{"id":514,"date":"2011-09-26T00:00:00","date_gmt":"2011-09-26T04:00:00","guid":{"rendered":"http:\/\/www.hypnosisinmedia.com\/blog\/?p=514"},"modified":"2011-09-26T00:23:34","modified_gmt":"2011-09-26T04:23:34","slug":"security-issues","status":"publish","type":"post","link":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/","title":{"rendered":"Security Issues"},"content":{"rendered":"<p>\nTwo such issues, actually.&nbsp;<\/p>\n<p>\nWhen I recent\u00adly installed a SEO plu\u00adg\u00adin, it includ\u00aded a log of all \u201c404\u201d calls. Each \u201c404\u201d is a serv\u00ader response to an attempt to find a non-exis\u00adtence page the&nbsp;blog.&nbsp;<\/p>\n<p>\nOne of these issues involves a bla\u00adtant attempt to fish for spe\u00adcif\u00adic PHP files (the script\u00ading lan\u00adguage files that serve as the back\u00adground for the web\u00adsite) that have a known secu\u00adri\u00adty error. This file, named \u201ctimthumb.php\u201d is not present in the stan\u00addard Word\u00adPress instal\u00adla\u00adtion but it is includ\u00aded in some themes and plu\u00adg\u00adins, and is used to manip\u00adu\u00adlate screen image files. The intent is to use access to this file to bypass the web\u00adsite secu\u00adri\u00adty by tak\u00ading advan\u00adtage of this file\u2019s abil\u00adi\u00adty to write a any kind of file into the Word\u00adPress direc\u00adto\u00adry, after which the per\u00adson can use that file to gain access to the entire direc\u00adto\u00adry sys\u00adtem, upon which they are able to mod\u00adi\u00adfy exist\u00ading PHP files or install their own soft\u00adware&nbsp;there.&nbsp;<\/p>\n<p>\nFor\u00adtu\u00adnate\u00adly this web\u00adsite is not affect\u00aded: I don\u2019t have or use any oth\u00ader themes or plu\u00adg\u00adins which include that spe\u00adcif\u00adic file. How\u00adev\u00ader, the inter\u00admit\u00adtent, repeat\u00aded attempts to find this file does cause some load on the sys\u00adtem and are annoy\u00ading, which is why I am try\u00ading to block them any way I&nbsp;can.&nbsp;<\/p>\n<p>\nThe oth\u00ader issue involves the \u201cspi\u00adder\u201d robot, the web device that scans web\u00adsite sites for infor\u00adma\u00adtion and changes to web\u00adsites. All the major web search sites, like Google, Bing, Yahoo, etc., use them, and for the most part, they are well-behaved. But there is one that is not, and that\u2019s the Baidu spi\u00adder robot. Baidu is the major Chi\u00adnese web search site. Ever since I installed the \u201c404\u201d mon\u00adi\u00adtor, I have seen dozens, if not over a hun\u00addred, attempts a day of the Baidu spi\u00adder crawl\u00ading my blog and search\u00ading for a spe\u00adcif\u00adic, non-exis\u00adtent file under a com\u00adbi\u00adna\u00adtion of many dif\u00adfer\u00adent loca\u00adtions. Its almost as if the spi\u00adder robot pro\u00adgram is bad\u00adly designed and does\u00adn\u2019t under\u00adstand that is com\u00adplete\u00adly miss\u00ading the pic\u00adture&nbsp;here.&nbsp;<\/p>\n<p>\nWhat links these two issues is the fact that I have not been able to block either using the two com\u00admon web\u00adsite func\u00adtions \u201crobots.txt\u201d and \u201c.htac\u00adcess\u201d. The Baidu sys\u00adtem says that its spi\u00adder robot obeys the \u201crobots.txt\u201d file but oth\u00ader web com\u00admen\u00adtary insists that it does\u00adn\u2019t. The scan\u00adner that hunts for the \u201ctimthumb.php\u201d file prob\u00ada\u00adbly does\u00adn\u2019t either. That said, I have set the \u201crobots.txt\u201d file to dis\u00adal\u00adlow those two spi\u00adder robots, with\u00adout suc\u00adcess. This is what I am&nbsp;using:&nbsp;<\/p>\n<pre>\nUser-agent: Baiduspider\nDisallow: \/\nUser-agent: Baiduspider\/2.0\nDisallow: \/\nUser-Agent: PycURL\/7.19.7\nDisallow: \/\n<\/pre>\n<p>\nThe oth\u00ader func\u00adtion is to use the \u201c.htac\u00adcess\u201d file, which is a sys\u00adtem lev\u00adel direc\u00adtive to the serv\u00ader to ignore these robots accord\u00ading to the user agent name they give when attempt\u00ading to access the web\u00adsite. Unfor\u00adtu\u00adnate\u00adly, this tile is a lit\u00adtle more dif\u00adfi\u00adcult to code. This is what I have been rec\u00adom\u00admend\u00aded to&nbsp;use.&nbsp;<\/p>\n<pre>\n#Block bad bots\nSetEnvIfNoCase User-Agent \"^Baidu[Ss]pider\" bad_bot=1\nSetEnvIfNoCase User-Agent \"^PycURL\" bad_bot=1\nOrder Allow,Deny\nAllow from all\nDeny from env=bad_bot\n<\/pre>\n<p>\nUnfor\u00adtu\u00adnate\u00adly, it does\u00adn\u2019t appear to work, either. I don\u2019t know if this is a prob\u00adlem of cod\u00ading the restric\u00adtions or if the restric\u00adtion file is not in the cor\u00adrect places: this is an area that I have lit\u00adtle expe\u00adri\u00adence with. My web\u00adsite host cus\u00adtomer ser\u00advice has not been much help, either.&nbsp;<\/p>\n<p>\nIf any\u00adone has a sug\u00adges\u00adtion to make, feel free to respond.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two such issues, actu\u00adal\u00adly.&nbsp; When I recent\u00adly installed a SEO plu\u00adg\u00adin, it includ\u00aded a log of all \u201c404\u201d calls. Each \u201c404\u201d is a serv\u00ader response to an attempt to find\u2026<a href=\"https:\/\/www.hypnosisinmedia.com\/blog\/security-issues\/\" class=\"more-link\">\u21d2 Con\u00adtin\u00adue read\u00ading \u201cSecu\u00adri\u00adty Issues\u201d<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wp_typography_post_enhancements_disabled":false,"footnotes":"","_wp_rev_ctl_limit":""},"categories":[136],"tags":[],"class_list":["post-514","post","type-post","status-publish","format-standard","hentry","category-website-maintenance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Security Issues - Hypnosis in Media<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Issues - Hypnosis in Media\" \/>\n<meta property=\"og:description\" content=\"Two such issues, actually.&nbsp; When I recent\u00adly installed a SEO plu\u00adg\u00adin, it includ\u00aded a log of all \u201c404\u201d calls. Each \u201c404\u201d is a serv\u00ader response to an attempt to find&hellip;&rArr; Continue reading &quot;Security Issues&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/\" \/>\n<meta property=\"og:site_name\" content=\"Hypnosis in Media\" \/>\n<meta property=\"article:published_time\" content=\"2011-09-26T04:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2011-09-26T04:23:34+00:00\" \/>\n<meta name=\"author\" content=\"HypnoMedia\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@HypnoMedia\" \/>\n<meta name=\"twitter:site\" content=\"@HypnoMedia\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/\"},\"author\":{\"name\":\"HypnoMedia\",\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453\"},\"headline\":\"Security Issues\",\"datePublished\":\"2011-09-26T04:00:00+00:00\",\"dateModified\":\"2011-09-26T04:23:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/\"},\"wordCount\":566,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453\"},\"articleSection\":[\"Website Information and Maintenance\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/\",\"url\":\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/\",\"name\":\"Security Issues - Hypnosis in Media\",\"isPartOf\":{\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#website\"},\"datePublished\":\"2011-09-26T04:00:00+00:00\",\"dateModified\":\"2011-09-26T04:23:34+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.hypnosisinmedia.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Issues\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#website\",\"url\":\"https:\/\/www.hypnosisinmedia.com\/blog\/\",\"name\":\"Hypnosis in Media\",\"description\":\"All about hypnosis and related subjects in the media\",\"publisher\":{\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.hypnosisinmedia.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453\",\"name\":\"HypnoMedia\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.hypnosisinmedia.com\/blog\/wp-content\/uploads\/2010\/09\/cropped-Hypnoeyes1.jpg\",\"contentUrl\":\"https:\/\/www.hypnosisinmedia.com\/blog\/wp-content\/uploads\/2010\/09\/cropped-Hypnoeyes1.jpg\",\"width\":512,\"height\":512,\"caption\":\"HypnoMedia\"},\"logo\":{\"@id\":\"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"Gentleman Adventurer Author, Editor, Photographer, Videographer, Hypnotist, Programmer, Philosopher, Drone Pilot he \/ him \/ his\",\"sameAs\":[\"http:\/\/www.terryobrien.me\",\"https:\/\/x.com\/HypnoMedia\"],\"url\":\"https:\/\/www.hypnosisinmedia.com\/blog\/author\/hypnomedia\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Issues - Hypnosis in Media","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/","og_locale":"en_US","og_type":"article","og_title":"Security Issues - Hypnosis in Media","og_description":"Two such issues, actually.&nbsp; When I recent\u00adly installed a SEO plu\u00adg\u00adin, it includ\u00aded a log of all \u201c404\u201d calls. Each \u201c404\u201d is a serv\u00ader response to an attempt to find&hellip;&rArr; Continue reading \"Security Issues\"","og_url":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/","og_site_name":"Hypnosis in Media","article_published_time":"2011-09-26T04:00:00+00:00","article_modified_time":"2011-09-26T04:23:34+00:00","author":"HypnoMedia","twitter_card":"summary_large_image","twitter_creator":"@HypnoMedia","twitter_site":"@HypnoMedia","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#article","isPartOf":{"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/"},"author":{"name":"HypnoMedia","@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453"},"headline":"Security Issues","datePublished":"2011-09-26T04:00:00+00:00","dateModified":"2011-09-26T04:23:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/"},"wordCount":566,"commentCount":0,"publisher":{"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453"},"articleSection":["Website Information and Maintenance"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/","url":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/","name":"Security Issues - Hypnosis in Media","isPartOf":{"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#website"},"datePublished":"2011-09-26T04:00:00+00:00","dateModified":"2011-09-26T04:23:34+00:00","breadcrumb":{"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.hypnosisinmedia.com\/blog\/514\/security-issues\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hypnosisinmedia.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security Issues"}]},{"@type":"WebSite","@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#website","url":"https:\/\/www.hypnosisinmedia.com\/blog\/","name":"Hypnosis in Media","description":"All about hypnosis and related subjects in the media","publisher":{"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hypnosisinmedia.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/eaa6b1fa89a45ff8994969d037809453","name":"HypnoMedia","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-content\/uploads\/2010\/09\/cropped-Hypnoeyes1.jpg","contentUrl":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-content\/uploads\/2010\/09\/cropped-Hypnoeyes1.jpg","width":512,"height":512,"caption":"HypnoMedia"},"logo":{"@id":"https:\/\/www.hypnosisinmedia.com\/blog\/#\/schema\/person\/image\/"},"description":"Gentleman Adventurer Author, Editor, Photographer, Videographer, Hypnotist, Programmer, Philosopher, Drone Pilot he \/ him \/ his","sameAs":["http:\/\/www.terryobrien.me","https:\/\/x.com\/HypnoMedia"],"url":"https:\/\/www.hypnosisinmedia.com\/blog\/author\/hypnomedia\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/posts\/514","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/comments?post=514"}],"version-history":[{"count":0,"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/posts\/514\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/media?parent=514"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/categories?post=514"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hypnosisinmedia.com\/blog\/wp-json\/wp\/v2\/tags?post=514"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}