<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>plugin &#8211; doncho.net</title>
	<atom:link href="https://doncho.net/tag/plugin/feed/" rel="self" type="application/rss+xml" />
	<link>https://doncho.net</link>
	<description>Късчета живот</description>
	<lastBuildDate>Mon, 29 Dec 2014 10:45:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://i0.wp.com/doncho.net/wp-content/uploads/2021/01/cropped-Doncho-Angelov.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>plugin &#8211; doncho.net</title>
	<link>https://doncho.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">12604956</site>	<item>
		<title>Inline Comments!</title>
		<link>https://doncho.net/2014/12/inline-comments/</link>
					<comments>https://doncho.net/2014/12/inline-comments/#respond</comments>
		
		<dc:creator><![CDATA[Doncho]]></dc:creator>
		<pubDate>Mon, 29 Dec 2014 10:44:25 +0000</pubDate>
				<category><![CDATA[Daily]]></category>
		<category><![CDATA[English]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[ajax]]></category>
		<category><![CDATA[ajaxify]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[comments]]></category>
		<category><![CDATA[customize]]></category>
		<category><![CDATA[inline]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[wordpress]]></category>
		<guid isPermaLink="false">http://doncho.net/?p=2461</guid>

					<description><![CDATA[Whoa! Inspired by Medium.Com, I decided to search, download and install Kevin Weber&#8217;s Inline Comments plugin (created by  to this blog too. Inline Comments lets users add comment with specific reference to any paragraph of the blog post, which is kind of cool, considering how hard is to quote blog texts. Now you just get one [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><a href="https://wordpress.org/plugins/inline-comments/screenshots/" target="_blank"><img data-recalc-dims="1" decoding="async" class="alignleft" src="https://i0.wp.com/ps.w.org/inline-comments/assets/screenshot-1.png?resize=291%2C96&#038;ssl=1" alt="Inline Comments Screenshot" width="291" height="96" /></a></p>
<p>Whoa! Inspired by <a title="Doncho's Medium" href="medium.com/@doncho" target="_blank">Medium.Com</a>, I decided to search, download and install <a title="Kevin Weber's Site" href="http://kevinw.de/" target="_blank">Kevin Weber&#8217;s</a> <a title="Inline Comments Plugin's Page" href="http://kevinw.de/inline-comments/" target="_blank">Inline Comments plugin</a> (created by  to this blog too.</p>
<p>Inline Comments lets users add comment with specific reference to any paragraph of the blog post, which is kind of cool, considering how hard is to quote blog texts. Now you just get one cute &#8216;+&#8217; sign close to the paragraph, over which you&#8217;re hovering (no mobile support, sorry), and if you click on that, you can leave comment instantly.</p>
<p>The same comment appears just like any other &#8220;legacy&#8221; comment below the post, but also with handy &#8220;reference&#8221; link to the paragraph you commented.</p>
<p>Together with Inline Comments, I decided also to install and run <a title="WP Ajaxify Comments Plugin" href="https://weweave.net/products/wp-ajaxify-comments/" target="_blank">WP Ajaxify Comments</a>, as these two compliment each other in quite nice way. As this is serious change to the overall comments experience, I will watch closely how it goes. Don&#8217;t hesitate to drop me a word, if you see any problems whatsoever.</p>
<p>So far I&#8217;m loving it :). And I hope Inline Comments will stay for a while on this blog.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://doncho.net/2014/12/inline-comments/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2461</post-id>	</item>
		<item>
		<title>Massive hacking attacks</title>
		<link>https://doncho.net/2013/04/massive-hacking-attacks/</link>
					<comments>https://doncho.net/2013/04/massive-hacking-attacks/#comments</comments>
		
		<dc:creator><![CDATA[Doncho]]></dc:creator>
		<pubDate>Mon, 15 Apr 2013 20:03:08 +0000</pubDate>
				<category><![CDATA[Daily]]></category>
		<category><![CDATA[English]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[bruteforce]]></category>
		<category><![CDATA[limit login attempts]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[superhosting.bg]]></category>
		<category><![CDATA[wordpress]]></category>
		<guid isPermaLink="false">http://doncho.net/?p=2020</guid>

					<description><![CDATA[Recently, I red in my fellow hosting provider Superhosting.BG about global, worldwide bruteforce attack over a lot of WordPress blogs (post in Bulgarian). I decided to quickly check what&#8217;s the actual attack activity and I installed the Limit Login Attempts WordPress plugin. What this plugin does is it logs all incorrect login attempts, and if [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><img data-recalc-dims="1" decoding="async" data-attachment-id="2024" data-permalink="https://doncho.net/2013/04/massive-hacking-attacks/hacking/" data-orig-file="https://i0.wp.com/doncho.net/wp-content/uploads/2013/04/hacking.jpg?fit=560%2C248&amp;ssl=1" data-orig-size="560,248" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;}" data-image-title="Hacking" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/doncho.net/wp-content/uploads/2013/04/hacking.jpg?fit=560%2C248&amp;ssl=1" src="https://i0.wp.com/doncho.net/wp-content/uploads/2013/04/hacking.jpg?resize=280%2C124&#038;ssl=1" alt="Hacking" width="280" height="124" class="alignleft size-full wp-image-2024" srcset="https://i0.wp.com/doncho.net/wp-content/uploads/2013/04/hacking.jpg?w=560&amp;ssl=1 560w, https://i0.wp.com/doncho.net/wp-content/uploads/2013/04/hacking.jpg?resize=300%2C132&amp;ssl=1 300w" sizes="(max-width: 280px) 100vw, 280px" />Recently, I red in my fellow hosting provider <a href="http://superhosting.bg/" target="_blank">Superhosting.BG</a> about <a href="http://blog.superhosting.bg/global-wordpress-brute-force.html" target="_blank">global, worldwide bruteforce attack over a lot of WordPress blogs</a> (post in Bulgarian).</p>
<p>I decided to quickly check what&#8217;s the actual attack activity and I installed the <a href="http://devel.kostdoktorn.se/limit-login-attempts" target="_blank">Limit Login Attempts WordPress plugin</a>. What this plugin does is it logs all incorrect login attempts, and if they go above given treshold, it blocks the IP for a while and logs the blocking. After few blockings, it blocks the IP for a day or so.</p>
<p>This functionality, of course, immediately blocks any bruteforce attempts. What&#8217;s more interesting here though is the fact that it logs the attempts. That was more interesting for me, because it gave me a chance to evaluate the attack size. And here&#8217;s what I&#8217;ve got, just for 2 days:</p>
<table>
<tr>
<th>IP</th>
<th>Tried to log in as</th>
</tr>
<tr>
<td>94.242.237.110</td>
<td>admin (8 lockouts)</td>
</tr>
<td>85.114.133.118</td>
<td>admin (8 lockouts)</td>
</tr>
<tr>
<td>91.224.160.135</td>
<td>admin (2 lockouts)</td>
</tr>
<tr>
<td>67.215.243.250</td>
<td>admin (1 lockout)</td>
</tr>
<tr>
<td>178.137.163.16</td>
<td>Bymnacculnela (2 lockouts)</td>
</tr>
<tr>
<td>72.32.68.101</td>
<td>admin (1 lockout)</td>
</tr>
<tr>
<td>194.247.30.126</td>
<td>admin (1 lockout)</td>
</tr>
<tr>
<td>95.173.186.104</td>
<td>admin (1 lockout)</td>
</tr>
<tr>
<td>188.40.69.202</td>
<td>admin (1 lockout)</td>
</tr>
<tr>
<td>108.163.188.186</td>
<td>admin (1 lockout)</td>
</tr>
<tr>
<td>109.200.29.66</td>
<td>Admin (1 lockout)</td>
</tr>
<tr>
<td>24.234.3.189</td>
<td>admin (1 lockout)</td>
</tr>
</table>
<p>Obviously, there was some &#8220;unhealthy&#8221; interest. But I never expected that the scale would be that big. And they were all shooting for &#8220;the big fella&#8221;, the &#8220;admin&#8221; account.</p>
<p>So it was time to change the admin username. Obviously, the success factor of the attack is based on the fact that WordPress comes with default &#8220;admin&#8221; username. If I change the username to something else, the attack would never succeed, even if it by some crazy stupid chance succeeds to get my password right (12+ symbols password). It was pretty quick change, although I had to play with the database directly (I&#8217;m almost sure there&#8217;s a plugin to do the job as well).</p>
<p>Now all seems safe. My wordpress applications locked my account twice, until I realized that I have to change the username there too, but that was the only harm so far.</p>
<p>So, if you&#8217;re managing WordPress blog, I urgently advise you to install Limit Login Attempts and change your admin user password (if you have only one admin user, if you have many, you have to live with the plugin only). Otherwise, you&#8217;re pretty much exposed to (some) risk, especially if you have easily guessable WordPress admin password.</p>
<p>Good luck!</p>
]]></content:encoded>
					
					<wfw:commentRss>https://doncho.net/2013/04/massive-hacking-attacks/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2020</post-id>	</item>
		<item>
		<title>Facebook Connect за моя блог</title>
		<link>https://doncho.net/2010/03/facebook-connect-%d0%b7%d0%b0-%d0%bc%d0%be%d1%8f-%d0%b1%d0%bb%d0%be%d0%b3/</link>
					<comments>https://doncho.net/2010/03/facebook-connect-%d0%b7%d0%b0-%d0%bc%d0%be%d1%8f-%d0%b1%d0%bb%d0%be%d0%b3/#comments</comments>
		
		<dc:creator><![CDATA[Doncho]]></dc:creator>
		<pubDate>Fri, 05 Mar 2010 10:26:00 +0000</pubDate>
				<category><![CDATA[Daily]]></category>
		<category><![CDATA[English]]></category>
		<category><![CDATA[Български]]></category>
		<category><![CDATA[Connect]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[plugin]]></category>
		<guid isPermaLink="false">http://doncho.net/?p=1109</guid>

					<description><![CDATA[Днес ми светна къде и какво миналата седмица ме е обърквало, че да не мога да си настроя Facebook Connect плъгина! И като ми светна, всичко взе че тръгна от раз. Какво точно беше ще пиша на английски, в следващ пост. Сега накратко искам да помоля всички коментиращи, освен стандартните &#8220;common sense&#8221; правила, да спазват [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Днес ми светна къде и какво миналата седмица ме е обърквало, че да не мога да си настроя Facebook Connect плъгина! И като ми светна, всичко взе че тръгна от раз. Какво точно беше ще пиша на английски, в следващ пост. </p>
<p>Сега накратко искам да помоля всички коментиращи, освен стандартните &#8220;common sense&#8221; правила, да спазват още едно &#8211; ако ще коментират, да го правят през Facebook акаунта си, ако имат такъв. Само 2 клика е, спестява писане по поленцата (ако вече ги нямате), а е много удобно.</p>
<p>Всички останали, които имат акаунт в моя блог, може да си &#8220;вържат&#8221; акаунта с техния Facebook акаунт, за да им е още по-удобно при коментиране. </p>
<p>Предварително ви благодаря!</p>
]]></content:encoded>
					
					<wfw:commentRss>https://doncho.net/2010/03/facebook-connect-%d0%b7%d0%b0-%d0%bc%d0%be%d1%8f-%d0%b1%d0%bb%d0%be%d0%b3/feed/</wfw:commentRss>
			<slash:comments>8</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">1109</post-id>	</item>
	</channel>
</rss>
