Headline »

Arthemia Premium Theme for WordPress

October 30, 2011 – 7:37 am | 2,773 views

Arthemia Premium Theme is a magazine-styled theme WordPress theme by ColorLabs that enables WordPress website owners to create a simple-yet-powerful content management system with an automatic thumbnail generation feature.Arthemia Premium Theme An elegant blend of a blog and a magazine. Arthemia Premium will convert your old-fashioned WordPress blog to an amazing and powerful front-end. If you are running an online magazine, Arthemia Premium is the one-stop ... Read More

Read the full story »
WordPress

WordPress is free open source web software. It is completely customizable and can be used to make a website for almost any purpose.

Plugin

Plugins are add-ons that can extend WordPress to do almost anything you can imagine. Most plugins are free to download and use.

Hosting

Many web hosting companies offer WordPress hosting. WordPress works best when it’s in a rich hosting environment with a WordPress friendly host.

Theme

WordPress themes are a collection of template files that can transform the look and function of a site into almost anything you want.

BuddyPress

BuddyPress is a free open source social networking software package that transforms WordPress into a social network platform.

Home » WordPress

Network Solutions Fixes WordPress Sites

Submitted by on April 14, 2010 – 3:08 pmNo Comment | 3 views

Network Solutions is reported to have deployed a fix for a configuration flaw that led to hundreds of WordPress blogs being compromised. The fix involved changing passwords for the WordPress databases hosted on its systems. It recommended that all customers using WordPress should log into their accounts to change their administrative passwords.

WordPress developers have made a statement that configuration parameters are the users’ responsibility, or the responsibility of automated installation scripts that might be run by a hosting company.

“A web host had a crappy server configuration that allowed people on the same box to read each others’ configuration files, and some members of the “security” press have tried to turn this into a “WordPress vulnerability” story.

WordPress, like all other web applications, must store database connection info in clear text. Encrypting credentials doesn’t matter because the keys have to be stored where the web server can read them in order to decrypt the data. If a malicious user has access to the file system — like they appeared to have in this case — it is trivial to obtain the keys and decrypt the information. When you leave the keys to the door in the lock, does it help to lock the door?

A properly configured web server will not allow users to access the files of another user, regardless of file permissions. The web server is the responsibility of the hosting provider. The methods for doing this (suexec, et al) have been around for 5+ years.”

From: http://wordpress.org/development/2010/04/file-permissions/

Share

Related posts:

  1. Network Solutions Report WordPress Compromised Sites Redirected
  2. Network Solutions Customer Websites Compromised Again
  3. ServerBuddy WordPress Plugin

Related posts brought to you by Yet Another Related Posts Plugin.

Leave a comment!

You must be logged in to post a comment.