old photo.
  • Loading...

waste of a day.

I’ve just gotten in the door after leaving the house 5 hours ago to do some shopping at a retail park with my mum. We managed to spend just £20 and that was £3 on lunch (McDonalds pound menu) and £17 in on juice, milk and bread. Typical. I was so looking forward to buying little things in Ikea or a few pairs of trousers for in Next or TK Maxx but every single shop that we went into was rubbish - shelves were half empty or items over-priced.

The whole point of going out in the first place was to let me do some but ended up I didn’t have a chance - mainly because the weather and traffic were horrendous. Hopefully I’ll manage to get out for an hour or two tomorrow since I feel like I haven’t been for ages and I want to sit my test soon, I’m fed up relying on buses to get around everywhere and taxis are costing me a fortune.

I’ve got to laugh at this listing on eBay for Irn Bru glasses - £14.99 buy it now? Those glasses are free for goodness sakes. There are about 150 of them sitting in the backshop in - we’re handing them out with a purchase of 2 x 2litre bottles of Irn Bru and people are selling them for £15? What on earth is the world thinking?

A complete overhaul of the way in which people navigate the internet has been given the go-ahead in Paris.

The net’s regulator, Icann, voted unanimously to relax the strict rules on so-called “top-level” domain names, such as .com or .uk.

The decision means that companies could turn brands into web addresses, while individuals could use their names.

A second proposal, to introduce domain names written in Asian, Arabic or other scripts, was also approved.

“We are opening up a new world and I think this cannot be underestimated,” said Roberto Gaetano, a member of the Internet Corporation for Assigned Names and Numbers (Icann)

The organisation said it had already been contacted about setting up domains in the Cyrillic script - used in many Eastern European countries.

“This is a huge step forward in the development of the internet - it will unblock something that has prevented a lot of people getting ,” said Emily Taylor, director of legal and policy at Nominet, the national registry for .uk domain names.

“At the moment, there are one-and-a-half billion people and four-and-a-half billion people for whom the Roman script just means nothing.”

Dr Paul Twomey, chief executive of Icann, described passing the resolution as a “historic moment”.

Continue reading at BBC News website…

So, finally the internet will be filled with witty .xxx and .blog domains, as well as ‘funky’ domains such as firstname.surname/ Something which I’m not looking forward to. As far as I’m aware TLD’s such as .biz and .me.uk never really took off. I personally wouldn’t want one, rather sticking to .com and .co.uk - and the latter only because of the uk part.

The only thing that I can see myself doing would be having a .scot just because I’m so proud of my nationality - but it doesn’t make for a sexy looking domain name - ashesfromstars.scot, anyone? google.rocks? msn.sucks? Novelty, that’s all. It (hopefully) will get old quickly.

But out of interest, what would you want to register and why?

Laptop

I’ve been looking at purchasing a new laptop for my partner. Yes, he has a super-dooper fast computer for all the that we play but I’d love to get him a nice, reliable laptop for when he’s just wanting to sit and browse the internet, or even for when we’re out playing pool in his garage. There’s often a reason for us to jump and check something when we’re out there and I usually do it via my iPod Touch, but that kills the battery a bit.

Saying that, I have just bought the pool table so he’ll have to wait a little while for a new laptop! And before I get him one, I need more ram for my laptop so that I can play The Sims 2 without it crashing all the time. Grr, so annoying!!

With everything that’s has been happening regarding I’ve not had a chance to jump in a wee while. But, for once in my I actually have things to blog about.

Last Friday the boy and I went out to play some pool in his local pub, usually where we can be found on a Friday night. There were two guys playing pool on the table next to us and we started talking to them, I knew one of them as he’s a local instructor and knows the boy’s mum. Anyway, they were laughing at the fact I’m useless at playing pool and decided to teach me properly. Well, I’ve never had such a laugh. They ended up moving every ball over the pockets so that no matter what the shot, I potted a ball - it was excellent!

I absent mindedly asked ‘are you this good at getting people through their tests?’ and ended up getting myself a instructer. Who, has it happens is pretty damn good!

I had my first, double, lesson with him the other day and it’s amazing, I can actually drive. We did the usual cockpit drill, starting off etc and then I got let free on dual carriageways where I was told to ‘put your foot down til you hit 70 to see what it’s like’, which was scary as hell but so good as I was really scared of going fast, and I’ve mastered hill starts and crawling up/down hills at 5mph, as well as feeling a lot better at going around roundabouts.

I’ve got an other lesson on Thursday evening and I’m really looking forward to it, should be good. Now that I’ve got a good teacher I should be through my test in no time, my confidence is soaring when I get behind the wheel these days!

Wordpress Security

Last night I found out the hard way why security is so important. My got hacked/hijacked and the result was that every single internal link autoforwarded to a pornsite that tried to install toolbars, trojans..the lot.

I know that this has happened to at least one other blog that I visit, and probably lots more. The reasoning is probably down to unsecure file permissions within the files on my server. (Possibly something to do with the fact that have released version 2.5.1 with ultra important security fixes?)

So after deleting everything from the server and installing afresh (which of course came with it’s own problems of trying to remember all the that I had installed etc) and importing a backup I took control of my blog again.

But it got me thinking. I’ve been for half my . I’ve had a website of some description for a decade. I should know about and implement security features. I shouldn’t have had to find out the hard way how important it is to keep my files safe from attack.

I’ve compiled a list of all the steps that you should take to protect your installation from malicious hijacking, after all I’ve been researching it for the past couple of hours to make sure that it never happens again.

File Permissions

Probably the biggest one on the list, and the one that can cause the most problems if you’re used to editing and through the dashboard.

None of your files should be set to 777 (all users read, write and execute). By using the WP Security Scan plugin you can automatically see which folder do not have the correct permissions and fix them with a click. The plugin also points out any other security issues on your . It’s an essential plugin for your , and if you ask me it should be included with rather than Hello Dolly.

User - Admin

Your default user in is more than likely ‘Admin’. The same goes for the thousands of other blogs out there. So it’s not that difficult to guess, is it? So the obvious answer is to delete the user ‘Admin’. But won’t let you delete the default user, so what can you do about it?

This is where phpMyAdmin comes in to play. Don’t worry too much if you’ve never used it before, it’s quite simple as long as you follow these steps.

  1. Log into your phpMyAdmin through your cPanel.
  2. On the left hand side of the window you’ll see a list of tables like wp_options, wp_users. (the wp_prefix may be different if you’ve set this up as a different value when you installed ).
  3. Click on wp_users.
  4. A table will load in the right hand frame, select the checkbox shown next to user_login.
  5. Select ‘Browse’ from the tabs at the top of the page.
  6. This then shows the table with all of your registered users details. You want to select the little pencil next to the name Admin to change this to a name of your choice.
  7. Once you’ve changed the name to something else, press Go at the bottom of the screen.
  8. That’s it - you’re done. The user ‘Admin’ no longer exists.

robots.txt

The robots.txt file on your server gives instructions to search engine robots (like GoogleBot). Remember that however not all search engine robots are good ones that play by the book, some will completly ignore your robots.txt file. But you can still add the following code to yours to stop all of your wp- folders being indexed by search engines.
Disallow: /wp-*

Passwords

Ok, this one’s a giver. We all know that passwords should be long and contain numbers, letters and symbols. But that’s hard to remember. But the amount of people who use the word ‘password’ as their password is incredible, and again it’s not that hard to guess, is it? Remember the MySpace password exploit? It threw up some interesting data on how people pick passwords, including the word ‘password’.

The easiest thing to remember is that you should keep your FTP and login password completely different and try and choose a password which is really hard to out, but means something to you - like an acronym of you and your partners names plus your anniversary date. You could use a random password generator to create a password, although you’ll probably have to get your browser to remember it for you!

version

Ok, so the geeks among us get excited when a new version of is in the pipeline and upgrade straight away, but some people wait a few weeks to ensure that any problems are ironed out amongst other reasons. It may be personal choice, but upgrading to the newest version of straight
away also protects your blog as there’s always security included in the upgrade. Try installing the WordPress Automatic Update Plugin to make upgrading your installation easy as pie.

Similarly, publishing what version of you are running is a danger in itself. You won’t realise that you’re letting the whole world know which version of you are running until you yourself check your page source. If there’s a Meta tag showing which version of you’re running from, remove it from your header.

Login Lockout

Login LockDown records the IP address and timestamp of every failed login attempt. If more than a certain number of attempts are detected within a short period of time from the same IP range, then the login function is disabled for all requests from that range. This helps to prevent brute force password discovery. Currently the plugin defaults to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified via the Options panel. Admisitrators can release locked out IP ranges manually from the panel.
Login Lockdown plugin

That says it all really, doesn’t it?

Directory Listings

By default anybody can access your by going to www.yourblog.com/wp-// and viewing every plugin that you currently have installed. By either including a blank html file in your // directory or switching off directory listings via your cPanel users will not be able to view these folders and files, and possibly any security risks that they have.

Don’t use FTP

Use SSH/Shell Access instead. It’s possibly not the easiest thing to do in the world but it’s one of the best moves you can make. If you can, disable FTP completely.

If you’ve got anything else to add, please feel free to leave a comment.

A pain in the arse.

Since around 9am this morning (it’s now 4pm) I’ve been sitting , jailbreaking my iPod touch and sorting my collection, which was a vast job. I’m still nowhere near finished. I’m pretty anal (hah, I can imagine the search referrals I’ll get with that one) about my collection being titled and tagged correctly. And all the ‘The’ bands are sorted alphabetically, like ‘Verve, The - Bittersweet Symphony’. I don’t know what made me start doing that but I like it that way. And somewhere along the line in the past five years I decided that all the nice little album artworks that were included with albums I’d downloaded were taking up valuable space and deleted them all. Uh, what a mistake. I’m now re-downloading album artwork and manually adding them to albums in iTunes since obviously there’s lots of albums that I have that iTunes doesn’t have. I’m special that way.

Anyway, I digress. Is it so hard for people to upload files to the internet and tag them properly? It would save so much time for people like me.

Welcome to the candyshop I really shouldn’t be sitting munching a lot of sweets considering the boyfriend’s on his way back with my lunch, a nice healthy Burger King!

My body’s all confused because the clock’s went forward this morning, the computer says 16.49 (right), the alarm clock says 15.49 and my body says it’s about 11.00 since I was up half the night!

Oh, and by the way weather system? It’s spring now. So stop with the rain and snow please?

Forgotten?

Nope, not forgotten about being I’ve just not had a minute to think for myself over the past week or so. It doesn’t look like much has been going on anyway!

In case you hadn’t noticed there’s a new theme up - it’s based on the previous theme since I loved that one so much and I’m still working on wee bits here and there but I love it so much I had to make it live. I’ve also had a bit of a clean up and am fixing pages and as I type.

A better post next time, just proving that I’m still alive.

I know that a lot of bloggers who use get slated. I’ve seen it referred to as ‘just like adverts on that I flick past’. The person was explaining why they do not read blogs which have sponsored posts; which is fair enough - each to their own. I for one actually quite enjoy reading sponsored posts as they show how great (usually) the blog writer’s imagination is. It’s a skill being able to write a review of a product / service and incorporate it into your blog, personal experience, writing style and making it keyword heavy all at the one time. It’s a challenge sometimes, but that’s why you’re getting paid for it!

As avid readers of my blog (go on, you know you all love me) you’ll probably have worked out that I use from time to time. I made a pact with myself when I signed up for the way back in July 2007 that I would only take opportunities that were actually relevant to me personally or my blog. I have no interest in garage storage
Top Earner list - I'm on there! cupboards or homeowner insurance, so why on earth would I want to blog about them and bore you all senseless with my opinion on something I’ve never used or had an experience with? Unfortunately not all Posties1 do this, and all you get is page after page of sponsored posts about gambling, websites and weight loss miracles2. To date I’ve been paid for just 12 posts, and made a grand total of 80GBP. Nothing changing but that has been put towards paying my credit card debt which is getting smaller and smaller by the month. Thus helping reinstating my credit rating, making me a happy girl again. Today I’m amused to see myself on the day’s top earner list. 3rd as well. And only from posting one post, sweet.

Anyway, I digress. And I’m starting to think that this post sounds like a sponsored post. I can assure you that it isn’t, I’m not getting a single penny for biggin’ up , as I’ve already done that and been paid for it.

What I am worried about is that these random, not-so-frequent paid posts are discouraging readership. Don’t get me wrong, my doesn’t revolve around how many comments I receive or my Alexa rating but I don’t like the thought of pouring so much time and effort into my , as I have done since 1998, only to be shooting myself in the foot and loosing out on readers (and more to the point, new and blogs to read etc) just because I make a few bucks writing about things that people don’t want to read about.

So my question is to you, dear reader, is this. What do you honestly think of blogs. Not just mine, although do feel free to make your feelings known, but any blog that sides on the making side. Do you have a tolerance level? Do you just skip the posts you don’t want to read or do you delete the blog from your RSS reader the moment a “This posts was sponsored by…” tagline pops up? Or do you not really care and read every post anyway?

I’m actually really interested in knowing what you think, good or bad. Everybody has their opinions so please share yours.

EDIT:This post has had over 200 views and only one comment, so I’ve added a poll for quick opinion posting. I like opinions, please pick one!

[poll=3]

——————————————————————————-
1 Posties are the affectionate name for bloggers who use .
2Weight loss miracles do not exist. All you need is portion control and some exercise and commitment!

« Older entries