PHP 5 updated
We’ve installed a PHP 5 security update. Customers should not notice any changes; the update just fixes several security issues in PHP 5.
We’ve installed a PHP 5 security update. Customers should not notice any changes; the update just fixes several security issues in PHP 5.
WordPress 3.2 was released a couple of days ago, and it looks like a great update. (We even contributed a little bit of performance-improving code to it ourselves.)
Our WordPress one-click installer automatically installs the latest version for new installs.
If you’ve previously installed WordPress, you can upgrade it from within your WordPress Dashboard. You should always do that when WordPress tells you there’s a new version available.
Our business offices will be closed on Monday, July 4 to observe the US legal holiday. As always, we’ll provide same-day support for time-sensitive issues via our ticket and e-mail systems. However, questions that aren’t time-sensitive (including most billing matters) may not be answered until the next day, and telephone support (via callbacks) will be available only for urgent problems.
Many, many years ago, some e-mail programs didn’t use a password when sending outgoing mail. That meant they didn’t work with many mail servers, including ours. To help customers with that problem, we used to allow a horrible alternate method called “POP before SMTP”, although it was never recommended or officially supported (it was unreliable and made it harder for us to prevent spam).
Well, here we are in a new millennium (“welcome!”). No popular mail program has needed “POP before SMTP” for more than a decade, and only a small handful of our customers are still using it. But spammers are continually trying to take advantage of the security problems it creates for all e-mail addresses, making it just as much of a nuisance on our end as it ever was.
Because of that, we no longer allow e-mail addresses to send mail using “POP before SMTP” unless they were previously doing so. In other words, if an address wasn’t using “POP before SMTP” before now, it won’t be able to start using it in the future.
We’ve updated our servers with a Perl security bug fix. This won’t affect most customers, but read on if you know you use Perl scripts on your site.
The “fry” server was the victim of a high-bandwidth Distributed Denial of Service (DDoS) attack beginning at 3:11 AM Pacific time this morning. On that server, Web pages were intermittently slow to load or generated timeout errors. (Other servers were not affected.)
We’ve blocked the large number of IP addresses from the “botnet” attacking the server, and the issue was completely resolved by 4:19 AM Pacific time. Please accept our apologies if you noticed any problems with your site loading slowly during this period.
We’ll be performing brief maintenance on the Web server that runs the Mailman list interface and archives tonight (June 9, 2011) between 10:00 PM and 11:00 PM Pacific time.
Microsoft FrontPage was once a popular Web design program. Microsoft stopped selling FrontPage in 2006, though, and we’ve been warning about the end of FrontPage support for a while now (on both our support pages and our blog).
That time has now arrived. Our FrontPage support for new sites will end on September 1, 2011, and support for existing sites will end a year after that.
World IPv6 Day is now in progress (it started at midnight UTC, which was 5:00 PM Pacific time). For the next 24 hours, many sites on the Internet, including our own www.tigertech.net, are fully IPv6-enabled.
If you have trouble connecting to www.tigertech.net, check other sites like Google, Yahoo and Bing. If you have problems with any of those, you should test your IPv6 connection and notify your ISP or network administrator about any problems.
For more information about IPv6 (and how sites hosted with us can participate), see our previous post: Now We Are Six: IPv6 support.
Today we detected that one of our customers had installed a WordPress plugin on his blog that did something malicious: when the plugin was activated, it sent a stranger an e-mail message allowing full administrator access to the blog.
How did this happen? Well, our customer simply searched the WordPress plugin directory for “Contact Form”, saw the popular “Contact Form 7” plugin listed, then clicked “Install Now”. That all sounds reasonable.