I’m very sorry if I zapped legitimate members, but I’m trying to clean up the ranks. Considering the problems I’ve been having, I’d say it’s about time, no? Anyway, I’m going after “suspicious” emails and user names, but suspicious is sort of in the eye of the beholder, no? so if I take you out by mistake, please understand, it’s nothing personal, just a desperate attempt to clean up the site. (Sort of like closing the gate after the horses are out, isn’t it? Ah, well. Anyway, sorry for any inconvenience this causes.
Archive for the ‘Blog Building’ Category
Mass Extinction in the Pub!
Monday, January 11th, 2010Problems navigating?
Sunday, January 10th, 2010Post a comment. Howzat for going after lurkers?
Seriously, I don’t have the remotest idea what’s going on, except that I’ve been messing a lot with my themes over the last few days and don’t know what sorts of hickups that might have left in the ether. Other visitors have said that posting a comment fixed goofy layout.
This should have, like my former choices, a single sidebar on the right and the main body of text on the left.
About 25th on my todo list of 25 things (that’s the way Abbey organizes stuff…I think I need to emulate) is redesigning my blog based on the same theme I used for CC, only optimizing for ‘NetWalkers, but that requires making and balancing backgrounds and stuff, and I just don’t have time for that right now.
Anyway…onto what I’ve been doing. I’ve got the ms part of RoL cleaned up and ready to go. I’m going to do some sketches to include during Nationals. I also have gone through the files for HT and HB and cleaned up lots of scanning artifacts. I’ve got a splitting headache and my eyes are crossing, but I think they’re pretty good now. I’ll be sending out the new links to those who have purchased as soon as I compile and convert HB.
Sorry to whine, but…If I missed things (and I’m sure I did.) unless they’re egregious…uh…don’t tell me, OK? At least for a month or so? I’m so tired of futzy detail stuff, I could scream.
It’s baaaaack
Friday, January 8th, 2010Grrrr….I’ll try a new theme, but I’m less than optimistic. If it were that easy, others would have done it.
I…really don’t need this…
Guardedly optimistic
Thursday, January 7th, 2010No new occurrences in the last 24 hours. I’m trying to monitor this closely. I found some references to gmpg(dot)org in the header file that didn’t arrive with the original theme. I wiped the statement out, then went searching. I found another reference to this site in the sidebar php file which did come with the original theme.
To me, that’s what’s known as suspicious. The reference was a simple href-style link and the gmpg organization appears to be legit, however, just as hackers use the WordPress acknowledgment link in the footer of most sites to target WordPress sites, I’m suspicious that hackers are using this sort of hidden link to somehow target and access a weakness in a given theme.
This is, you understand, totally conjecture on my part, but I’m leaving those references out of my themes from now on, (as well as a bunch of other security measures) and hoping I don’t get a recurrence of those pesky links.
Again, this was not dangerous to anyone visiting. It was pure and simple a means to fool search engines into legitimizing those links that were being inserted and thus raising them to the top of the search lists. The more places with “links” to sites, the more “legitimate” they are, to the search robots. (Do I have that correct, oh computer gurus?)
Back to editing RoL.
Pook
Wednesday, January 6th, 2010Here we go again. New links popped up. Grrrr….This time I did a line by line comparison with the original header file and I think I got at least this file clean. What’s lurking elsewhere, I don’t know. The problem is, I’d modded this file fairly extensively. There was a bunch of animation most computers couldn’t handle, and some rather rude (I’m sure the coder thought it was funny/clever…I didn’t) comments when the animation didn’t work. So, I took all that out. I also put my copyright stuff that appears at the top of the page into it.
So why, you ask, don’t I have a copy of the uncorrupted file on my home computer somewhere? Well, I think I do, but I couldn’t find it. probably on the computer that died. Who knows? Anyway, I’ll be surprised if this fixes it. I’ve probably got some kind of link to the buzzards at the moment. But if it shows up again, I’ll see what I can do. Meantime…I’m working on security….
I found some suspicious stuff in my sidebar php file as well. I zapped it. Hopefully I didn’t zap anything significant. Please let me know if there are any problems logging in or anything like that.
And RoI languishes.
Pook.
I was hit by a zoooommmmbie….
Wednesday, January 6th, 2010
Message from Lynn this AM: As best I could determine last night, the spam loads aren’t meant to display on a monitor, they’re meant to fool search engine spiders into believing that legitimate sites are linking to the spammer’s sites, thereby legitimatizing the spam sites for SEO. It looks like you’ve been hit by a zombie spammer….none of the injected links are valid and appear to date back to 2008 or earlier when Harvard University’s servers were hacked.
Which brings us to the one I totally forgot to thank last night: Lynn. She was on it like a hawk when I emailed her yesterday.
I’d let the matter slide, intending to attack it with a fresh brain today. I’d figured, from the form it took, that is was nothing particularly dangerous to anyone and the info I was getting/finding all pointed to code that was harmless to visitors and designed to affect search engines. It’s the sort of thing that can get a site “blackballed”by search engines, so I wanted to take care of it, but I also wanted some sleep. (Nice thing, sleep.)
But a late-night email from Lynn jerked my brain awake and my default from html-speak into php-speak, and I knew I wouldn’t sleep until I found the answer to the question.
I went searching the php files most likely to have been “infected.” She said it usually manifested in the footer.php, and I did check that first. Nothing suspicious there, but then I realized…footer? Why the footer? Of course…these pages are created on the fly. It had to be something common to every page, not just the posting page. The next file common to all pages and posts is the header. I checked it and there it was, bold as brass.
So, no need for you visitors to worry, and no need for me to worry.
All is well!
Mischief managed!
Wednesday, January 6th, 2010I believe the problem is solved. Somehow that code got inserted into my theme’s header.php file. I zapped it and the source code and display appear to be fine now. My thanks to you all, and especially to Jaakko for putting me onto the problem in the first place.
YOU GUYS RAWK!
It appears I’ve been hacked.
Tuesday, January 5th, 2010update: I probably won’t be posting anything new for a few days until I track this down, but I’d appreciate continuing the conversation in the comments of this page. Right now, I can’t even find the posts on the site using my FTP program. I was going to download them and attack the code with a text editor, but I’m not seeing them as files, so I’m not sure how one goes about this. Anyway, I’m going to be working on the problem….sigh…why me…. (whine whine whine. :D)
I don’t know how it’s ultimately going to manifest, but The Captain has some very unpleasant-looking html in his gullet right now. Thanks to one of you, I became aware of the problem and I’m trying to figure out what to do about it.
I don’t see anything on the blog itself, in IE or Firefox, but if you look at the source code, there are about a gazzilion links imbedded into every expletive deleted page, along with some script. I don’t know what that means about visitors’ protection. Any of you computer gurus out there who have some idea what it might be all about, I’d sure appreciate your advice. I also have no idea how long it’s been there.
I really don’t get it. I don’t see what it’s accomplishing, but then I don’t understand the script code surrounding the links either. I’d REALLY appreciate any help and would like to know if I should, like, shut the blog down or something.
Gawd…I’m so depressed. I don’t need this! You hackers are icky!!!!!
Avatars and main page pix…
Friday, May 8th, 2009
Quick update: I’ve fixed the problem of disappearing Gravatars and Wavatars. If you have a Gravatar, an image from your uploaded gallery will no longer supercede it. The downside is, you can’t supercede it, but if you really want to change your avatar, just change it at Gravatar.
The same change brought back the Wavatars. Yippee! The downside is, this plugin really wants to give you an avatar, so if you upload an image, it will be your avatar, like it or not. So…if you want to keep your wavatar, make sure you right click and save it before uploading any pictures, then upload it to your gallery and choose it as your avatar. I’d suggest doing it in the Pub, since those are bigger images.
At least, I think this will work…going to check out this theory….
Well…saving the image worked. OTOH…er…those who have tried to supercede the wavatar with an uploaded image are now back to the wavatars. ARGH!!!!!! I’ve got to figure how to fix this. ..
Phooey…going back to the way it was. I’ve saved down the wavatars for everyone who still had them and put them in as default avatars for those who remain anonymous. If you’d rather have the Captain default image, just go into your gallery and delete the wavatar. If you have a wavatar and want a different avatar, for right now you’ll have to upload an avatar to your gallery. And if you have a Gravatar and want to upload other images into your gallery, you’ll need to make your gravatar image one of your images.
Are we having fun yet?
Hang in there, folks. We’ll make this work!
The Pub
Wednesday, May 6th, 2009I’m trying a new plugin. “The Pub” should be available to all registered users. There’s nothing there right now except a listing of the registered users, but it should eventually provide a “conversation pit” for all you lovely folk. (This isn’t a live chat, just threaded messaging that’s semi-private.) Mainly, it gives the option of choosing your own avatar, uploading some pictures to share (not a lot, this isn’t flickr or anything like that) and in general giving the site a few more options.
To load an avatar, go to your dashboard (the page that comes up when you log in) and check out the user options on the left hand side bar. One is your Profile, where you can change your password and such, and one is your Gallery. Go to the gallery, upload the image you want to use for your avatar and it will give you the option to choose it as your avatar.
For those who have grown fond of their wavatars, I’ve got a query to the plugin designer to find out how to get those back. They aren’t lost, merely hiding. The Wavatar is somehow linked to your email. I’ve got a query to the wavatar designer to find out if the wavatar dice can be rerolled.
Time to go skate. More later.
Answer on the Wavatar…no, it can’t be changed. It’s actually determined by the email itself. I’m not quite sure I understand correctly, but I think that certain elements are linked to certain features…like “em” in the email might equate to “green” and “it” might correspond to “round glasses.” It’s really extremely clever!
I’m still working on getting the default to be your wavatar. Meantime, I’m going to go make a much more interesting default. Maybe load some default options and see if I can make it so you can choose one.
Off to play with avatars…