Press "Enter" to skip to content

Posts tagged as “plugins”

WordPress Plugin ‘Simple Ads Manager’ Exploit

Anyone who runs sites using the WordPress platform and the plugin Simple Ads Manager will want to read this and learn from our mistake. Even those not using this particular plugin, but who have deactivated plugins not being used but still residing on their servers might find this useful. Luckily, in our case no harm was done, but that’s only because the incident occurred on a test site, so we were able to just take the site down. Lucky for us, it wasn’t FOSS Force or one of our other active sites.

Early Saturday evening we began receiving numerous email notices with two worrisome subject lines from our server. One subject was “LOCALRELAY Alert for sitename,” being sent to us at the rate of about every five minutes, with each showing info on the “first ten of 101 emails” that had been sent by the server since the last email notification. The other subject, “Script Alert for /path/to/script” was coming with the same frequency. To make a long story short, someone had hacked into a site we use to evaluate and test WordPress plugins before possibly deploying them on active sites, and was using it to send spam. Our test site had been turned into a spambot in other words.

Why Not ‘Click to Play’ Flash?

Last week we learned that in the near future, browser plugins won’t automatically work out of the box in Chrome and Firefox. Instead of running automatically whenever a website calls for a plugin function, they’ll be “click to play,” meaning the user will have to give permission for the plugin to run with each instance. According to Google and Mozilla, this new rule will apply to each and every browser plugin in existence on the entire planet, save one. Flash will still run automatically, requiring no prompt from the user. With Flash, it’ll be business as usual.

This has the look and smell of a business play all the way through, although that might not be immediately evident when reading what ad giant Google and open source Mozilla have to say. At first glance, their reasoning makes sense. Flash is just too darn ubiquitous. It’s everywhere; buried in everything. Including Flash in “click to play” would put too much of a burden on the user.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Breaking News: