Blog
WordPress Brute-Forced!
In the last couple of days, I received many invalid login alerts from one of my clients’ WordPress site — Someone was trying, desperately, to log into my client’s WordPress dashboard using invalid usernames and/or passwords. The “desperation” (i.e. large number of login attempts within a very short period of time) and the fact that
{ Read More }
Cleaning Up Messy LaunchPad (The Geeky Way)
I was installing and updating apps on my MacBookPro, and accidentally dragged an .app file into a sub-folder in the Application folder (which it doesn’t belong). That inevitably created a duplicate icon for the app in the LaunchPad. After cleaning up my mess in the Application folder and moved everything into their right places —
{ Read More }
Can you spot a phishing email?
Phishing and scam emails come in all shape and sizes, but all of them look at least somewhat legit… Do you know how to spot them? Thing to look for (i.e. red flags) when spotting phishing and scam emails: What else? If you can think of any other tricks to spotting phishing and scam email,
{ Read More }
WordPress 3.5.1 is Out!
It’s WordPress update time! WordPress 3.5.1 was released a few days ago, and this is the first maintenance release of 3.5, fixing 37 bugs. It is also a security release for all previous WordPress versions. Here is the highlight of what’s new: This release also addresses the following security issues: For a full list of
{ Read More }
Merry Christmas!
Wishing you a Joyous Holiday Season and a New Year filled with Peace and Happiness.
Phishing Alert: “Your Amazon.com Order” email
Yes, it’s the holiday season, and it’s also the season of cyber crooks taking advantage of holiday online shoppers, especially those who don’t usually shop online. I came across a fairly convincing (at first glance anyways) phishing/malicious email claiming to have been sent from Amazon.com. Although the email used images from Amazon.com (hotlinked from g-ec2.images-amazon.com),
{ Read More }
What to do if TSA asks for your password
Image: AP Photo/Elaine Thompson, file This is some serious privacy issue for travelers, especially many of us will be traveling for the holidays. First of, TSA isn’t supposed to confiscate laptops, search digital devices or demand passwords. If someone at a TSA checkout ever attempts to confiscate your devices and/or gain access to your passwords,
{ Read More }
Beware of “Help Hurricane Sandy victims” Scams
Image: The Next Web Sadly, another natural disaster, another opportunity for scammers and spammers to take advantage of people generosity and willingness to help. I came across of a spam comment while surfing Mashable this morning, it was something like: “Shop here [short URL] to help victims of Hurricane Sandy” If clicked, the short URL
{ Read More }
Hide Your WordPress Login from Author Archive
Did you know your WordPress login username can be leaked quite easily via author archive page’s permalink? http://websiteurl.com/author/username/ The important part here is /author/username/, as this is where your login username could be leaked. How This Works… When you create a new user on your WordPress site, you assign this user a username for login purposes. There
{ Read More }
WordPress Plugin Exploit Alert: Wordfence Security
Secunia has reported a XSS vulnerability in WordPress security plugin Wordfence Security, which can be exploited to execute arbitrary HTML and script code in a user’s browser session in context of an affected site. The vulnerability affects versions 3.3.5 and prior, and has been patched in the latest version (3.3.7). If you’re using this plugin, please
{ Read More }
















