<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JK's Journal &#187; Website News</title>
	<atom:link href="http://www.planetjk.com/journal/category/website-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.planetjk.com/journal</link>
	<description>The good thing about opinions is that they don't have to be backed up with facts</description>
	<lastBuildDate>Tue, 29 Nov 2011 01:47:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Europe 2010: Screwed Up Captions</title>
		<link>http://www.planetjk.com/journal/2010/09/europe-2010-screwed-up-captions/</link>
		<comments>http://www.planetjk.com/journal/2010/09/europe-2010-screwed-up-captions/#comments</comments>
		<pubDate>Sun, 12 Sep 2010 19:08:44 +0000</pubDate>
		<dc:creator>JK</dc:creator>
				<category><![CDATA[Home Svelte Home]]></category>
		<category><![CDATA[Website News]]></category>

		<guid isPermaLink="false">http://www.planetjk.com/journal/?p=695</guid>
		<description><![CDATA[We landed yesterday evening, we&#8217;re back in the States. The trip was amazing! Yesterday we relaxed and spent time with the cat; today is unpacking, errands, chores, etc (and the first Redskins game!). As I&#8217;ve mentioned, I also want to blog the trip and get photos up soon, before I get caught up in other [...]]]></description>
			<content:encoded><![CDATA[<p>We landed yesterday evening, we&#8217;re back in the States.  The trip was amazing!  Yesterday we relaxed and spent time with the cat; today is unpacking, errands, chores, etc (and the first Redskins game!).</p>
<p>As I&#8217;ve mentioned, I also want to blog the trip and get photos up soon, before I get caught up in other To Do&#8217;s.  In attempting to do so today, I&#8217;ve learned that when <a href="http://gallery.menalto.com/wiki/Gallery_Remote">Gallery Remote</a> asks for a caption it really wants a filename.  So I&#8217;ve been putting lengthy &#8220;captions&#8221; into fields that are only sized to fit filenames, truncating a lot of the text in the photo album.  I&#8217;m annoyed, so I thought I&#8217;d vent here.  I&#8217;m going back to fix it, but it&#8217;ll take some time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.planetjk.com/journal/2010/09/europe-2010-screwed-up-captions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website CMS Quandary</title>
		<link>http://www.planetjk.com/journal/2010/01/website-cms-quandary/</link>
		<comments>http://www.planetjk.com/journal/2010/01/website-cms-quandary/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 07:40:50 +0000</pubDate>
		<dc:creator>JK</dc:creator>
				<category><![CDATA[Home Svelte Home]]></category>
		<category><![CDATA[Website News]]></category>
		<category><![CDATA[xTreme G33k]]></category>

		<guid isPermaLink="false">http://www.planetjk.com/journal/?p=625</guid>
		<description><![CDATA[I&#8217;ve been considering redesigning PlanetJK for at least a year now. I&#8217;ve been truly considering it for about 3 months. One of the main problems I run into is Content vs. Aesthetics. I could justifiably ramble on for a long time about that topic alone, but realistically speaking I just want to focus on telling [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been considering redesigning PlanetJK for at least a year now.  I&#8217;ve been <em>truly</em> considering it for about 3 months.  One of the main problems I run into is Content vs. Aesthetics.  I could justifiably ramble on for a long time about that topic alone, but realistically speaking I just want to focus on telling what I&#8217;m <em>trying</em> to do and go from there.</p>
<p>I&#8217;m immensely proud of the fact that the current design exists because of me manually coding PHP, CSS, and XHTML 1.1 Transitional files.  I have my own homegrown template system that allows me to change the code on one include file and affect the entire site, whether it be menu, header, footer, content, or overall layout.  Alas, the time to maintain such a setup eroded years ago, and I&#8217;ve been limping along ever since.  It&#8217;s time to focus on content.</p>
<p>I really like WordPress as a blogging platform- I&#8217;ve been using it for years, and the backend is easily maintainable using <a href="http://wiki.dreamhost.com/One_Click_Installs">DreamHost&#8217;s One-Click</a> options.  But now that I&#8217;m trying to incorporate WordPress as the sole website publisher/ controller/ editor/ etc, I find myself wanting assurances that it will be stable, secure, and work solidly for what I need.</p>
<p>Unfortunately, as an IT Security guy, I also know that WordPress has the potential to be more vulnerable than other CMS&#8217;.  And yes, I know that virtually EVERYTHING is rife with vulnerabilities: the <a href="http://alexking.org/blog/2010/01/08/wordpress-security-upgrades-backups">debate</a> is fierce and will <a href="http://wpgarage.com/news-views/is-wordpress-security-vulnerable-at-its-core/">thrive</a> for some time.  At the same time, Zope and Plone have been relatively safe from exploits- yet, they&#8217;re much tougher to customize <strong>the way I want.</strong></p>
<p>In the end, getting things the way I want is my first priority, so for now I&#8217;m strongly leaning toward WordPress.  A very close second is being safe from exploits.  Wish me luck in finding the appropriate level of compromise.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.planetjk.com/journal/2010/01/website-cms-quandary/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Summary of PlanetJK exploit attempts</title>
		<link>http://www.planetjk.com/journal/2010/01/summary-of-planetjk-exploit-attempts/</link>
		<comments>http://www.planetjk.com/journal/2010/01/summary-of-planetjk-exploit-attempts/#comments</comments>
		<pubDate>Sat, 09 Jan 2010 12:16:37 +0000</pubDate>
		<dc:creator>JK</dc:creator>
				<category><![CDATA[Home Svelte Home]]></category>
		<category><![CDATA[Website News]]></category>
		<category><![CDATA[xTreme G33k]]></category>

		<guid isPermaLink="false">http://www.planetjk.com/journal/?p=618</guid>
		<description><![CDATA[Jan 31, 2010: Made status updates below. In this post I&#8217;m taking rough notes of what appear to be attempted exploits against planetjk.com. I&#8217;m noting these partially for my benefit, so I can keep a log of things to potentially upgrade/mitigate. I have a CSV file of traffic (currently logging the last 20 months) for [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><strong>Jan 31, 2010: Made status updates below.</strong></p></blockquote>
<p>In this post I&#8217;m taking rough notes of what appear to be attempted exploits against planetjk.com.  I&#8217;m noting these partially for my benefit, so I can keep a log of things to potentially upgrade/mitigate.</p>
<p>I have a CSV file of traffic (currently logging the last 20 months) for cumulative analysis, but I couldn&#8217;t get Open Office to quickly trim out my home and work IP&#8217;s so right now I&#8217;m just eyeballing the data.</p>
<p>For a bit of a visual, here&#8217;s the visitor traffic broken down by country, courtesy of <a href="http://haveamint.com">Mint</a>:<br />
<a href="http://www.planetjk.com/images/journal/2010/01/traffic-by-region.png"><img src="http://www.planetjk.com/images/journal/2010/01/traffic-by-region-148x300.png" alt="" title="traffic-by-region" width="148" height="300" class="alignnone size-medium wp-image-620" /></a></p>
<ul>
<li>Someone with an IP in Sweden is trying to login to my<a href="http://crowdfavorite.com/tasks/"> Tasks</a> and <a href="http://gallery.menalto.com/">Gallery2</a> (photo albums). A lot.</li>
<li>My installation of <a href="http://haveamint.com">Mint</a> needs to be updated <strong>//Done</strong></li>
<li>I&#8217;m seeing a moderate amount of trolling for phpMyAdmin directories</li>
<li>In Mid-December, I see a lot of HTTP 500&#8242;s returned from disparate IP&#8217;s trying to get to this blog.  Perhaps I was doing maintenance?</li>
<li>An obvious zombie host tried exploiting some PHP code in the FAQ to surreptitiously upload a PDF (presumably loaded with more exploits).  Oh wow: I just scrolled up and saw 12 more instances of the same thing, to different target paths, from the same source.  That&#8217;s getting reported. <strong>//Done: sent an e-mail to the Abuse coordinator at <a href="http://www.americanis.net/">Americanis</a></strong></li>
<li>A machine in Brazil tried to route the Photo Albums through a known brute force tool previously hosted online (I say previously because the domain name has since been suspended).   I&#8217;m glad that DreamHost has one-click installs which allow me to upgrade ASAP.  Now that I think about it more, I host photo albums and blogs for a few friends that don&#8217;t really use them anymore.  It might be time to remove them. <strong>//Done: sent e-mails to friends</strong></li>
</ul>
<p>Okay, that&#8217;s enough for this morning- I have some abuse POC&#8217;s to contact. The notes above represent a reverse chronological eyeballing of traffic from Dec 2009 through now.</p>
<p>The biggest &#8220;problem&#8221; I have is that search bots don&#8217;t have memory loss.  I still get trolled for directory structure that I had in place in 2001- I should really look into modifying robots.txt or creating proper sitemaps so they know where to go.  It&#8217;s not really a security issue but it creates a ton of noise in the logs.</p>
<p>The biggest note to self is that I <strong>REALLY</strong> need to make a habit out of checking logs more often.  Getting pwn3d on your personal domain is a bad thing for an IT security guy.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.planetjk.com/journal/2010/01/summary-of-planetjk-exploit-attempts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

