Results 1 to 19 of 19
  1. #1
    The Buzz's Avatar
    The Buzz is offline GPWA Gossip Hound
    Join Date
    February 2007
    Location
    Newton, MA
    Posts
    4,478
    Thanks
    454
    Thanked 2,029 Times in 1,268 Posts

    Default WordPress getting a face lift

    VentureBeat says that the new version of WordPress to be released soon is to be the "best WordPress yet."

    (Automattic founder Matt Mullenweg) said WordPress 3.7 will be coming out in October with security and language features, and 3.8 development starts tomorrow with a release scheduled for December. The Twenty Fourteen theme, a magaziney visual extravaganza, should be released before the end of 2013 and will feature a lot of premium-like features.
    http://venturebeat.com/2013/07/27/br...wordpress-yet/

  2. The Following User Says Thank You to The Buzz For This Useful Post:


  3. #2
    LukeC is offline Non-sponsor Affiliate Program
    Join Date
    October 2012
    Location
    Birmingham, UK
    Posts
    495
    Thanks
    49
    Thanked 122 Times in 49 Posts

    Default

    Sounds promising but hopefully it won't cause too many compatibility issues.
    Head of Affiliates at Digital Fuel

  4. #3
    ocreditor's Avatar
    ocreditor is offline Private Member
    Join Date
    April 2009
    Location
    Israel
    Posts
    7,354
    Blog Entries
    1
    Thanks
    7,103
    Thanked 4,343 Times in 2,836 Posts

    Default

    Hope so.

  5. #4
    rak's Avatar
    rak
    rak is offline Former AM
    Join Date
    January 2011
    Location
    Philippines
    Posts
    1,123
    Thanks
    250
    Thanked 334 Times in 258 Posts

    Default

    please.. please.. please.. keep the same hooks for plugins. I really don't want to spend time re-writing my custom plugins, widget and themes.

    With every major update, they usually change the database structure somehow.

    I got a feeling, there might be some social media integration with this release. Possibly blog stats as well.

  6. #5
    edgarf76's Avatar
    edgarf76 is offline Private Member
    Join Date
    March 2013
    Location
    Montreal
    Posts
    2,196
    Thanks
    804
    Thanked 582 Times in 429 Posts

    Default

    Quote Originally Posted by rak View Post
    please.. please.. please.. keep the same hooks for plugins. I really don't want to spend time re-writing my custom plugins, widget and themes.

    With every major update, they usually change the database structure somehow.

    I got a feeling, there might be some social media integration with this release. Possibly blog stats as well.
    I do not get why they keep making these updates. The last update helped the photos a bit but it really did not do much. If there is social plugins that is good but almost every wordpress user has 3rd party plugins already. I think it would be bettor to keep the same version if there is nothing wrong with it.
    Visit Play Slots 4 Real Money and Casino Slots Money for trusted recommendations and tips on the best casinos.

  7. #6
    DaftDog's Avatar
    DaftDog is offline Private Member
    Join Date
    October 2008
    Location
    South Africa
    Posts
    2,162
    Thanks
    697
    Thanked 779 Times in 467 Posts

    Default

    Quote Originally Posted by edgarf76 View Post
    I do not get why they keep making these updates. The last update helped the photos a bit but it really did not do much. If there is social plugins that is good but almost every wordpress user has 3rd party plugins already. I think it would be bettor to keep the same version if there is nothing wrong with it.
    It's called evolution. Imagine if we had stopped evolving once our ancestors had invented fire.

  8. The Following User Says Thank You to DaftDog For This Useful Post:

    -Shay- (31 July 2013)

  9. #7
    ocreditor's Avatar
    ocreditor is offline Private Member
    Join Date
    April 2009
    Location
    Israel
    Posts
    7,354
    Blog Entries
    1
    Thanks
    7,103
    Thanked 4,343 Times in 2,836 Posts

    Default

    By the way, to anyone using wordpress beware of the link spammers that knows how to hack to the wordpress admin and plant in the site header a bulk of fishy outgoing links. Its hidden and the only way to find it is by doing view source.
    There are several solutions for this problem on the web.

  10. #8
    DaftDog's Avatar
    DaftDog is offline Private Member
    Join Date
    October 2008
    Location
    South Africa
    Posts
    2,162
    Thanks
    697
    Thanked 779 Times in 467 Posts

    Default

    If you have the current version of WordPress this should not be a problem. Sometimes dodgy plug-ins have a backdoor that allow hackers in. Any semi experienced affiliate who uses WordPress should be aware by now that using "admin" as a user-name, along with a weak password, is a grave security threat.

  11. #9
    AffMike76 is offline New Member
    Join Date
    April 2012
    Posts
    3
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Default

    That's right!!!

  12. #10
    ocreditor's Avatar
    ocreditor is offline Private Member
    Join Date
    April 2009
    Location
    Israel
    Posts
    7,354
    Blog Entries
    1
    Thanks
    7,103
    Thanked 4,343 Times in 2,836 Posts

    Default

    Quote Originally Posted by Ixian View Post
    ...WordPress should be aware by now that using "admin" as a user-name, along with a weak password, is a grave security threat.
    Not sure its enough, always good to have a strong pass but you also need to get rid of the dodgy plugins and maybe block access to admin by IP and leave several or single approved.

  13. #11
    rak's Avatar
    rak
    rak is offline Former AM
    Join Date
    January 2011
    Location
    Philippines
    Posts
    1,123
    Thanks
    250
    Thanked 334 Times in 258 Posts

    Default

    Quote Originally Posted by ocreditor View Post
    Not sure its enough, always good to have a strong pass but you also need to get rid of the dodgy plugins and maybe block access to admin by IP and leave several or single approved.
    Agreed! Ideally you'd want admin login to work via IP. If admin enters correct user and pass, from a different IP as its last IP - sends an email to add that IP to the "accepted" list. User clicks link on email to add IP to the database.

    But the dodgy plugins is where its at. You just need to find one which is poorly coded, doesn't use the hooks, sql injection, and you're in all sorts or trouble.

  14. #12
    edgarf76's Avatar
    edgarf76 is offline Private Member
    Join Date
    March 2013
    Location
    Montreal
    Posts
    2,196
    Thanks
    804
    Thanked 582 Times in 429 Posts

    Default

    Quote Originally Posted by rak View Post
    Agreed! Ideally you'd want admin login to work via IP. If admin enters correct user and pass, from a different IP as its last IP - sends an email to add that IP to the "accepted" list. User clicks link on email to add IP to the database.

    But the dodgy plugins is where its at. You just need to find one which is poorly coded, doesn't use the hooks, sql injection, and you're in all sorts or trouble.
    How can you tell where the last IP login was?
    Visit Play Slots 4 Real Money and Casino Slots Money for trusted recommendations and tips on the best casinos.

  15. #13
    rak's Avatar
    rak
    rak is offline Former AM
    Join Date
    January 2011
    Location
    Philippines
    Posts
    1,123
    Thanks
    250
    Thanked 334 Times in 258 Posts

    Default

    Quote Originally Posted by edgarf76 View Post
    How can you tell where the last IP login was?
    Store in a custom table in Wordpress.
    Eg

    If admin logged in successfully - thats check #1

    Check the current users IP against one stored in the database for user admin
    if they match.. continue successfully to admin panel - check #2

    if not match, send an email to email address associated with the account with link to add the new IP Address.

    Admin user clicks on link in email - it adds the users IP to some custom table in WP.

    Admin user now tries to log into the panel, and it should be successful, as their IP is in the table, it matches their IP.

    Thats what WP should be doing. I'm not sure if its possible to create a plugin which adds a step for check #2 - but with how flexible WP has become, it wouldn't surprise me.
    Last edited by rak; 31 July 2013 at 11:42 am. Reason: sperring

  16. The Following User Says Thank You to rak For This Useful Post:

    edgarf76 (31 July 2013)

  17. #14
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,977
    Thanks
    4,537
    Thanked 9,295 Times in 5,979 Posts

    Default

    You could probably just as easily protect the admin folder with a username and password.

    In that manner you couldn't even access the login page without the webserver authenticating the user. I guess you could also possibly do an ip check, although I would have to think about how to do that.

    Rick
    Universal4

  18. The Following User Says Thank You to universal4 For This Useful Post:

    edgarf76 (31 July 2013)

  19. #15
    Pmig is offline Private Member
    Join Date
    August 2012
    Posts
    189
    Thanks
    48
    Thanked 78 Times in 55 Posts

    Default

    I give up wordpress long time ago, switched to drupal and never look back again (on all my network only have 2 wp sites).

    drupal have a huge learning curve, but once you learning it worth every single second you take studding...

  20. #16
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,977
    Thanks
    4,537
    Thanked 9,295 Times in 5,979 Posts

    Default

    Here are a few plugins that might do the trick.
    http://wordpress.org/plugins/limit-login-attempts/
    http://wordpress.org/plugins/restricted-site-access/
    http://wordpress.org/plugins/whiteli...ogin-attempts/

    Please understand I know nothing about any of those plugins and am not endorsing any of them, but offered as something that might work. If anyone has any personal experience with them or others, let us know.

    I am a firm believer in using security methods that are server-based when possible, instead of depending on a third party plugin or program since that adds more overhead.

    Making a few quick searches I see it is fairly easy to do in IIS 7, and workarounds available in IIS 6. (this means no database queries are needed, and if the ip doesn't pass, you won't even see the page requested) My guess is you could do something similar with ht access on a Apache server.

    Rick
    Universal4

  21. The Following User Says Thank You to universal4 For This Useful Post:

    edgarf76 (31 July 2013)

  22. #17
    sweetbet's Avatar
    sweetbet is offline Public Member
    Join Date
    November 2012
    Posts
    2,824
    Blog Entries
    5
    Thanks
    898
    Thanked 1,574 Times in 1,086 Posts

    Default

    I'm looking forward to it. I love wordpress.

  23. #18
    ocreditor's Avatar
    ocreditor is offline Private Member
    Join Date
    April 2009
    Location
    Israel
    Posts
    7,354
    Blog Entries
    1
    Thanks
    7,103
    Thanked 4,343 Times in 2,836 Posts

    Default

    Thanks for sharing !

  24. #19
    xecutable's Avatar
    xecutable is offline Private Member
    Join Date
    March 2011
    Location
    Zurich, Switzerland
    Posts
    1,979
    Thanks
    583
    Thanked 1,225 Times in 708 Posts

    Default

    Finally took the step to update after a few days of that message showing up. Nothing got broken, various plugins were updated and all worked out fine. To be honest I didn't see much difference.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •