Update WordPress 2.6 Immediately

Published on Jul 14, 2008   //  Security
Off

Attention bloggers if you have manually installed WordPress then you should immediately upgrade to 2.6. There are lots of enhancements to 2.6.

For those who installed WordPress with Fantastico, Netenberg usually has the upgrade released a week or two later. We do post Fantastico updates on the blog so keep an eye open for that.

The Dog Days of Hackers

Published on Jun 9, 2008   //  Security

HackersAs we approach the end of another school year in a few weeks most of you are ready to soak up the sun, go on trips or take a dip in the water. While you are dreaming of paradise. We are a few weeks away from the time of year when site defacement goes through the roof. This year I hope to reduce the amount of defacement’s by providing a proactive approach to locking down your sites.

If you read this post and choose to ignore it and find your site defaced you will know why. The following guidelines should be done…

  1. Secure your Folders – Go through and lock down all your folders using the tips in this post.
  2. Secure your Files – Watch the video on how to set your files to a permission of 644.
  3. Upgrade your scripts – If you have any Open Source software upgrade it if you are using it, remove it if you are not using it.

Looking at last years tickets we had the following defacement issues…

  1. CMS and Blogs that were defaced because they left the .htaccess set to a permission of 777. If yours is set to 777 set it back to 644 now.
  2. Subdomain and addon domains where index.php files were replaced with index.html. The reason this happen is that the folders which had the subdomain or addon domain were set to 777. Set your folders back to 755 if they do not require to be set to 777.
  3. Some blog theme defacement happened because the themes folder and files are set to 777. If your done editing your themes then go through and set the permission of the files back to 644 and the folders back to 755.
  4. We had sites defaced because they used scripts that had not been updated or were not even using the scripts anymore. If your using a script then upgrade it now if you have scripts but not using it anymore then remove it.

Are we susceptible to hackers more then any other host? No definitely not! We use a lot of security measures to ensure your site and our servers remain as secure as possible. From the examples above you will see that the defacement’s were caused by end users leaving there own sites open or hackers to misuse it.

Take action and over the next few weeks. Go through your site and lock it down.

Update WordPress 2.5.1 Immediately

Published on Apr 25, 2008   //  Security

Attention bloggers if you have manually installed WordPress then you should immediately upgrade to 2.5.1. There are lots of bug fixes to 2.5.1.

Do not think about it or put it off. Your site is at risk so upgrade now.

For those who installed WordPress with Fantastico, Netenberg usually has the upgrade released a week or two later. We do post Fantastico updates on the blog so keep an eye open for that.

Update WordPress 2.5 Immediately

Published on Mar 29, 2008   //  Security

Attention bloggers if you have manually installed WordPress then you should immediately upgrade to 2.5. There are lots of bug fixes to 2.5 but the major difference you will notice is the new navigation and colour scheme of the admin area.

Do not think about it or put it off. Your site is at risk so upgrade now.

For those who installed WordPress with Fantastico,  Netenberg usually has the upgrade released a week or two later. We do post Fantastico updates on the blog so keep an eye open for that.

Horde Security Update

Published on Mar 6, 2008   //  Security
Off

Horde LogoIt was just released by cPanel that there is a major security hole in some versions of Horde webmail. We are going through and updating all our servers immediately to ensure that this hole is plugged. If you are on our shared servers there is nothing that you need to do, we have it under control.

 If you are running a dedicated server with horde on it, please update it immediately. If your not sure how to do that please open a ticket with support and they can help you with upgrading.

Update WordPress 2.3.3 Immediately

Published on Feb 5, 2008   //  Security

Attention bloggers if you have manually installed WordPress then you should immediately upgrade to 2.3.3. A security upgrade notice has been issued by WordPress in regards to this. 

Do not think about it or put it off. Your site is at risk so upgrade now.

For those who installed WordPress with Fantastico,  Netenberg usually has the upgrade released of a week or two later. We do post Fantastico updates on the blog so keep an eye open for that.

Page 3 of 512345