Tag Archives: MySQL

WordPress 2.6.2 Release

As most of you have probably already seen in your Dashboard, yesterday afternoon saw the official WordPress 2.6.2 Release. And as mentioned in the comments on my intitial news break on the 2.6.2 Beta, the focus is on two security patches to cover weaknesses in PHP’s random number generation (which affects password encryption strength), and in MySQL’s field length checking. [...]

Posted in Announcements, Community, WordPress | Also tagged , , , , , , , , , | 8 Comments

VPS Recommendations?

I’m looking for a Virtual Private Server host. The server I’m currently on is woefully underpowered for the handful of sites I running (on the plus side, it’s been free), and it’s high time that I moved my stuff to a box that’s up to the task.

Ideally, I’d like the following features:

  • Virtual Private Server with at least 1GB of RAM (preferably with root access within my instance).
  • SSH shell access.
  • Decent monthly bandwidth allotment (at least 250GB/month).
  • Plenty of disk space (25GB would be be plenty, but I can live with less).
  • Hosting of multiple web/email domains.
  • PHP5 and MySQL 5.
  • Ability to configure many email alias fowards within each domain.
  • Procmail for mail filtering.
  • DNS hosting, preferably with the ability to directly edit my own zone files, but I’ll live with a web interface if I have to.

Those are listed roughly in order of importance. [...]

Posted in Servers, Services, Tech | Also tagged , , , , , , , , , , , , | 23 Comments

Creating a secure WordPress install

Over on BlogSecurity, there’s a whitepaper on How to create a secure WordPress install. It covers several areas, including MySQL setup, WordPress user configuration, Apache protection of directories, and some useful plugins. I’ve glanced over it, and I have mixed feelings. Here’s a quick list of notes, off the top of my head:

Pros:

  • There is detailed information about granting the minimum privileges necessary for the MySQL login. This is a good idea that many people probably don’t think about.
  • Creating a less privileged WordPress account for posting, separate from your blog admin login, is also a good suggestion.
  • The notes on password enumeration are important. [...]
Posted in Security, WordPress | Also tagged , , , , , , , , | 29 Comments