Be afraid, be very afraid!
August 13th, 2010 by Sarah KingSo you have a great idea for a site, you buy a domain, throw a WordPress site up on your shared hosting and upload a free template and every cool plugin known to man. Within an hour you’ve written 5 blog posts and dropped a link at dp so within 2 more hours the spiders will be all over the site and the world will know about you.
Anyone who has been around for a bit knows that all of those plugins and themes should be checked out before they get uploaded but in reality some can get pretty gnarly and the vast majority of WordPress users can do little more than ftp.
Pharma hack and their C&C (Command & control) server
Understanding and cleaning the Pharma hack on WordPress
Securi have blown the whistle on a so-called “Pharma hack” where a few lines of code nestled in a template (but could just as easily be a plugin) allow the hacker to upload further scripts and take control of your site. They appear to be taking it easy right now and just inserting new links around the place and hoping, I guess, that most will be on auto-blog so that the owners are relatively disinterested and won’t notice their changes.
A few years ago WordPress had a situation where they’d stopped using a file that had a security flaw in it. Those of us who upgraded properly deleted the file and were fine. Those who just uploaded the new files ontop of the old still had the file on their servers and were vulnerable.
If you’ve got lazy of late its time to rethink how you upgrade and what you install. Probably time to lock down that config.php too.
And time for WordPress to let us have any files that are never called directly isolated and either moved below the root or locked away from public access.
viagra levitra review? Viagra For Sale caught selling viagra
Viagra erection duration viagra erection enhancers problems 400. Cheapest Viagra Prices generic viagra levitra regalis
viagra pages edinburgh find generic girl, Viagra Prescription Uk order phizer viagra
Viagra alcohaol viagra alcohol 20. Viagra No Prescription Uk alternative viagra uk biggest viagra case 775.
forced viagra and tied up Viagra Sale viagra free gratis
Auckland hosts WordCamp, and aint it great!
August 7th, 2010 by Sarah KingWhen you’re a WAHM freelancer the first thing you notice is the lack of techies to talk with so it’s great to be able to break out and attend events like Auckland’s WordCamp.
I only made it to the afternoon session but the techie sessions were worth going to:
- An intro to HTML5 and CSS3 and why we should care
- Custom Pages – opening WordPress up to a whole new style of development
- WordPress Plugins and customisation
Some of the info was possibly a bit superficial but hanging out in the corridor afterwards with WP developers and guys from Instinct.co.nz was just the thing for a tech starved geek. So much better than infracting fools at dp!
Great to catch up with Michael Brandon too, find out what he’s been up to and chat SEO.
I’m all set to have a play with the e-commerce plugin so I can quiz Jeffry Ghazally at his session tomorrow.
generic indian viagra Cost Of Viagra viagra legal!
natural supplement for viagra Viagra Prices Buy viagra internet buy viagra levitra alternative lavitra 922.
viagra and hair loss Canadian Viagra viagra triangle chicago
viagra quartering 100 mg Viagra Alternatives viagra acts alone
viagra effects on dog? Buying Viagra viagra and flying
DIY Adsense Ban for your competitors
July 16th, 2010 by Sarah KingI’ve always thought that Adsense had the best tools for picking up on click rings etc and fraudulent use. I particularly like how they string bad users along to garner the really damning evidence.
I was surprised, though, that their tools didn’t show that DigitalPoint was being targeted by disgruntled ex-users of the forum. See A 3rd Party CAN Get You Banned From AdSense for the blow by blow account.
Effectively all you have to do is set up gambling sites and use your competitors adsense code.
There are rules though… (I imagine)
- never click the ads yourself
- never visit the admin pages of the sites from an IP that you log into any Google service from
- have whois guard turned on for the gambling domains you register
- never mention those domains in any blog posts, tweets, forums etc
Which all sounds like too much hard work to me.
In the meantime if Google wanted to let me loose on their tracking systems I reckon I could find the culprits in no time at all because I don’t think they will have followed the rules at all!
viagra bom, Cialis Vs Viagra online uk viagra
buy cheap generic online viagra Uk Viagra Sales penis enlargement pills viagra men
government viagra! Female Viagra Cream cheap drugs viagra cialas
“wedding night viagra thing” Viagra Soft Tabs viagra medical need?
Fuzzuck: sane and sensible SEO, for a change!
July 4th, 2010 by Sarah KingSome days I feel like the internet marketing world has gone mad so it was a relief to find Fuzzuck.com, a straight shooting, ethical search engine optimization blog.
Fuzzuck is run on WordPress so it is comfortable to use with a nice clean theme. The latest post is Self Service Links and Why I Hate Them. I wouldn’t say that I “hate” them* but I do despair of the hordes who are selling services around exploiting them. They definitely shouldn’t be the mainstay of any link building campaign.
Outbound Links as a Signal of Quality? looks at the impact the links on your site have on your position in the SERPs. A client of mine owns The Paepae and has benefited from this quite by accident. He refers to other blogs and gives his sources – and in turn Google rewards his natural linking habits. I couldn’t agree more that it helps to have solid outbound links on your pages – but they need to be relevant and perhaps not too “perfect”.
So What Happened to Mike Siwek? takes a step away from the totally serious and looks at how an article about Google search has totally hijacked one man’s name.
Fuzzuck isn’t a blog you’ll return to weekly or daily but it is one to bookmark for when you are doing a bit of study or revision – checking out the latest thinking and so on. Its got hits on DMOZ and a great hint for directory owners which, with a bit of automation, wouldn’t impact on your workload. Fuzzuck has been around since ’06 and has stood the test of time. The advice is as clearly thought out today as it was back then. Its worth a bookmark and checking back on.
* Ironically my latest experimental page makes it easier for those hordes.
drug generic generic viagra Discount Viagra drug manufacturers buy softtabs viagra
Interactive Google Ads at Ask Dave Taylor
May 20th, 2010 by Sarah KingThis is a first for me. Google Ads with forms you can complete and the “click” doesn’t happen until you hit the submit button.
Its nothing new to fake a form, and when the user goes to enter their email they are taken to the advertisers page. But on this one, you can actually fill in the form!
Check out Ask Dave Taylor to see the real thing.
The moderation challenge facing YouTube
May 19th, 2010 by Sarah KingVideo Marketing is big business these days as companies try to use the visual media as a way to reach their audiences. Bandwidth gets cheaper and users don’t hesitate to jump from clip to clip. Even nonsense like “Fred goes swimming” is talked about in the playground and my son has tried to create his own “tribute to Fred” – be assured it didn’t make it off the camera!
So when I see ebooks being sold at dp about how to steal traffic from YouTube its cause for concern. Are my kids going to stumble across something unethical and start thinking that “if it’s at YouTube it must be ok” or “if everyone is doing it it must be ok”?
Copy videos and republish as your own
Just as Copyscape can identify copied text on a page YouTube needs tools to identify if a video has been published before and if it has to flag that video for moderation – and the oldest version is retained. It also needs to be smart enough to identify if the video is part of, or an amalgamation of other videos.
Hold many accounts and like each others videos
If Amazon can bring us software to show “If you liked this you’ll like that” surely the brains behind YouTube (ie Google) can give their moderators tools to show that this cluster of accounts are too tightly connected in what they “like”.
Hold many accounts and report the originals of the videos you have republished
This ties the previous two points together. If one account in a cluster reports a video that is a close match to a video from another account in the cluster then the second video should be marked for moderation also.
Publish videos on hot/viral topics
This is like “SEO 101″ to grab the issue of the day and exploit it just like the tshirt vendors selling RIP Michael Jackson within hours of the singer’s death.
Where those videos are purely exploitative and offer no content or are purely to drive traffic to a site which then doesn’t deliver then YouTube needs to shut them down.
That means the guys with 220 tshirts are fine to brand their video but the guy who says “want to see what happens next” may not be. The moderators need to view the video in the context of other submissions and the site it is pointing to. A big job? you bet but it’s all part and parcel of running a video sharing site.
Bad Sites a video can point to
- A parked domain… if its parked within x months of the video being submitted then the video is suspect.
- MFA Made for Adsense sites. These stick out like sore thumbs and are exploiting another arm of the Google stable – or some other group of advertisers. If the video isn’t quality and the site is MFA then there is an obvious problem.
- CPA Cost Per Action exploit sites. Another site that is clearly all wrong to those in the know but users still go to sites, see that they can’t access without filling out a form and they do it! There is a world of difference between a member only site and one that needs you to fill in an offer. Yes, the CPA exploit sites can be very clever but they don’t deliver. You end up somewhere else altogether and instead of complaining to the CPA firm the user disappears. The site owner gets richer and the advertiser wonders where all the ad spend is going.
Infractions?
vBulletin has given the moderators on the forums running it’s software a great tool called Infractions. You accrue infractions (which usually expire over time) for breaking forum rules. Get X points and you are temporarily banned.
If users are relying on the age of their account to save them from a ban then the moderators need to have some sort of counter or infraction system so that new users and old are treated equally. If anything old users suffer because they have had longer to earn infractions.
The Harsh Reality is that creating quality, unique content is really hard and most of us just don’t have what it takes. That’s why people copy, cheat and steal. Its not cool and its not clever. Perhaps if they used tools like XtraNormal they could create clever, witty content of their own. Then again, that takes initiative and creativity…
World of Warcraft: have you sold your account? Phising Alert
May 16th, 2010 by Sarah KingThe latest phishing scam I’ve seen is supposedly from Blizzard.com telling me that I need to verify my account at World of Warcraft and that I’m not allowed to sell my accounts.
One confused 10 year old boy later and we see that accounts need to be bought and he doesn’t have even have a trial account.
Then a second email comes in and I look closely. That url that looked like a secondary Blizzard server turns out to http://blizzard123.idc177.com/ and AVG blocked access to it.
Full marks to AVG and all you WoW folk out there… watch out for the phish!


