Monday, December 13, 2010

Wordpress site Infection : save your site

Today I witness something , that I never expected to happen. At office I was having chat with my friend Gopal. Gopal had subscribed to my wordpres site "burnedpages.com" through feeds. Suddenly his computer blocks an infection from my site (Thanks to Avast, the best in business). I was kinda surprised.
First I thought it was a false alarm but when i reached home, I couldn't access to my site. My own avast was blocking all the infection. So I figured something had wrong. It was my first time hosting a site, and I didn't wanted Google to show my site as unsecured.
I was using wordpress 3.0.1 with "erudite" theme. no other plugins.
I don't want google or other search engine to ban my site from search results, So here are some (desperate) steps that I took:-
  • Backup of Data:- I used my website admin tools to get access to my wordpress database and then exported all the data to my computer. after all its your work and it shouldn't be wasted. My site provides an easy way to export the database using "PhpMyadmin". phpmyadmin has an export option that can be use to export your data to a text file. This backup is very usualful  if you need to change wordpress database name. In most cases it wouldn't be necessary though.
  • Change FTP password : I guess hackers some how accessed my ftp password, or used sql-injection techniques to transfer the infected code to my index.php file. Any ways I changed my ftp password to a secure and hard to crack one.
  • Deleted WordPress:- Then I deleted all word press files. (Yeah its better to delete it and then install a fresh one, rather then cure the infected file yourself. You can remove  'Extra Melicious code' from your webpages,but i guess wiping is better ;)   )
  • Note for users:- Created a html page in my site saying that my site is undergoing maintenance.It is great for your traffic, otherwise people may go like "WTH, this site was working yesterday".
  • Upload the original installation: If you have original installation of wordpress in your computer , you can upload them back and get your site to its original state easily.
  • Access modification  : Change file permissions on your site so only you can write them.
And my sites was up and running in 10 mins. Next time I will be more careful.
    What I have learned :- Don't use Wordpress own theme installation module . Why? it uses FTP and its better if you do it from your FTP client. Choose a hard password to crack for your wordpress installations. Its better that your site remains under maintenace mode rather then spreading infection. I hope it helps those wordpress sites that have such infection. Wordpress is great blogging tool and such incidents shouldn't put a question mark on it. Webmaster can be and must be a little careful next time.

    Saturday, December 11, 2010

    Beat within my heart

    Music is something that is just beyond description. The very essence of life , pleasure and faith. A calm beat that constantly loops while you surf the net. An aura of music beats that surrounds you when you are happy , a simple song that you hum every sec of the day.
    It remarkable how taste of music varies with person to person , place to place and time to time. With so many genre of music around us, how we like so many form of music . From plain jazz , Hindi songs , ghazals  to  pop ,rock and  metal.
    Music has the power of devouring you in it. An affliction that constantly beats within you. How we enjoy every line of our favorite song. Feel every word of the song ,listening to every line like its part of our life. Singing it like we are the one who created it.
    Our culture is rich in Music forms. So many flavours , types and colors,  defines music and the way we appreciate it.
    "Music is Life ".

    Monday, December 6, 2010

    Wiki Leaks : Down?

    I was just trying to search wikileaks at google, and guess what? their main domain appears to be down. "www.wikileaks.org" is down. I think government striped their domain name from name server or somehow prevented access to their name server or even worse their site may be under attack. I think thier other mirrors are still operational. I found their facebook account showing some mirrors working directly on IPs.

    But what I found interesting was how google's search engine still is able to search them. Just type "wiki leaks" and google searches page that don't have a domain name , but rather a static IP. Strange? well kinda yeah. I mean how the hell they did that? ( might have been the cached pages... don't know for sure). I mean it blows up the SEO right? Or is it just googles own preference to find them cause it is a burning topic?

    Is it possible to remove wikileaks from Internet? Well the answer is probebly "nope". Why? Because Internet was designed for this specific purpose. (I know you don't know that. So here is a link http://en.wikipedia.org/wiki/Arpanet ).
    Internet was designed to endure a Nuclear attack. So it even works if some of its portion is blown.

    P.S. dismantling Internet would be the only way to bring down wikileaks to dust i guess  :)