June 12, 2008

Hana Code Insert WordPress Plugin

Filed under: WordPress — HanaDaddy @ 5:32 pm

Inserting some javascript or Html codes in the middle of an article is not an easy task. It’s hard to copy and paste bunch of codes into the article whenever you write an article. Sometimes, the code breaks and doesn’t work as intended because WordPress encodes HTML entities.

So I decided to come up with the plugin that will help me insert that AdSense or Paypal Donation code into the middle of article.

Download Hana Code Insert Plugin v1.0

(more…)

May 25, 2008

Hana Flv Player WordPress Plugin

Filed under: WordPress — HanaDaddy @ 11:21 pm
As part of ongoing personal project for creating and embedding Flash Video in my Wordpress, I have decided to create a Wordpress plugin to help me writing embed tags inside the articles. If you are interested on my previous quests, check out below links.

Download Hana Flv Player Plugin v1.5

Change Log

Now you can easily embed the FLV Flash videos in your WordPress Blog. I have packaged the two GPL FLV Flash player, OS FLV and FlowPlayer. So you can use them freely without worries even for the commercial purpose unlike the JW player - If you have AdSense or display ads showing , you should purchase the player according to its website.

(more…)

May 16, 2008

Wordpress blog hacked with admin-ajax.php vulnerability

Filed under: Uncategorized — HanaDaddy @ 12:36 am

Whew~!
I just upgraded my old (don’t even know what the old version was) Wordpress to the latest 2.5.1 because somebody hacked into my site and added bunch of hyper links in my latest post. And it was very clever that the hyperlinks are not shown in the browser since the position of the div is out of screen. But probably search engines will see the links and increase the pagerank or simliar action could have been done I guess.

Anyway, the migration was very easy except that I had to redefine the tag keywords from the old UTW (Ultimate Tag Warrior 3) to the Wordpress.

I guess my blog was attacked by this admin-ajax.php vulnerability. They say that a hacker can run the SQL query through admin-ajax.php.

Here are some of the blogs explaining the vulnerability.

 

42 queries. 0.323 seconds. Powered by WordPress