Posts Tagged ‘CMS’

7 Widespread Admin Errors in CMS

Published: Sep 21, 2010
Tags: , , , ,

CMS (Short for Content Management System) is often a extremely common piece of software for running blogs, personal sites, corporate internet sites and any other kinds of internet sites you’ll be able to believe of. CMS are reasonably straightforward to use and this can be a single crucial explanation why they became so well-known.

Nevertheless, simple to make use of and secure are definitely not synonyms when CMS are concerned. Although most in the leading CMS will not demand considerably effort to make them quite safe, it can be not uncommon to see CMS with out the proper protection. Such CMS are easy targets for hackers.

When a CMS gets hacked, generally the cause for this just isn’t that the CMS itself is insecure but that hackers took advantage of some common admin mistakes. The list of admin blunders is pretty long but not surprisingly, the number of probably the most prevalent ones is usually a single digit. Here are some of these errors you will need to know and never do inside the CMS you administer:

1. Default passwords

A single in the 1st things hackers examine when they plan to attack is for “easy passwords”. Default passwords (i.e. the passwords that come together with the set up) are straightforward to locate. It truly is true that numerous CMS never come having a default password or even if they do, the set up procedure will make you change your password before it is possible to use the application but in case your CMS comes with a default password, make sure that you alter it. Also, make sure that you just modify the password for the database too since the database is also a target for hackers.

2. Blank passwords

In addition to default passwords, clean passwords are another common mistake admins make (if the CMS enables them since fortunately a lot of CMS don’t make it possible for clean passwords). It’s not needed to state how risky clean passwords are – they call for no guessing at all and hacking a CMS having a blank password is simply a piece of cake for a beginner. All it takes is to guess the username – if the username is “admin”, “administrator” or some thing comparable, then breaking into your CMS is a matter of seconds.

As with default passwords, the risk is higher when the admin account is affected but there is no cause to let non-admin customers, who have access to the database to have empty passwords. This really is why it makes sense to force strict rules for passwords for everybody.

3. No patches put in

It truly is correct that installing tens of patches a day is boring but when you do not watch out for (at least) the critical updates and do not set up them in a timely manner, that is an invitation to hackers. Hackers monitor reports for new vulnerabilities and depend on the truth that the administrator won’t install the patches quickly.

In fact, several hacks occur just within the time period between a vulnerability is reported as well as the admin installs the patch. This really is why it can be critical to set up patches fast and manually. Automatic set up is simpler but as strange as it may sound, it could make issues worse – i.e. break your CMS. You do will need to set up patches manually, so that you know exactly what has been installed.

4. PHP register_globals on

If your CMS is written in PHP and also you are using PHP 5 or earlier, one far more thing you need to check right away is if register_globals is on. If register_globals is on, you will need to turn it off instantly due to the fact when it really is on, you’ll find millions of methods in which this might be misused to hack your web site. For quite a few CMS this variable is by default off but you can’t rely on that – you’ll want to verify it manually.

From the rare case when you have plugins or other functionality that can’t work when register_globals is off, it truly is a no brainer what to complete – just get rid of these plugins/functionality since this is less of a sacrifice than having register_globals on.

5. Insecure internet hosting


Insecure web hosting is a single with the greatest danger for the security of your CMS. Vulnerabilities within the operating system and also the other software which is installed on your word wide web host are also among the favorite targets of hackers plus the worst is that if your word wide web host is insecure, there isn’t much you as an admin of one’s CMS can do to counteract it. You cannot fix the holes in the security of one’s net hosting provider as well as the only issue you may do is escape to a far better net host.

6. Generous person privileges

You’ll find hardly any admins (in their correct mind), who will give admin privileges to ordinary users but there aren’t that few admins, who are really generous when user privileges are concerned. One particular of probably the most critical security guidelines could be the least privilege rule – i.e. give customers access only to those parts of your internet site they truly need to have to have in order to complete their jobs. A single of the risks of generous person privileges is that the credentials might be utilized for internal hacking, which will not be a smaller issue than external hack attacks.

7. Insecure plugins

Hackers may well not enter via the front door within your CMS but when the other doors are open, they do not need to have backdoors (i.e. malware) to gain entry to your web page. Practically any CMS relies on plugins to offer additional features and this can be the charm of CMS due to the fact you get a base set up and also you have the freedom to add only the features you will need but this freedom is also a security risk.

As a rule, plugins are developed by third-parties and it is not quite clear if they’re rigorously tested. Incredibly typically plugins have safety holes in them and hackers are happy to take benefit of any such security holes. The wisest it is possible to do is remove any plugins with known protection issues. It really is considerably greater not to possess a specific features than to put the safety of one’s whole website at danger.

Rocky Rasonable

A filipino Senior PHP Programmer, Web Developer and Webmaster based in Davao, Philippines. Expert in Joomla, WordPress, Soholaunch, Oscommerce, Drupal, Social Media Sites, and etc.

More Posts - Website

 

Posts Tagged ‘CMS’

7 Widespread Admin Errors in CMS

Published: Sep 21, 2010
Tags: , , , ,

Free Website Promotion…Why Not?

Can you ever avail of free website promotion? Is that even feasible?

Of course yes! Nowadays, your baby website can amass huge traffic in no time thanks to free website promotion.

How does this free website promotion go anyway? What are things to be done?

1. Enlist your website.

Look for the hottest Internet directories and enlist your site there. This is the easiest and most effective free website promotion tactic. Start with this step and the rest of the good things will follow.

Just don’t forget to prep your website and make it all spruced up for a higher chance to get accepted in your directory of choice.

2. Know your forums.

One reason why forums are created is for free website promotion for everyone. Log in, post actively, let them know about your site in every post and you attract instant visitors right there.

3. Write a press release.

Release your writing prowess and start up a press release that advertises your site! This is a free website promotion tactic that you can do anytime. Type a brief paragraph or two and email it to your friends, colleagues, internet e-zines, newspapers and other media and massive traffic will come to you pronto!

4. Be friendly online.

Free website promotion means you need to be friendly to other webmasters. Why, you ask? So they can link you immediately! Establish contacts and never tire of link requests and exchanges.

5. Write an article.

Say, your website is about your travel agency. Write an article about the perks of traveling or the hottest travel spots in the world. On the concluding paragraph, mention your website in passing. This article works as an advertorial and doubles as a free website promotion approach.

6. Just let the whole world know about your site.

What is free website promotion without the word of mouth? Insert your website, its URL and features in daily conversations and let the good news spread from one mouth to another!

7. Make a banner ad.

Make a banner ad for your site and ask another webmaster to do the same for his site. Then swap!

8. Take up a free website promotion course online.

Yes, there are free website promotion tutorials. But don’t you know that you can actually take a free website promotion course that can help you out further? Part of the free website promotion program is signing up for newsletters.

When you make a website, you need not pay anything to promote it. You just read it — there is such a thing as free website promotion!

Rocky Rasonable

A filipino Senior PHP Programmer, Web Developer and Webmaster based in Davao, Philippines. Expert in Joomla, WordPress, Soholaunch, Oscommerce, Drupal, Social Media Sites, and etc.

More Posts - Website

 

Posts Tagged ‘CMS’

7 Widespread Admin Errors in CMS

Published: Sep 21, 2010
Tags: , , , ,

Compiled from http://wp123.info

WordPress is great! It’s no doubt. But unfortunately it still doesn’t have many quite necessary features. One of them is the ability to change wp-admin folder name, which is the admin directory as you probably already now. After searching for several hours on the internet without any success I started thinking of ways how to change my wordpress admin directory name. In this small tutorial I’ll show how to do it. Before starting the tutorial I have to say that this is rather complicated way and there may occurred some bugs. Anyway I have tested it and didn’t found any. So let’s start.

All we have to do is to search “wp-admin” in all wordpress files and change it to what we need to use as a admin directory name. Let’s name it for example “profile”. There are over 50 files to change. It’s practically impossible to find all these files manually so we need this great software called “grepWin” (Download). After installing this software right click on your wordpress folder and then choose “grepWin…” (see image below)

wpadmin

Then type “wp-admin” in “Search for:” box and “profile” (or anything you wish) in “Replace with:” and click “Replace”. This software will find every “wp-admin” and replace it with “profile”.

Now we are almost done. There is one file in /wp-admin/ directory called wp-admin.css. You have to change it’s name to “profile.css” (your_admin_directory_name.css).

Please note that some plugins and themes may also use the “wp-admin” name somewhere, so before you upload any theme or plugin don’t forget to scan it using grepWin and change every “wp-admin” to your chosen directory name.

 

DISCLAIMER: THIS IS NOT ADVISABLE IF YOU ARE PLANNING TO UPDATE YOUR WORDPRESS SITES REGULARLY. Please back up your files

Rocky Rasonable

A filipino Senior PHP Programmer, Web Developer and Webmaster based in Davao, Philippines. Expert in Joomla, WordPress, Soholaunch, Oscommerce, Drupal, Social Media Sites, and etc.

More Posts - Website

 

Posts Tagged ‘CMS’

7 Widespread Admin Errors in CMS

Published: Sep 21, 2010
Tags: , , , ,

1.) CCCA by IDX Web Designs

cccaContent management system based on PHP and MySQL. Powerful yet simple CMS for all. Comprehensive functionality. Pricing seems to be reasonable for the small company. Easy to install and user friendly.  Available only for All IDX Web Designs Clients. Contact IDX Web Designs and Request a quote

2.) Joomla by Wilco Jansen

joomla-s-webtreatsetc-128An award-winning content management system (CMS), which enables you to build Web sites and powerful online applications. Many aspects, including its ease-of-use and extensibility, have made Joomla the most popular Web site software available. Best of all, Joomla is an open source solution that is freely available to everyone.

3.) WordPress by Ryan Boren

wordpress-logoState-of-the-art publishing platform with a focus on aesthetics, web standards, and usability. WordPress is both free and priceless at the same time.
More simply, WordPress is what you use when you want to work with your blogging software, not fight it.

4.) Soholaunch

soholaunchAn easy-to-use website creation tool to help you build, maintain, and manage your personal or business website. It runs right from your website, making it easy to take shopping cart orders online, create forms, and edit site pages from any computer in the world!

5.) Drupal

drupal-s-webtreatsetc-128A free software package that allows an individual or a community of users to easily publish, manage and organize a wide variety of content on a website. Tens of thousands of people and organizations are using Drupal to power scores of different web sites

Rocky Rasonable

A filipino Senior PHP Programmer, Web Developer and Webmaster based in Davao, Philippines. Expert in Joomla, WordPress, Soholaunch, Oscommerce, Drupal, Social Media Sites, and etc.

More Posts - Website

 

Translator

English flagItalian flagKorean flagChinese (Simplified) flagChinese (Traditional) flagPortuguese flagGerman flagFrench flagSpanish flagJapanese flag
Arabic flagGreek flagDutch flagBulgarian flagCzech flagCroatian flagDanish flagFinnish flagHindi flagPolish flag
Romanian flagSwedish flagNorwegian flagCatalan flagFilipino flagHebrew flagIndonesian flagLatvian flagLithuanian flagSerbian flag
Slovak flagSlovenian flagUkrainian flagVietnamese flagAlbanian flagEstonian flagGalician flagMaltese flagThai flagTurkish flag
Hungarian flag         

My Partners

Review rockyrasonable.com on alexa.com

hostgator
Hostgator templateplazzaelegantthemesrocketthemeTopPhilippineWebsites.com Programming Blogroll Center

Tags

Get Adobe Flash playerPlugin by wpburn.com wordpress themes

Powered by WP Robot