Archives

Support this Site!

You may have noticed that there's very little third-party advertising on this site. I'd like to keep it that way. Here's how you can help:

  • Buy my books. They're available at great prices on Amazon.com.
  • Check out my training videos on Lynda.com. It's a great source for "all you can eat" training.
  • Donate a few dollars. It'll help cover my hosting costs and give you a chance to tell me what you want to see covered here.
  • Comment on blog posts. You can help get a discussion going that can benefit others, making the site more valuable for everyone.

WordPress Security Alert!

Dr Dave sends out the alarm; I spread the word.

Dr Dave, developer of the must-have spam prevention tool, Spam Karma, sent out the following alert message to all Spam Karma users as an announcement in the Spam Karma administration panel:

MAJOR SECURITY ANNOUNCEMENT
Affecting all WP users (this is not specifically a Spam Karma problem). Please immediately disable ‘guest user registration’ on your blog if it’s enabled and advise all your friends to do so (details here). I cannot give too much technical details as it would further endanger vulnerable Wordpress users, but trust me this is not a joke.

What Dr Dave means is to follow these instructions:

  1. Log in to your WordPress blog and display the Dashboard.
  2. Click Options to display the General Options administration panel.
  3. Turn OFF the Anyone can register check box under Membership.
    Membership Options
  4. Click the Update Options button at the bottom of the window.

On his site, Dr Dave also recommends that if this option had been turned on, you should view your Users list and delete any user you’re not sure about.

Dr Dave did not provide any details for this security problem. He’s worried that it’ll spread the word about how a WordPress system might be compromised.

Our advice: just do it. I’m sure more details (and probably a fix) will come soon.

WordPress, security, problem

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>