Wednesday, 25 December 2013

3 Sneaky Tricks Hackers Use to Target WordPress Sites

hacker-cartoon
The open source nature of WordPress has one downside, and if you’re not careful it could ruin your online business. I know this because it happened to me. Just a few months ago, I had a hacker hijack a WordPress site that was consistently earning me several hundred dollars a month.
The hacker:
  • Blocked all logins from my IP address
  • Deleted 217 pages of content, including over 50 pages of premium membership content.
  • Posted 182 spam articles on my site, all which were visible from the home page and which tanked my search engine rankings.
  • Changed the admin account to their email so that I could not update my password OR get back into the site

Thankfully, with a little research and my newly acquired knowledge of PHP MYSQL programming, I discovered three easy-to-correct vulnerabilities that I now believe every WordPress blogger needs to know about…
#1: Vulnerability to “Brute Force” Logins

Brute force logins are also called “cracks.”
A crack is when a hacker builds a program that generates thousands of new random passwords per minute and attempts to login to your application by stumbling upon the right combination. For example, let’s assume the hacker already knows that your primary username is “admin.”
All they need to do is crack the password using their trusty automated crack program. The program might start out its first 10 attempts by inputting:
1.     aaa111
2.     aaa112
3.     aaa113
4.     aaa114
5.     aaa115
6.     aaa116
7.     aaa117
8.     aaa118
9.     aaa119
10.   aaa120
As you can imagine, this would take ages without the assistance of a computer. But even the most amateur hackers have access to cracking tools, so you need to make your site as “crack proof” as possible.
(More on that in a second)
#2: Vulnerability to DNS Snooping

If your domain is publicly listed (check with your domain host) and hosted on a shared server, any hacker can use whois.com to find out who you’re hosted with, as well as information about your DNS server AND what other sites are hosted on the same server as yours.
They can also ping your site for the IP Address, feed it into sameip.org and come up with a list of the sites being co-hosted with yours.
If they can’t find a security hole in your WordPress site, they can still hack into the server if they find vulnerabilities on other sites hosted on the same server.
What they can do with this information will depend on their skill level and how much spare time they have between live action role playing games. Any reasonably experienced and moderately persistent hacker could:
1.     Use SQL injections to insert content (blog posts, etc) into your WordPress database and have it display on your WordPress site.
2.     Drop (i.e. delete) your entire WordPress database.
3.     Decode your user’s passwords (including yours) by reverse engineering the algorithm used to encrypt them.*
*Common encryption algorithms  such as MD5 and SHA are used in WordPress scripts and commonly known in the hacker world.
Again, we’ll cover a few precautions you can take to prevent this from happening, but it’s important that you know how your site may be at risk…
#3: Vulnerability to Plugin Hijacking

Right now you probably have at least a few WordPress plugins installed which are not up to date. Some of them aren’t even being updated by the developer anymore. This is a major security hole, especially if you’re receiving updates about the plugin in through your WordPress dashboard.
Those updates are likely being reported to you by a script that’s running on your server called a “cron job.” If a hacker discovers the “doorway” which that script is using to communicate with your WordPress site, they can create their own scripts that can interact or make changes to your WordPress site.
How easy is this?
First, the hacker finds a couple of WordPress plugins which are known to be out of date and which (at least at one time) installed a cron job on the host server. Then, they use a search program (similar to a spider) to harvest all the WordPress sites that have that plugin currently installed.
Once they’ve got that information, they can use a vulnerability in the plugin itself to access your WordPress scripts and, in some cases, your configuration file.
From there, they’ve got a buffet of options for turning the WordPress site you’ve worked so hard to build into a cesspool of spam articles…or  into barren wasteland, devoid of all your well-written content.
So, now that I’ve got you scared and aware about these vulnerabilities, here’s what you can do about them…
Checklist for Closing Up Known WordPress Security Holes
  1. NEVER leaving the generic username “admin” as your primary WordPress username, doing so makes it too easy to crack your WordPress admin password.
  2. Create an admin username password which are less memorable, but more secure than your current ones. For example, instead of using  something like your last name and date of birth, use a randomly generated password with numbers and letters and write it down somewhere that you can access it quickly.
  3. Don’t publicly display your WordPress username, create a nickname instead. You can do this from your WordPress profile in your admin dashboard).
  4. Limit the number of IPs users can login from in order to prevent brute force login attempts. Most WordPress membership plugins can do this, including the WPMU DEV plugins.
  5. Change your domain listing to private, if customers want to find out more about you and your company, create an information page for them.
  6. Get your own dedicated server as soon as financially possible.
  7. Have your web developer create a login script that limits failed login attempts and reports any suspicious logins to you. These are fairly easy to create, I built one in just 40 hours.
  8. Keep your WordPress plugins up to date with your current version of WordPress. Don’t use plugins which aren’t being maintained by the developer. I suggest becoming a Premium Member of WPMU DEV to permanently solve this problem.
  9. Avoid free WordPress themes and plugins at all costs, unless they’re being provided by someone who also sells premium products. People who are being paid for their work are more likely to stay on top of maintaining it. Again, I suggest you check out WPMU DEV.
  10.  If at all possible, use a Gmail account for your admin login rather than one attached to your domain name. This way it will be harder for hackers to guess the primary admin email for your domain.
  11.  Only run cron jobs which are 100% necessary for maintaining your WordPress site. Most cron jobs can be turned off from your cpanel, just make sure you don’t turn off one that you really need. See your web hosting company about this if you’re unsure.
Anymore questions or comments?
Post them here. I check reader feedback every day.
Happy and safe blogging my friends!

for more detail visit
http://premium.wpmudev.org/blog/3-sneaky-tricks-hackers-use-to-target-wordpress-sites/

DHOOM MACHALE DHOOM LYRICS - Dhoom 3

Katrina Kaif in Dhoom 3
Dhoom Machale Lyrics from Dhoom 3: The Title song of Dhoom 3 is finally here, The song is sung by Aditi Singh Sharma, composed by Pritam with lyrics penned by Sameer Anjaan.
Song: Dhoom Machale Dhoom
Singer: Aditi Singh Sharma
Music: Pritam
Lyrics: Sameer Anjaan
Cast: Aamir Khan, Katrina Kaif, Abhishek Bachchan, Uday Chopra
Music on: YRF Music

 

Dhoom Machale Dhoom Lyrics

You know that thing must be the hundred years old!

Dhoom Dhoom, Sar chadhi hai
Dhoom Dhoom, Bekhudi hai
Dhoom Dhoom, Race mein gum ho ja
One minute...

Dhoom Dhoom, khalbali hai
Dhoom Dhoom, har gali hai
Dhoom Dhoom, race mein tu kho ja

Dhoom nashaa hai
Dhoom junoon hai
Dhoom hai hulchul
Dhoom sukoon hai
Aaj tu sab kuchh bula ke jhoooom
Dhoom Machale...

We rock it, we roll it
So come on you people

Dhoom Machale, Dhoom Machale..
Dhoom Machale, Dhoom Machale..
Dhoom Machale, Dhoom Machale, Dhoom.. (x2)

Dhoom Dhoom, jism-o-jaan mein
Dhoom Dhoom, ho jahaan mein
Dhoom Dhoom, josh woh bhar ja
Let's Go!
Dhoom Dhoom, Har zubaan pe
Dhoom Dhoom, Zikr tera
Dhoom Dhoom, aisa kuchh kar ja

Ho... dhoom sharara
Dhoom ishara
Dhoom o yaara
Dhoom dobaara
Aaja dil se dil milake jhooooom...
C'mon...

Dhoom Machale...
We rock it, we roll it
You ready to party!

Dhoom Machale, Dhoom Machale..
Dhoom Machale, Dhoom Machale..
Dhoom Machale, Dhoom Machale Dhoom.. (x2)

Kar na fikar tu kal ki
Lutf le aaj ka
Zindagi hai bas do pal ki
Ek ek pal chura
Jee bhar ke jee le, jee le
Gham dhuein mein uda
Dhoom macha macha macha...

It's time now for a big big DHOOM!

Dhoom Machale, Dhoom Machale..
Dhoom Machale, Dhoom Machale..
Dhoom Machale, Dhoom Machale Dhoom.. (x2)

GOD, ALLAH aur BHAGWAN LYRICS - Krrish 3 | Sonu Nigam, Shreya Ghoshal

God Allah aur Bhagwan - Krrish 3
God Allah aur Bhagwan Lyrics from Krrish 3: A song that praises Krrish, sung by Sonu Nigam & Shreya Ghoshal, composed by Rajesh Roshan with lyrics penned by Sameer.
Song: God, Allah aur Bhagwan
Singers: Sonu Nigam, Shreya Ghoshal
Music: Rajesh Roshan
Lyrics: Sameer Anjaan
Cast: Hrithik Roshan, Priyanka Chopra, Kangana Ranaut, Vivek Oberoi, Rekha
Music on: T-Series

God Allah aur Bhagwan Lyrics

God, Allah aur Bhagwan
Ne banaya ik insaan

God, Allah aur Bhagwan
Ne banaya ik insaan
Aaya zameen pe lekar woh
Upar waale ka farmaan
Woh doston ka hai dost
Yaaron ka hai yaar
Jiska naam sunke kaanpe har shaitan (x2)

God, Allah aur Bhagwan
Ne banaya ek insaan

Woh tujhme bhi hai
Woh mujhme bhi hai
Kahin na kahin woh
Hum sab mein hai (x2)

Sab mein woh chhupa hai
Usey pehchaan le
Uska jo iraada hai
Hum thaan lein (x2)

Woh doston ka hai dost
Yaaron ka hai yaar
Jiska naam sunke kaanpe har shaitan

God, Allah aur Bhagwan
Ne banaya ek insaan (x2)

Jahaan kal woh tha akela khada
Kadam apna bhi udhar chal pada (x2)

Dil ke khabon ki jannat sajayenge hum
Pyar ka savera leke aayenge hum (x2)

Woh doston ka hai dost
Yaaron ka hai yaar
Jiska naam sunke kaanpe har shaitan

God, Allah aur Bhagwan
Ne banaya ek insaan (x2)

Read more: http://www.lyricsmint.com/2013/09/god-allah-aur-bhagwan-krrish-3.html#ixzz2oVqPcfQY

RAGHUPATI RAGHAV Lyrics - Krrish 3 Song

Raghupati Raghav - Hrithik Roshan & Priyanka Chopra in Krrish 3
Raghupati Raghav Lyrics from Krrish 3: The first song from Krrish 3 Raghupati Raghav Raja Ram is here which features Hrithik Roshan dancing with Priyanka Chopra. The song is composed by Rajesh Roshan and sung by Neeraj Shridhar, Monali Thakur & Bob.
Song: Raghupati Raghav
Singers: Neeraj Shridhar, Monali Thakur, Bob
Music: Rajesh Roshan
Lyrics: Sameer Anjaan
Cast: Hrithik Roshan, Priyanka Chopra, Kangana Ranaut, Vivek Oberoi, Rekha
Music on: T-Series

 

 

Raghupati Raghav Lyrics

Sabse haseen hai
Sabse juda hai
Woh dekho meri jaan

Pyaar ke liye hi duniya bani hai
Pyaar ka mila inaam

Raghupati Raghav...

Raghupati Raghav RajaRam
Raghupati Raghav RajaRam
Non-stop party
Aaj ki party
Celebrations tere naam (x2)

Raghupati Raghav Raja Ram
Raghupati Raghav Raja Ram
(Raghupati Raghav, Raghav....)

Kya raat hai, kya baat hai
Meri zindagi mere saath hai
Na chain hai na hosh
Har aarzoo madhosh hai

Maangi dua jo kabhi tere mere lab ne
Jaane tmanna poori ki usey Rab ne
Kaise karoon main shukriya
Raghupati Raghav
Raghupati Raghav
Raghupati Raghav Raja Ram
Non-stop party
Aaj ki party
Celebrations tere naam
Raghupati Raghav Raja Ram
Raghupati Raghav Raja Ram

What a groove!
I wanna move
Check it out!
Na na na na...

Rangon se bhi rangeen hai
Yeh pal bada namkeen hai
Phir ye samaa na aayega
Phir ye nasha na chhayega

Raina bhi khwabon ke charagon se saji hai
Mere khayalon mein bhi dhoom machi hai
Behke huey hai armaan

Hola Amigo!
Hola Amigo!
Hola Amigo, sabko salaam..
Hola Amigo, sabko salaam..
(Hola Amigo means "hello friend" in Spanish)

Raghupati Raghav Raja Ram
Raghupati Raghav Raja Ram (x2)

Non-stop party
Aaj ki party
Celebrations tere naam
Raghupati Raghav Raja Ram
Raghupati Raghav!

Raghupati Raghav!

Raghupati Raghav..
Raghupati Raghav....

Read more: http://www.lyricsmint.com/2013/09/raghupati-raghav-krrish-3.html#ixzz2oVpYF1Hn

Saturday, 21 December 2013

What is HTML 5?

HTML5 will be the new standars for HTML.

The previous version of HTML,HTML 4.01,came in 1999. The internet has changes significantly since then.
HTML5 is intended to subsume not only HTML 4,but also XHTML 1 and DOM Level 2 HTML.

HTML5 is designed to deliver almost everything you want to online without requiring plugin. it does everything from animation to apps, music to movies, and can also be build complicated applications that run in your browser.

HTML 5 is platform Independence so don't worry about platform. the HTML 5 is running every where like all browser,Phone,Tablet etc...

you can build a mobile apps and games in HTML5. the HTML5 provide many interface to create graphice and animation in HTML5 is easy.