War to hackers – The aftermath

Emanuele Feronato WordPress

As you should know if you are an old time reader, this blog has been hacked several times with malicious script injection.

I tried to secure the blog in every possible way without any luck.

Finally, I think I figured out what allowed hackers to exploit the blog. I use a custom theme built on an old version of Silhouette theme by Brian Gardner.

As you can see from the link, the theme is not longer available for download, but I believe the file comments.php contains a vulnerability.

Here it is:

Since I changed it, I am not having injections for a month.

Moreover, I found a couple of sites using the same theme reporting an hack attack.

Any security hero willing to tell us if I am right? Of if it’s just a coincidence and hackers simply decided to leave me alone?

From null to full HTML5 cross platform game

I will take you by hand from the bare bones of JavaScript programming through the creation of a full cross platform HTML5 game, with detailed explainations and source code.

If you don't know where to start, then From null to full HTML5 cross platform game is the book for you.

Comments 4

  1. Darren

    I dont see any code in there that I wouldn’t use in any other theme bar the code for the comment backgrounds.
    WordPress itself it pretty secure. You should try and cut down on as many plugins as possible. After you got hacked did you go through your db to check for any malicious code? Try and add as much functionality to your theme as possible, instead of depending on plugins.

