window (text and images won’t be formatted, for example). Last, but not least, who would like after a performed internet search to land on a un-formatted RSS page with comments, for example, instead of on the blog post itself, to which the comments are related? And this happened to me, and more than once…

(Example: you can use this link to subscribe to the RSS feed of my blog, or just to check the ten last blog posts from optimiced in RSS format.)

Can we prevent this from happening?

I searched the Internet for some time, until finally I dropped on the WordPress Support forum, where the solution was found, and the thread itself, titled “Prevent indexing of feed pages”, was marked as ‘resolved’.

Here’s the way to do it - you must use a robots.txt file.

What is robots.txt?

robots.txt graphicAs the name itself suggests, robots.txt* is a text file in the standard text format (.TXT), intended to use by robots:-)

But not all robots, of course (for example, Roomba doesn’t count;-), but only by the search machines (spiders), like Google, Live Search (until recently MSN Search), Yahoo!, Alta Vista and all other search (ro)bots.

(more…)

Mike Davidson switches from Movable Type to WordPress

Monday, September 10th, 2007

Yep, that’s right.

That Mike Davidson has recently switched from MT to WP.

I see more and more bloggers switching over to WordPress.

A few years ago Movable Type didn’t have rivals. Now things are changing.

Movable Type was free. Then it became paid, unless you wanted to use a free (partially limited in its use) copy.

Then WordPress appeared on the horizon, it was open source, it was free and it became one of the fastest developing blog platforms on the market.

Now and then, I see people switching over from Movable Type, from Blogger/Blogspot and from other blog engines to WordPress.

Now Movable Type released a brand new free version (4.0), open source, too… will this be enough to keep it on par with growing WordPress?

To be frank, I doubt it…

It’s interesting to see how things change so fast on the Internet. And for now, I am a (still) happy user of WordPress… actually, I use it since the creation of my blog optimiced in January this year:-)

Finally (but don’t take this seriously, please, this is just a joke, and an excuse for me to master a bit more Adobe Fireworks;-), here’s a graphical representation of what happens to Movable Type currently:

WordPress Eats Movable Type :-) (illustration by Michel)

WordPress 2.1.2… finally on my blog as well:-)

Saturday, March 31st, 2007

…or, in other words, the latest and greatest WordPress (namely, version 2.1.2), now works on my website as well:-)

All plugins are OK - the few I use include LightBox 0.6.4beta, Google Sitemap 3.0b6, WP-Shortstat 1.12a.

WordPress powers optimiced.com from January 1st, 2007. I like a lot WP from the moment I started to use it.

The first version I’ve installed was 2.0.5, and then WP 2.0.6 was out, then 2.0.7, 2.0.9, 2.1 “Ella”, 2.1.1… and only then I decided that it’s time to upgrade. I did.

But on the next day, after I have successfully made backup of the database and of the files and upgraded to 2.1.1, a serious possible security problem was discovered in 2.1.1 and news was spread we should upgrade as soon as possible to 2.1.2.

Well, I got lazy.

I used 2.1.1 for a few weeks and only tonight have decided that the right moment has come, and after a new series of backups and strict adherence to the instructions, I am already with 2.1.2 up and running :-) Same applies to the Bulgarian version, of course.

After my brilliant upgrades I celebrated with a cup of healthy tea and one beer from the fridge:)

After that I read some blogs (designers’ & developers’ blogs mostly)…

…and now I am sleepy as hell, so good night! More to come soon;-)

Hello world! (finally;-)

Monday, January 1st, 2007

Welcome to WordPress. This is your first post. Edit or delete it, then start blogging!

It’s 11:40 pm on January 1st, 2007.

For 23 hours and 40 minutes, Bulgaria is in the EU.

For the first time in the last few weeks, I have installed a WordPress blog/website, and I do not intend to delete it ;-)

It’s a step forward - for me (and maybe not so big a step for humanity;-)

(more…)