Archive for the ‘Word Press’ Category

WordPress plugins leave you vulnerable to attack, and new devices ‘protect you’ from cellphone radiation

Mark Gibbs | June 25, 2013

Gibbs is worried by how bad WordPress plugins can be and wonders about the efficacy of cellphone radiation attenuators.

First up this week, a white paper or report or ... I have no idea what these things should be called any more ... maybe a "glorified press release"? Whatever. Let's call it "a study" from Checkmarx, a company that specializes in automated security code review, titled "The Security State of WordPress' top 50 Plugins."

Yep, Checkmarx's conclusions are as depressing as you might have guessed: "20% of the 50 most popular WordPress plugins and 7 out of the top 10 most popular e-commerce plugins are vulnerable to common Web attacks. This amounts to nearly 8 million downloads of vulnerable plugins. Namely, these plugins are vulnerable to: SQL Injection (SQLi), Cross Site Scripting (XSS), Cross Site Request Forgery (CSRF), and Path Traversal (PT)."

So, the bottom line of the study: Be very careful of your WordPress plugins ... oh, and use Checkmarx to check your code.

While we're talking about protection, how about protection from the dangers of cellphone radiation? I recently talked to a company named Bodywell that sells a product called the Bodywell Chip which, they claim:

"... is a revolutionary new approach to reducing exposure to cell phone radiation. Place the chip anywhere on your phone to lower radiation exposure without interfering with your cell phone's signal."

Bodywell's PR people (who shall remain nameless) waxed lyrical in their pitch: "The culprit. Our body cells use carefully balanced frequencies to store and transfer the information needed to function. These fields are easily disrupted by information from sources such as cellphones with incorrect or harmful frequency oscillations ... We discovered that certain minerals and metals contain natural frequencies that can be calibrated to 'counter' the cellphone's frequencies, lowering the radiation absorption for users ..."

The chip is not really a "chip," as such, but rather a plastic patch with what appears to be some embedded circuitry.

I've run the concept past several electrical engineers and physicists and, to a wo/man, they all snickered and, to cut to the chase, declared that the product sounded like nonsense.

Original post:
WordPress plugins leave you vulnerable to attack, and new devices 'protect you' from cellphone radiation

Word Press Theme Azon Theme – Video


Word Press Theme Azon Theme
Found unmatched tags!n.

By: FREEMLMLEADSTODAY12

Read the original:
Word Press Theme Azon Theme - Video

Elite Marketing Pro: UPDATE from Tim Erway ( CEO of Magnetic Sponsoring ) – Video


Elite Marketing Pro: UPDATE from Tim Erway ( CEO of Magnetic Sponsoring )
http://www.TenDayChallenge.com This just keeps getting better and better. Exciting Announcements from Tim Erway (CEO of Magnetic Sponsoring) were just releas...

By: Greg Bagnaro

Here is the original post:
Elite Marketing Pro: UPDATE from Tim Erway ( CEO of Magnetic Sponsoring ) - Video

Even Though Paula Deen May be Racist, Joe Randall Still Respects Her

Also: Watch as Deen introduces her 'friend/son' who is 'black as that board'

*Famous African American Southern chef Joe Randall once taught Paula Deena few tricks.

It seems one thing he forget to include in his lessons was a trick to stay out of the press, or at least in a negative light.

Paula Deen is currently under fire from her admitted use of the n-word. Although Randall is extremely hurt by Deens poor choice in words, he tells TMZ hed still welcome her at his establishment.

Chef Joes famous Savannah Cooking School in Georgia is where Deen once studied. Although he cant say definitely whether Deens a racist simply because she once used the n-word, Randall says, I can say that her admitting to using derogatory language and the n-word is very hurtful.

Randall called the language racist, but said, You have to understand were in the South and some people think that its acceptable to use [racist] language from 50 years ago.

Shockingly Randall adds, As a businessman, of course she is welcome in my establishment like any other client would be. I wouldnt turn her down at all.

Although I dont respect that she used derogatory hateful words and if she came into my establishment and we were to talk, I would tell her I dont agree with her words.

We wonder how old Joe would feel about Paula if knew about the video below where she talks to the NY Times in 2012 about her hard-to-see black friend/son, Hollis Johnson.

While talking about her great-great-grandfather who shot himself after the Civil War because all of his help were no longer available to him for free, she decided to play show and tell with Johnson, who is black as that board (her words) while pointing to the background.

Follow this link:
Even Though Paula Deen May be Racist, Joe Randall Still Respects Her

Open Source WordPress 3.5.2 Updated for Server-Side Request Forgery Attacks

From the 'Why are you reading this? Update NOW' files:

In recent years, the open source WordPress content management (nee Blog) platform has emerged to become the dominant player in web CMS space. That's why when there is a security update you should RUN DON'T WALK to patch.

WordPress 3.5.2 is out today fixing 12 flaws of varying severity.

Top of the list (and top of mind for me) is: "Blocking server-side request forgery attacks, which could potentially enable an attacker to gain access to a site."

and

Multiple fixes for cross-site scripting.

Cross-Site Scripting (XSS) attacks have long been among the top attack vectors so it's great to see swift action from WordPress in fixing these flaws.

If you're already running a WordPress 3.5.x site, you can update your site easily from the dashboard - which is something you should do - NOW.

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

See the article here:
Open Source WordPress 3.5.2 Updated for Server-Side Request Forgery Attacks