WordPress 2.3.3 Security Upgrade: A simple upgrade technique

Today’s announcement of an insecurity in Wordpress 2.3.2 may have spooked a few people:

WordPress 2.3.3 is an urgent security release. A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog. … If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php.

I have already applied the patch the blog, to ease my mind. To apply the patch, I’d recommend the following five steps:

  • Step 1: Download the patch directly from Wordpress.org.
  • Step 2: FTP to your account and login.
  • Step 3: Find the xmlrpc.php file in the /yourblog.com folder and rename it as xmlrpc.old.
  • Step 4: Upload the new file to the same folder.
  • Step 5: Once everything’s working, move the file to the root of your FTP User account out of harm’s way.
  • (If things go wrong: rename the new file you just uploaded as xmlrpc.new. Then rename the xmlrpc.old as xmlrpc.php until you can fix the problem. Of course, this is a good technique but the patch is a SECURITY patch, so you really OUGHT to upgrade the xmlrpc.php to the latest one.

If you’re ever upgrading plugins or even themes, renaming a current file or directory as *.old is a good way to give you a Plan B, just in case things go wrong when you install the new theme or plugin or file. You can simply revert to the old versions, provided you haven’t updated the database. CAUTION in upgrading is ALWAYS advised.

And, just in case you think hacking can’t happen to you, read several postings on MattCutts blog about his true but less severe hacking. There’s also a post on John Cow’s blog that got me thinking about this issue.

If you know any other great posts about blog security, do add them in the comments!

How do you navigate a 1000 posts? Five Practical Suggestions for WordPress Bloggers

I’ve made a number of improvements to find posts and get around the blog, I’m featuring five improvements that I think readers will like.

1. Random Post Plugin

I’ve been working on the blog upgrading usability somewhat in the last few days. I’ve also been trying out the Random Post Plugin.

randompost

You can see it clearly in the grey bar at the top of the blog! Try it!

2. ADDTHIS Widget

The AddThis Bookmark plugin is now featured. I’ve used three separate instances of the Bookmark This code in each page to help readers add this to their favorite service. It works well.

bookmarkthis

3. Bob’s Simplistic Navigation

I’m also using Top/Bottom Navigation which places code at the top and bottom of the blog page to show the previous/next post. It’s a standard feature in some themes, including Kubrick, but not my current theme. I still need to sort out the words since I use LONG titles.

navig plugin

In Pages View it’s fine, but the long title in Single Post View is ugly. See what I mean in the next picture…

navig plugin2

There’s no clear marker between the two posts. Oh, well. You can get the plugin here. It’s still pretty neat.

4. Related Posts Plugin

This plugin simply “returns a list of the related entries based on active/passive keyword matches.” You can see it on the main pages and on the Single Post pages. It requires a little hacking of the theme since it’s not installed by standard, but it works well. Get it here.

related posts

5. Feature Pages

I’m adding feature pages that are posts in the top bar, it’s slow progress, and I don’t want to crowd the bar area with too many, but this theme allows this extra space, and it’s easy to edit. Just edit the HTML in the theme header.

top bar2

Right now, it’s just got ‘WordPress and Top Posts’ but I’ll expand it slowly to include more posts that I want to highlight!

So those five ways will help readers find pages, esp. important pages, their own favorites and discover new stuff… When there are nearly a thousand posts in the archives, it’s time to help readers find some of the better ones. And these three tools help a lot.

How do you help readers find their way around your blog? As a reader, what do you like or hate in blog navigation? I know I loathe really long and loaded sidebars…. but… what about you?

Technorati: Why you should bother, how you do it, and the ‘dark side’

As advertisers, bloggers and readers have struggled for quite some time to find quality blogs, ranking systems have come to the forefront as a shorthand for everyone. While the jury is still locked on whether ranking systems are accurate or not, having a metric is important particularly for advertisers as a way to judge the value of a website or blog, and the price of advertising.

Over the last few weeks, I’ve been examining the different ranking systems available to Bloggers and their Audiences including:

and also…

How I first signed up

When I first joined Payperpost, I was unaware of the importance of Technorati. It was only when in the summer of 2007 that Payperpost introduced (then subsequently removed) Technorati rankings as a way to evaluate a blog’s popularity that I actually had my blog added to their system. Since then, my blog’s linking popularity has soared from multiple millions to approximately 39,000 right now.

technorati frontpage

So what is Technorati?

Technorati is a search engine system that collates, indexes and makes searchable the approximately 112 million blogs in its catalogue. It was founded by Dave Sifry and its headquarters are in San Francisco, California, USA. (source: WikiPedia Entry).

Technorat’s whole modus vivendi is to search and index, then make the results easily found by visitors to the website. In this way it functions much like Google or Yahoo! BUT the focus is primarily on blogs, and so many traditional websites aren’t included UNLESS there is a blog on the website. Hence, many websites are now converting to blogs or CMS-type blogs for fronting their online operations: the whole blog type setup allows many ways for visitors to find blogs rather than in the 90’s type websites when sites were static and had to be found in directories.

Its business model is to then sell adverts in various guises around the content that is collated, indexed and presented to its users. It, in many respects, could be considered a ‘splog’ except for its size, and its additional ranking and interactive functions.

——-
For more articles on running a business, making money, cutting debt, or creating your blog, subscribe to the RSS feed or email newsletter. There’s a lot more in the Random Walk to Wealth on InvestorBlogger dot com. Subscribe TODAY!
——-

And why should I bother?

For bloggers, there are three specific reasons to bother registering your blog with Technorati: Traffic, Exposure, and Authority.

1. Traffic – you will get traffic from Technorati, traffic that comes to both your front page and your indexed posts, even posts that have been indexed for a while. During the past year of 2007, Technorati sent me approximately 2.8% of my total visits for the past 12 months, not great but all the 2.8%s add up, and it was in fact my #6 source of referrals;

2. Exposure – Both readers and advertisers will be able to evaluate (albeit crudely) the apparent ‘worth’ of your blog by its relationship to others. For readers, this means that they will either ‘discover’ an unranked or low ranked gem and enjoy the thrill or feel glad to be able to participate in a well-recognized niche blog with a decent ranking. For advertisers, this simply means traffic and potential traffic by advertising on better known sites in their niches, advertisers will be able to understand, value and purchase appropriate advertising because the metrics Technorati uses will help to sort the wheat from the chaff; and

3. Authority – Increasingly, websites and blogs are being perceived not for the volume of links to them, but for their apparent authority. The adoption of the term ‘authority’ by Technorati last year was an attempt to value the content of blogs by counting specific types of links and sites linking to a particular site. Google’s PageRank also attempts this method.

The downside? There is one, isn’t there?

As with all metrics there are shortfalls and problems inherent in the nature of the system. Technorati has numerous problems that indicate how to game their system. It’s not the nature of this posting to describe those methods in detail. They do exist, and as John Chow found out, you can get banned, too.

There are more good strategies I found here, though they are perhaps less orthodox. Naturally, as John Chow found out, there are ways to be banned at Technorati so avoid using blackhat techniques that may risk a hard-earned reputation!

More importantly, though, the links themselves do NOT measure traffic to the blog well at all. In all respects, the links can be considered dead as they represent a potential path for traffic. In fact, Technorati expires links after a set period (usually six months). And the volume of links is not directly related to the amount of traffic. As such, if you see blogs that are moderately well linked, you may still have no idea how much daily traffic they have.

Some advertising companies DO rely on Technorati Rankings still as a way to evaluate the worth, either as a sole metric, or as part of a continuum of metrics, including REVIEWME, Text-Link-Ads, Payperpost (no longer), and more.

While bloggers (myself included) do rail against specific metrics from time to time, it’s difficult to deny that a triangulation of metrics, such as Alexa, PageRank and Technorati, may indicate that a blog is materially more popular than a similar blog in the same niche. Please note: I did NOT use the word ‘better’.

Lastly, there are technical problems with the website, with claims, and so on. I had a frustrating few months trying to claim a blog last year, until I actually blogged it. Weirdly, the problem was resolved quickly after that. Other bloggers reported the same thing at the time.

How to set up your blog on Technorati – in a few minutes

When you first sign up for Technorati and login, you can add your blog to their index in a simple fashion. Enter your blog URL in the ‘add URL’ on your account page.

claim method technorati

Claim That BLOG! It really is Mine!

Once entered, you need to ‘claim’ your blog and there are two simple ways: logging in via their website or posting a post on your blog with a special link that Technorati will pick. I’m choosing the first method as it’s much quicker, convenient, and doesn’t involve posting a useless item on your blog, an important thing to remember when you already have readers and subscribers!

So here goes…

quick claim step two

Now my blog has been claimed, and I need to add information to the entry, as below. If you’re not sure what to add, don’t worry as you can come back and change it later.

blog settings technorati

After the blog is claimed, you’ll see the entry listed in your account with buttons and information.

claimed blogs

The buttons on the left are self-explanatory:

1. ‘Edit Settings’ takes you right back to the ‘settings page’, as you saw already.

2. ‘Edit widget’ takes you to a page with the widgets listed and options that allow you to tailor a widget for your blog. This is largely a useless piece of widgetry as your blog already includes a search function, and Authority for blogs with ‘0’ is pointless (why flaunt it when you ain’t got it!?). Worse, excess javascripts on your sidebar will SLOW your blog loading times down. I don’t recommend this widget. If you still don’t believe me, why would you send your valuable traffic to Technorati for the searches when you risk the visitors NOT returning? Perhaps they’ll click on a link to another blog, an advert on Technorati, or… Silly.

widget example

3. However, the ‘Ping Setting’ can be quite useful. Of course, if you are using WordPress, you can simply ping the server automatically when you post by entering the code in the Options >>> Writing Page under ‘Update Services’ and the code is: http://rpc.technorati.com/rpc/ping. Sometimes, though, if Technorati isn’t working properly, you will HAVE to manually ping, and this Ping Setting can be done from your account in Technorati.

Reality Sets In: It’s in the millions!

Once you’ve entered all the settings, you’ll see the somewhat depressing result as one of my blogs below: “No authority” and a rank in the multi-millions! Don’t worry. Once you get a link or two, it quickly zips up as many millions of blogs are registered, but fewer have any referring links at all. Rank: 8,911,336 is pretty much bottom of the pile at the moment!

my first ranking

While it’s difficult to give an absolute answer, right now you need about 450 actual links to get your blog within the 10K ranking on Technorati. This blog (InvestorBlogger) has shot up from the multi-million ranking to approximately 39K at the moment. So, encouraging linking, posting links and getting links in posts from friends, bloggers, et al., will help you to zip up to under 100K quickly enough.

You can also gain links through: link trains, memes, commenting on dofollow blogs, guest postings, blog carnivals, directories (sometimes), and entries in all blogs. However, Technorati does not treat all links the same, so not all links will see your ranking rise. For example, blogroll links are seen as poorer quality.

Additional Notes:

Late last year, though, Technorati temporarily discontinued Rankings in favor of “Authority”, for reasons that seem to be unclear, even now. They obviously prefer the term “Authority” but in practice I see little reason for it to exist, or little difference from Ranking, except that it is accumulated from 0. However, this is their rationale:

we measure the number of blogs, rather than the number of links. So, if a blog links to your blog many times, it still only count as +1 toward your authority. Of course, new links mean the +1 will last another 180 days. Technorati FAQ.

And finally

So, if you are interested in developing your blog, you will find it worthwhile to register with Technorati as a way to increase traffic (albeit incrementally), exposure (always a good thing), and authority. There’s little to be lost by not registering. So what are you waiting for?