Press "Enter" to skip to content

Posts published in “Web Apps”

Six WordPress Plugins Vulnerable

In the same week that we learned from W3Techs that the popular open source content management system (CMS) WordPress now powers a full 25 percent of all sites on the web, we learn that six popular WordPress plugins contain serious security vulnerabilities. The later news comes to us by way of security firm Wordfence, which specializes in WordPress security and develops the Wordfence security plugin for the platform.

** If our coverage matters to you, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

WordPress logoThis news isn’t surprising, nor is it cause for alarm. Because WordPress is by far the most popular content management platform on the web, it’s an obvious target for hackers, and third party plugins are the most obvious way inside. However, the folks at Automattic, which develops the platform, have proven themselves to be diligent at finding vulnerabilities and keeping them patched.

Linux Foundation Scales, Raspberry Music Pi & More…

FOSS Week in Review

Back to school, back to work, back to just about everything else free and open source this week: The temperatures could be a little cooler in California, but there’s a modicum of cool to go with the heat.

Like the following items in this week’s wrap…

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

Tipping the Scales for Linux: Sean Michael Kerner over at Datamation wrote an article accompanying a video interview with Linux Foundation executive director Jim Zemlin, who says, among other things, why the foundation is just going to keep growing.

Larry Cafiero

Larry Cafiero is a journalist and a Free/Open Source Software advocate and is involved in several FOSS projects. Follow him on Twitter: @lcafiero

Is Microsoft Enterprise Mobility a Trojan Horse?

It’s been easy to think that the FOSS world has little to worry about from Microsoft these days. By the time Steve Ballmer was forced out a few years back, the company seemed to be a basket case. Windows was becoming less relevant by the minute, many consumers were sparing themselves the expense of Office by adopting LibreOffice and OpenOffice and efforts to launch Windows Phone were going nowhere, even after Steven Elop drove Nokia to the brink of bankruptcy, allowing Redmond to purchase the Finnish company’s once unstoppable phone business at fire sale prices.

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

Microsoft logoAlthough some have been trying to sound the alarm, many of us have been lulled into complacency brought by a belief that Microsoft is no longer a real threat and that we are now free to concentrate all of our energies on growing Linux and FOSS, which is basically all we’ve wanted to do.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

phpMyAdmin Bids SourceForge Farewell

phpMyAdmin, the popular free and open source web based tool for administering MySQL databases, has left the SourceForge building.

In a blog post on Saturday, the project’s infrastructure coordinator, Michal Čihař, announced that a migration from Sourceforge is all but complete. The few remaining items left on the SourceForge server will be “hopefully handled in upcoming days as well.”

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

phpMyAdmin logoA popular web based application for administering MySQL databases, phpMyAdmin is the preferred tool of many webmasters for working with MySQL when used to power websites and is installed by default with most web hosting packages. The app can be used to perform a variety of tasks, including creating, modifying or deleting databases, tables, fields or rows; executing SQL statements; and managing users and permissions.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

SourceForge Not Making A Graceful Exit

If SourceForge were a person and I were the New York Times, I’d make certain I had an obituary on file right about now. It’s obvious that the once essential code repository for open source projects is terminally ill, although it’s just as obvious that Dice Holdings, which took over ownership of the site nearly three years ago, has no plans of letting SourceForge go gently into the good night, so we’ll probably see more kicking and noise-making until the lights are inevitably extinguished.

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

SourceForge logoNewer converts to open source probably don’t know much about the site, but it wasn’t long ago when Linux users were very aware of SourceForge and how to use the service, at least well enough to download software — perhaps more aware than they wanted to be. It was the go-to site when looking for a program not available in a particular distro’s repository. Not anymore. Not for a while. These days, the more important projects have either migrated to GitHub or are hosting their own.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

WordPress Upgraded to Fix Security Holes

Website publishers using the popular free and open source WordPress content management system (CMS) woke up this morning to find that their sites had been upgraded to version 4.2.2. Users who’s sites somehow missed being automatically upgraded are urged to update immediately, as this update addresses several important security issues. According to Wordfence, maintainers of a popular WordPress security plugin, this release fixes one recently discovered vulnerability and further hardens a security issue that was addressed in version 4.2.1.

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **
Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

WordPress Plugin ‘Simple Ads Manager’ Exploit

Anyone who runs sites using the WordPress platform and the plugin Simple Ads Manager will want to read this and learn from our mistake. Even those not using this particular plugin, but who have deactivated plugins not being used but still residing on their servers might find this useful. Luckily, in our case no harm was done, but that’s only because the incident occurred on a test site, so we were able to just take the site down. Lucky for us, it wasn’t FOSS Force or one of our other active sites.

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

Early Saturday evening we began receiving numerous email notices with two worrisome subject lines from our server. One subject was “LOCALRELAY Alert for sitename,” being sent to us at the rate of about every five minutes, with each showing info on the “first ten of 101 emails” that had been sent by the server since the last email notification. The other subject, “Script Alert for /path/to/script” was coming with the same frequency. To make a long story short, someone had hacked into a site we use to evaluate and test WordPress plugins before possibly deploying them on active sites, and was using it to send spam. Our test site had been turned into a spambot in other words.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Old News Anew: Fixing Zen Cart for SSL v3 Vulnerability

PayPal was supposed to have made the change on December 3, the date it announced as the target for no longer accepting secure connections from sites using SSL v3 instead of TLS. As I manage a Zen Cart site which uses PayPal’s express checkout as it’s only payment option, I checked with the server’s technical support staff to make sure we were covered. Yup. We got you set up with that, they said. I was good to go.

When December 3 came and went with the site continuing to take orders, I figured I had weathered the storm quite handily, although this seemed a little too easy to me.

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

Then came Monday night.

While I was away from home and office, sitting at a borrowed computer, I received a series of emails from PayPal, notifying me that a customer was making repeated unsuccessful attempts to place an order — unsuccessful because PayPal was refusing the handshake from the server. I easily recreated the problem by logging on to the site using a dummy customer account and attempting to make a purchase. At the point where the order was sent to PayPal, the process failed with a red letter warning saying something like “(35) error:14094410:SSL routines:func(148):reason(1040).” Not cool.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Netflix, Chrome, DRM & Other Nasties

Monday’s article on easy Netflix coming at last to Linux garnered a few polite responses, taking me to task for my enthusiasm for a “non-free” solution. The problems are that Netflix uses DRM and that currently its use on GNU/Linux requires the use of the proprietary Chrome browser. One commenter even questioned FOSS Force’s commitment to software freedom with the remark: “Your logo “Keeping Tech Free” I take it that means free beer and not freedom.”

** If you're finding this article useful, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

Netflix logoNope. I’m an advocate of free “as in speech” software — which includes the freedom to choose. If there’s a FOSS solution for something I need or want to do, I’ll take that every time, and encourage my friends to do so as well. However, if there’s something I need or want to do with no FOSS solution available, I might use a proprietary solution, depending on the depth of my need or want and on how draconian the terms of the proprietary EULA.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Don’t Fret Linus, Desktop Linux Will Slowly Gain Traction

When Linus Torvalds was asked last week at LinuxCon where he’d like to see Linux excel next, he replied, “I still want the desktop.”

I nearly stood up an cheered when I read this, here in my house nearly 700 miles from the conference. That is until I became confused by what he said next.

“The challenge on the desktop is not a kernel problem. It’s a whole infrastructure problem. I think we’ll get there one day.”

** If our coverage matters to you, please consider supporting our work through our FOSS Force Independence 2026 fundraiser. **

Linux Torvalds
Linus Torvalds at LinuxCon 2011 in São Paulo, Brazil
Photo by Beraldo Leal from Natal / RN, Brazil.
What? What challenge?

Of course there’s not a kernel problem. From where I sit, there’s not a GNU problem either. I’ve been using Mint with Xfce for a while now and I find it better than any version of Windows I’ve ever used, many times over. Other than needing a little polishing with some distros, there’s no problem whatsoever with the penguin. Desktop Linux is only the best there is.

However, if by “infrastructure problem” he means that consumers can’t rush down to the local Best Buy store and pick a new computer off the shelf that’s already been loaded with a carefully configured Linux distro, I agree. That is a problem. Right now, it’s the only thing keeping Linux from having decent user share. But I’m pretty darn sure that’s getting ready to change.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux