3 ms·
"...a weakness in an old install of WordPress...allowed the jerk to set up a phishing scam under my domain. I learned all of this from Bluehost, which hosts the
by synnik 16y ago
"...a weakness in an old install of WordPress...allowed the jerk to set up a phishing scam under my domain.
I learned all of this from Bluehost, which hosts the WordPress portion of my site."
When you log into Bluehost's control panel, and go to your installed apps, it immediately informs you whether or not you are up to date with the latest versions/patches. It has automated scripts to do the updates for you.
Either this author completely disregarded application security by not staying up to date, or he customized it so much that automated updates were not possible, but then did not maintain his own code.
Either way, and whether or not you agree with Yahoo's actions, the author needs to own his own responsibility for his apps.
- earl 16y agoOr, perhaps the author was tired of random wordpress updates breaking stuff and declined to install updates to a working system. Further, the wordpress people can't be arsed to indicate which updates are for security and which updates are for more stupid features. so unless you go through the release notes line by line for the software and all your plugins, it's very difficult to tell. More and more, the solution seems to be static files and disqus.
- synnik 16y agoThat is true, but that is exactly my point. If you choose to use a product like Wordpress, then you should also accept the maintenance that goes with that choice, tedious and annoying though it may be. Installing a product, running a business on it, but ignoring patches and updates is flat out unprofessional.
- paulgb 16y agoHow often does the average Bluehost customer go to that page of the panel? I rarely log into my control panel at all unless things are going wrong.