January 20th, 2009

The site was attacked again, this time a Phishing netbank login screen was posted in one of my upload folders. So much for Dynamic content! The IP addresses of the attacker are in New Dehli, India. Suspiciously that is exactly where my horrible hosting service Powweb is located. The day before the attack I had complained to them about the poor service and price hikes.

Powweb has a statement “One plan, One price” of 7.77 monthly on their main page. I had been paying that times seven for the sites I host. This year they decided since selling out to India and outsourcing that a 20 percent price increase was justified. After a horrible email battle the final reply from customer service was this: “We are sorry to inform you that we are unable to honor the rates that we have posted on our website.”

The previous successful hack was in May 2006.


    With WordPress, watch for cross site scripting attacks. This leads to the very annoying necessity of continually making sure all your WordPress installs are up-to-date. Occasionally search google for site:popsynth.com casino or some marketing term that they can’t resist. In the worst case, you’ll see some link spam showing up on google, but it’s not in the source of your pages and it’s not in the google cache. Also, I had a slash in the title of a post and it was continually targeted by spammers. I finally removed the slash and it settled down for some reason. Also, install Akismet if you haven’t.

    The new administration screens of WP are awesome! I have other WP installs out there that the custom themes I wrote will break if I update them. It is time to bite the bullet and fix all those.

