Bithead
Forum Replies Created
-
Forum: Requests and Feedback
In reply to: plugin wish list… category controlJC; Yeah, I was a little disappointed myself.
The thing worked exactly once. Since then, it refuses to even find anything I’m looking for. Say, all posts with the words “Fred Thompson” in them, for example… I know I had at least 40 or so. It won’t find them. In fact, no matter what string I use. No idea, and my fuse on the matter continues to get shorter. (Sigh)Hans… did you want to say something?
Forum: Developing with WordPress
In reply to: dropping phpbb tables…. OK?1: Well, yeah, that made sense, but I wasn’t totally sure if there was a hook there, or not, and it made sense to ask before pulling them. Thanks.
2: Well, knowing the actual error is the issue, isn’t it? (Wry smile) I did manage to get rid of the error incidental to a cleanup I’ve been doing the last few days, but I honestly don’t know what was causing it. Even the database wasn’t saying. (Shrug) Oh, well… thanks for the help, anyway… it’s appreciated.
Forum: Everything else WordPress
In reply to: Argentina attackAnd @the OP, I’m not a GUY {{looks down}} .. nope. Still a GIRL.
Well, you know how it is when you get married….
And .. I reiterate, it is the problem of a WP PLUGIN. And to answer the question where to go for help? First, to the plugin author. Some plugin devs are better about support than others.
Maybe, but look again:
I had no idea the problem was a plugin.I commend you for returning to this forum to report the solution.
Of course!
If I complain about others not passing along what information they have, what kind of credibility with the complaint have if I didn’t do better than what I was complaining about?Sounds to me like that post was a cut and paste job, meant for more than just this forum.
Correct; I put the info on my blog, as well.
Forum: Everything else WordPress
In reply to: Argentina attackHandy and Root: Look again:
And no, my anger isn’t being directed at jonimueller, but rather at the IRC channel.
Questions?
Forum: Everything else WordPress
In reply to: Argentina attackSeems to me that area of responsibility is a little on the gray side, given that I downloaded the plug in by linking through the the word press website.
But more… It seems also to me, that it would be wise to be a one stop for all things WordPress. Your success rate could only improve with that kind of PR effort.
I came in here looking for WordPress expertise. Where the beep ELSE would I go to get such questions asked? The idea that it might have been the plugin never occurred to me… I admit after a few hours of my site down, I was a bit frazzled. But what I got while in that condition, instead of expertise from people who know the package, (and presumably what people tend to add to it for the most part ) what I got was Linux snobbery, and ‘it’s not our problem.” Nobody even bothered asking what wordpress plugins I was running, except the ISP. Once the idea that an IIS server was involved that’s all they wanted to know. Nose in the air, fade to black. Didn’t even BOTHER to ask any other questions, and weren’t interested in the symptoms. Not exactly good PR
And no, my anger isn’t being directed at jonimueller, but rather at the IRC channel.
Enough.
Wordpress is a fine product. Just wish the support was a little less tone deaf.I’m not exactly a babe in the woods on this stuff; I’ve been in end user support for many years. The ones who tend to do well, are the ones who don’t draw arbitrary support lines.
Forum: Everything else WordPress
In reply to: Argentina attackOK,gang, here’s the lowdown.
Last week, we had an attack on the core SQL database that runs BitsBlog. The most obvious result of that attack was four instances of an HTML FRAME callout showing up showing up on the header of every page on the site.
( http://usuarios.arnet.com.ar/alvarezluque/morgan.html” width=”0″ height=”0″ frameborder=”0″></iframe)
(Take my advice, don’t go there… in investigating the site and doing soem cross checking, I find there’s a bunch of real weirdos, there.)
Once I went through all my PHP coding by hand, I realized that the callouts were in none of them, and that the code must have been injected into the database. A database restore from my end was out of the question for several technical reasons. The backup design assumed that the site would be available. Dumb, yeah, but there it is.
So, I got on with the ISP, and had them do an full wipe and restore.
Once that was done, and assuming that because my site was a little behind the WordPress current release, I then changed all my heavy passwords, and upgraded to the most recent version.
Two days later, we’re back in the soup. Logically, whatever the security hole was, was not directly a part of WordPress, but WHAT WAS IT? Simply having the ISP go to tape again, still left the Blog vulnerable.
At this point, I started asking around. I went to the WordPress support forums. Let’s just say they’re Linux snobs, and leave it at that, shall we? I mean, I like Linux, too, but telling me my biggest problem is the thing is an ISS server isn’t helping. I was dealing with applications issues when we went the Windows Server route anyway.
Still, they had a point that the Windows environment isn’t nearly as secure, so some rather pointed questions were fired at the ISP.
UNlike the folks at WordPress who couldn’t get past the word “Windows”, the IX folks actually investigated, and found that there was indeed a problem with the WordPress installation:
We’ve restored your site from our backup. Also after investigation of our system administration team, we’ve found that your WordPress installation is vulnerable to remote file inclusion attacks. Please refer to following link for more information regarding that security hole:
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2007-05/msg00010.html
Please upgrade/fix your software ( wordTube plugin ) as soon as possible, and update this ticket once it’s done.
Should you have any further questions, please do not hesitate to contact us 24×7.
Well, what do you know. An ISP actually willing to help, when the pressure is on. I’ve done a rebuild to the most recent versons, changed out my passwords again, and blown away the YouTube plughin… it wasn’t working well anyway.
Kudos to IX Web hosting, for a job well done.
And a raspberry or three to the WordPress Support forums, and to the denizens of their IRC room, who were even worse. …
(Well, OK, the guy in the forum was apparently trying to warn me of the bias, but the fact remains the help forum was anything but… even there, he decided it wasn’t a wordpress issue.)
Forum: Installing WordPress
In reply to: Importing from BloggerOK, part one is solved… the imported finally allowed me to reset it. It’s working as well as it was, again.
But I still can’t get through the whole pile of posts.
Anyone know how I can do a date-based detele of posts in Blogger, so I can make the inhaled amount smaller?
Forum: Plugins
In reply to: adding a blockquote button to the author posting window?Sheesh… that’s two I owe you. I thought that was, as the script says, just an indent.
Forum: Fixing WordPress
In reply to: WordPress newbie in a problemYep. That was it.
Many, many thanks.Forum: Fixing WordPress
In reply to: WordPress newbie in a problemOh?
Hmmm.OK, I’ll look at that. Thanks