Tuesday, September 17, 2013


BulletProof Security

WordPress Website Security Protection. Website security protection against: XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection hacking...

htaccess Core Website Security (Firewalls)

WordPress Website Security Protection: BulletProof Security protects your WordPress website against XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection... hacking attempts. One-click .htaccess WordPress security protection. Protects wp-config.php, bb-config.php, php.ini, php5.ini, install.php and readme.html with .htaccess security protection. Security Logging. HTTP Error Logging. Login Security/Login Monitoring: Log All Account Logins or Log Only Account Lockouts. Website Maintenance Mode (HTTP 503). Additional website security checks: DB errors off, file and folder permissions check... System Info: PHP, MySQL, OS, Server, Memory Usage, IP, SAPI, DNS, Max Upload... Built-in .htaccess file Editor.

Login Security & Monitoring Website Security

Login Security & Login Monitoring: Log All User Account Logins or Log Only User Account Lockouts (see Screenshot). Brute Force Login Security Protection. Email alerting options allow you to choose 5 different email alerting options: Choose to have email alerts sent when a User Account is locked out, An Administrator Logs in, An Administrator Logs in and when a User Account is locked out, Any User logs in and when a User Account is locked out or Do Not Send Email Alerts. Choose Standard WP Error Messages or Generic Error Messages for Login Security Stealth Mode. Choose to Enable or Disable Login Password Reset capability for Login Security Stealth Mode. See BulletProof Security Login Security & Monitoring Features for additional features and options.

Why is .htaccess Website Security So Much Better Than Any Other Type of Website Security?

The answer is very simple - .htaccess files (distributed configuration files) are processed first before any other code on your website. In other words, hackers malicious scripts are stopped by BulletProof Security .htaccess files/Firewalls before those scripts even have a chance to reach the php coding in WordPress. BulletProof Security uses .htaccess website security files, which are specific to Apache Linux Servers. Please read the FAQ page for Server compatibility questions.

BulletProof Security Fast and Simple with No Manual Configuration Required

The BulletProof Security WordPress Security plugin is designed to be a fast, simple and one click security plugin to add .htaccess website security protection for your WordPress website. Activate .htaccess website security and .htaccess website under maintenance modes from within your WordPress Dashboard - no FTP required. The BulletProof Security WordPress plugin is a one click security solution that creates, copies, renames, moves or writes to the provided BulletProof Security .htaccess master files. BulletProof Security protects both your Root website folder and wp-admin folder with .htaccess website security protection, as well as providing additional website security protection.
BulletProof Security allows you to add .htaccess website security protection from within the WordPress Dashboard so that you do not have to access your website via FTP or your Web Host Control Panel in order to add website security protection for your WordPress site. BulletProof Security Modes: Root .htaccess security protection, wp-admin .htaccess security protection, Deny All .htaccess self protection, WordPress default .htaccess mode and .htaccess Maintenance Mode (503 Website Under Maintenance). In BulletProof Security Mode your WordPress website is protected from XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection hacking attempts.

BulletProof Security Maintenance Mode

BulletProof Security Maintenance Mode allows you to create your custom website under maintenance page within BulletProof Security and activate Maintenance Mode to put your website in maintenance mode. Maintenance Mode allows website developers or website owners to access and work on a website while a 503 Website Under Maintenance page is displayed to all other visitors to the website. Allow access to your WordPress Dashboard for only yourself or add additional IP addresses to allow mulitple IP addresses access to your WP Dashboard while in maintenance mode.

BulletProof Security Additional Website Security Protection

WordPress is already very secure, but every website, no matter what type of platform it is built on should have additional website security measures in place as a standard. BulletProof Security provides that additional website security protection that every website should have.

Translations

  • Lithuanian by Vincent G from Host1Free.com
  • Filipino/Tagalog by pointen.dk
  • Russian by EyeFinity
  • If you would like to translate the BPS plugin to your language see this BPS Plugin Language Translation Tutorial. Please include a link to your website so that we can add it here. Thank you.
  • Tip: If you use the Google Chrome Browser you can right mouse click in plugin pages and then click on Translate to... To translate plugin text into your Language.

BulletProof Security Bonus Custom Code

BulletProof Security htaccess Core (Firewalls, etc.) Features

  • Root Folder BulletProof Mode/Firewall
  • wp-admin Folder BulletProof Mode/Firewall
  • Built-in .htaccess File Editor & File Manager
  • Built-in .htaccess Backup and Restore
  • One-click .htaccess website security protection from within the WP Dashboard
  • .htaccess security protection against XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection.......... hacking attempts
  • TimThumb Vulnerability/Exploit .htaccess security protection (Firewall)
  • .htaccess Lock / Unlock (404 Read-Only)
  • .htaccess AutoLock On or Off
  • Security / HTTP Error Logging - Log 400, 403 and 404 Errors
  • Security Log: Add / Remove User Agents/Bots to Ignore/Not Log or Allow/Log
  • Security Log: Turn On / Turn Off / Delete Log
  • Automatic .htaccess file updating on BPS upgrade installation
  • New .htaccess security filters automatically added during upgrade
  • WP Dashboard Alerts / WP Dashboard Dismiss Notices
  • Anti Comment Spam .htaccess code - works together with Akismet or other Spam plugins to keep Comment Spam at a minimum
  • Anti Comment Spambot .htaccess code - Forbid Empty Referrer Spambots
  • Custom Code feature: Add, Edit, Modify, Save additional Bonus or personal custom .htaccess code
  • WordPress readme.html and /wp-admin/install.php protected with .htaccess security protection
  • wp-config.php and bb-config.php files protected with .htaccess security protection
  • php.ini and php5.ini files protected with .htaccess security protection
  • WordPress database errors turned off - Verification and function insurance
  • WordPress version is not displayed / not shown - WordPress version is removed
  • WP Generator Meta Tag filtered - not displayed / not shown
  • WP DB default admin username / account check
  • System Info: PHP, MySQL, OS, Server, Memory Usage, IP, SAPI, WP Filesystem API Method, DNS, Max Upload, Zend Engine Version, Zend Guard/Optimizer, ionCube Loader, Suhosin, APC, eAccelerator, XCache, Varnish, cURL, Memcache and Memcached
  • Security Status Page - Displays website security status information
  • File and Folder Permission Checking - CGI / DSO - SAPI check / display
  • Help & FAQ page - links to BPS Guide and other detailed Help & Info pages
  • Extensive Read Me! jQuery Dialog Help buttons throughout the BulletProof Security plugin pages
  • Website Developer Maintenance Mode (503 website open to Developer / Site Owner ONLY)
  • Log in / out of your website while in Maintenance Mode
  • Customizable 503 Website Under Maintenance page
  • HUD Success / Error message display
  • i18n Language Translation coding

BulletProof Security Login Security & Monitoring Features

  • Brute Force Login Security Protection
  • Log All User Account Logins or Log Only User Account Lockouts
  • Logged DB Fields: User ID, Username, Display Name, Email, Role, Login Time, Lockout Expires, IP Address, Hostname, Request URI
  • Email Alerting Options: User Account is locked out, An Administrator Logs in, An Administrator Logs in and when a User Account is locked out, Any User logs in when a User Account is locked out, Do Not Send Email Alerts
  • Login Security Additional Options: Max Login Attempts, Automatic Lockout Time, Manual Lockout Time, Max DB Rows To Show, Turn On/Turn Off
  • Login Security Stealth Mode: Standard WP Error Messages or Generic Error Messages.
  • Login Security Stealth Mode: Enable or Disable Login Password Reset capability and links.
  • Dynamic DB Form: Lock, Unlock, Delete
  • Enhanced Search: Allows you to search all of the Login Security database rows/Fields
  • Stand-alone Unlock Form bpsunlock.php: Unlock User Accounts without having to be logged into the WP Dashboard
  • Please click the Login Security Blue Read Me help button for full descriptions of all features and options.

Easy Steps that Protect Your Website From Hackers

Written by Taylor Hawes
Tuesday, March 19th, 2013
website security
As a webmaster, is there anything scarier than the thought of seeing all of your web developed work being altered or wiped out entirely by a nefarious hacker?  You’ve worked hard on your website – so take the time to protect it by implementing basic hacking protections!
In addition to regularly backing up your files (which you should already be doing, for various reasons), taking the following three easy steps will help to keep your website safe:

Step #1 – Keep platforms and scripts up-to-date

One of the best things you can do to protect your website is to make sure any platforms or scripts you’ve installed are up-to-date.  Because many of these tools are created as open-source software programs, their code is easily available – both to good-intentioned developers and malicious hackers.  Hackers can pour over this code, looking for security loopholes that allow them to take control of your website by exploiting known platform and script weaknesses.
As an example, if you’re running a website built on WordPress, both your base WordPress installation and any third-party plugins you’ve installed may be vulnerable to these types of attacks.  Making sure you always have the newest versions of your platform and scripts installed minimizes the risk that you’ll be hacked in this way – though this isn’t a “fail safe” way to protect your website.

Step #2 – Install security plugins, when possible

To enhance the security of your website once your platform and scripts are up-to-date, look into security plugins that actively prevent against hacking attempts.
Again, if you’re running a WordPress website, you’ll want to look into free plugins like Better WP Security and Bulletproof Security (or similar tools that are available for websites built on other content management systems).  These products address the weaknesses that are inherent in each platform, foiling additional types of hacking attempts that could threaten your website.
Alternatively – whether you’re running a CMS-managed site or HTML pages – take a look at SiteLock.  SiteLock goes above and beyond simply closing site security loopholes by providing daily monitoring for everything from malware detection to vulnerability identification to active virus scanning and more.  If your business relies on its website, SiteLock is definitely an investment worth considering.
site lock hacking protection

Step #3 – Lock down your directory and file permissions

Now, for this final technique, we’re going to get a little technical – but stick with me for a moment…
All websites can be boiled down to a series of files and folders that are stored on your web hosting account.  Besides containing all of the scripts and data needed to make your website work, each of these files and folders is assigned a set of permissions that controls who can read, write and execute any given file or folder, relative to the user they are or the group to whom they belong.
On the Linux operating system, permissions are viewable as a three digit code where each digit is an integer between 0-7.  The first digit represents permissions for the owner of the file, the second digit represents permissions for anyone assigned to the group that owns the file, and the third digit represents permissions for everyone else.  The assignations work as follows:
4 equals Read
2 equals Write
1 equals Execute
0 equals no permissions for that user
As an example, take the permission code “644.”  In this case, a “6” (or “4+2″) in the first position gives the file’s owner the ability to read and write the file.  The “4” in the second and third positions means that both group users and internet users at large can read the file only – protecting the file from unexpected manipulations.
So, a file with “777″ (or 4+2+1 / 4+2+1 / 4+2+1 )permissions would then readable, write-able, and executable by the user, the group and everyone else in the world.
As you might expect, a file that is assigned a permission code that gives anyone on the web the ability to write and execute it is much less secure than one that’s been locked down in order to reserve all rights for the owner alone.  Of course, there are valid reasons to open up access to other groups of users, but these instances must be carefully thought out in order to avoid creating a security risk to your website.
For this reason, a good rule of thumb is to set your permissions as follows:
  • Folders and directories = 755
  • Individual files = 644
To set your file permissions, log in to your cPanel’s File Manager or connect to your server via FTP.  Once inside, you’ll see a list of your existing file permissions (as in the following example generated using the Filezilla FTP program):
chmod 1
The final column in this example displays the folder and file permissions currently assigned to the website’s content.  To change these permissions in Filezilla, simply right click the folder or file in question and select the “File permissions” option.  Doing so will launch a screen that allows you to assign different permissions using a series of checkboxes:
chmod 2
Although your web host’s or FTP program’s backend might look slightly different, the basic process for changing permissions remains the same.  If you have any questions about modifying your folder and file permissions, please see this helpful link.  Don’t put off taking this important step – securing your site using all of these different strategies is a big part of keeping your site healthy and safe in the long run!

Posted in

Web and Hosting Tips

Next Steps for Syria, Russia and the US

Next Steps for Syria, Russia and the US

TUE SEP 17, 2013
US–Russian diplomacy has ended America's threat of force against Syria, at least for the moment. But it requires Syria's Bashar al-Assad to declare and destroy his chemical weapons faster than that's ever been done before. If he refuses, what are America's options? Is Syria any closer to ending its increasingly brutal civil war? Also, rescues continue in Colorado's thousand-year flood. On Today's Talking Point, AMC's Breaking Bad has just two episodes left after five seasons of playing to a large and loyal audience. Is there any satisfying way to construct the last chapter?
Banner image: US Secretary of State John Kerry walks next to Russian Foreign Minister Sergey Lavrov (R) before delivering opening remarks to the media prior to their meeting to discuss the ongoing crisis in Syria, in Geneva September 12, 2013. Photo: Larry Downing/Reuters

The most corrupt administration in American history: Obama closed the WH to American citizens and keeps it open hundreds of lobbyists. WH for sale!

Posted on | September 17, 2013 | 4 Comments


EXography: No public tours, but 344 visits by lobbyists to the WH

By Luke Rosiak | 09/17/13 05:07 AM
Regular American citizens visiting the nation’s capital lost access to the White House in March as President Obama eliminated public tours to make a point in his battle with House Republicans in the sequestration debate over cutting spending or raising taxes.

Bill Clinton deprived members of the U.S. military of their rights to carry arms and defend themselves on military bases. Each and every member of the military has to contact his member of Congress, his senator and demand to repeal this law immediately

Posted on | September 17, 2013 | 2 Comments

Obama Administration Helped Kill the Push for Transparency on Military Aid


Reuters
The U.S. spent roughly $25 billion last year on what's loosely known as security assistance—a term that can cover everything from training Afghan security forces to sending Egypt F-16 fighter jets to equipping Mexican port police with radiation scanners.
The spending, which has soared in the past decade, can be hard to trace, funneled through dozens of sometimes overlapping programs across multiple agencies. There's also evidence it's not always wisely spent. In Afghanistan, for instance, the military bought $771 million worth of aircraft this year for Afghan pilots, most of whom still don't know how to fly them.
Last year, legislators in the House drafted a bill that would require more transparency and evaluation of security and all foreign aid programs. The bill was championed by an unlikely coalition of Tea Party budget hawks and giant aid groups such as Oxfam America.
But the Obama administration successfully pushed to have security assistance exempted from the bill's requirements, according to a letter obtained by ProPublica and interviews with Congressional staffers.
The Pentagon wrote that it "strongly" opposed last year's bill in a statement to Congressional staff laying out its "informal view" last December. "The extensive public reporting requirements raise concerns," the letter said. "Country A could…potentially learn what Country B has received in military assistance." Foreign governments would also "likely be resistant" to monitoring and evaluation from the U.S. Staffers say the State Department had also resisted the bill's increased oversight of security assistance. (The State Department declined our requests to discuss that.)
Two weeks later, the House passed a version that covered only "development assistance." The bill never made it to a vote in the Senate.
The State and Defense Departments, which handle most security assistance, "really are scared," said a House staffer who worked on last year's bill.  "They're afraid of transparency about what the money is funding, where the weapons are going, who is getting training."
As it is now, the staffer said, "some reports come two or three years after the fact, and the data is not easily manipulable."
Increased oversight of security assistance is needed, said Walter Slocombe, former Undersecretary of Defense for Policy, who recently led a government-sponsored study on the issue. The problem is that "a lot of these programs have been developed ad hoc," he said. "There's not much coordination among agencies, though often they are trying to do more or less the same thing."
New versions of the bill have been reintroduced in the House and Senate. This time, the administration's stance isn't clear. A spokesman for the National Security Council declined to comment, as did the Pentagon.
This year's bill has a loophole for security spending: a waiver allowing the Secretary of State to exempt such programs if he deems it in the "national interest."
Still, including security programs in the bill at all is "going to be a bit more difficult," said an aide to one of the House bill's co-sponsors, Gerry Connolly, D-Va. The exemption requires the State Department to tell Congress which programs it isn't including, and why.
Lauren Frese, a State Department foreign assistance official said, "We support Congress' objectives with the bill. It's more a matter of making sure we're not legislating something that isn't aligned with what we've already got going on." As the White House points out, it has already required agencies to be more transparent about spending on foreign aid.  Agencies must upload budget data to a central public dashboard, foreignassistance.gov, though the site's data is currently incomplete and information from the Defense Department is available only in generic categories. The bill would turn such directives into law.
The legislation also goes further. It would require the State Department to develop guidelines for monitoring and evaluating aid's effectiveness across agencies.
In a hearing in April, the House bill's co-sponsor, Ted Poe, R-Texas, said that "Americans want to see [whether] the money that we're sending to NGOs, the governments, et cetera is working or not working."
Representative Connolly hopes the bill will help the public "better understand the rationale for aid, and the context: what a small, small part of the government's budget it represents," he told ProPublica. Indeed, foreign aid makes up only about 1 percent  of the federal budget.
Supporters of the bill say excluding security assistance would leave a huge gap.
In January, an independent advisory board to the State Department recommended comprehensive reform of the whole concept of security assistance, calling for concrete objectives, better long-term monitoring, and a greater emphasis on non-military programs, such as programs to strengthen justice systems. (A few months later, the White House issued a policy directive that pledged to take on many of the same issues.)
"Nobody looks at it systematically," said Gordon Adams, who worked on national security and international affairs for the Office of Management and Budget in the 1990s and has argued for a reduced military role in security assistance. That's in part a reflection of how the landscape of programs has grown and fragmented in recent decades. Security assistance grew 227 percent between fiscal years 2002 and 2012, to a peak of $26.8 billion, according to data collected by the Stimson Center, where Adams is a fellow. That growth comes largely from programs in Iraq and Afghanistan, which are beginning to be scaled back. This year's budget still allocated more than $20 billion across State and Defense.
State officially oversees all foreign aid, including many programs traditionally thought of as "military," like weapons sales, but the Pentagon expanded its portfolio of "military operations other than war" and special operations in the 1990s. After 9/11, Congress also legislated new programs related to the "war on terror," such as the Combating Terrorism Fellowship Program and the Coalition Support Fund. With its Afghan programs, the Pentagon accounts for more than half of all security spending – not counting covert operations.
Last year, then-Defense Secretary Leon Panetta promoted training and aid to partners as "low cost and small-footprint approaches" to military objectives.
The Pentagon's increased role in foreign aid highlights a long-standing tension between the State Department and the military, which always has more cash on hand. "If you've got a $600 billion budget it's easier to squeeze in a few million dollars here and there," said Slocombe, who chaired the study for the State Department.
Countless examples from Afghanistan illustrate the problem of lack of both long-term planning and cooperation between agencies. In 2010, ProPublica and Newsweek documented the failures of the police training program, which had by then cost $6 billion. Responsibility shifted between agencies and contractors, and State and Defense squabbled "over whether the training should emphasize police work or counterinsurgency." Last year, in one police facility built by the Army Corps of Engineers, the inspector general for Afghanistan reconstruction found a well building being used as a chicken coop. Another encampment, designed for 175 police, was occupied by just 12. The men didn't even have keys for many of the buildings.
Other reports found the military paid $6 million for vehicles that were destroyed or hadn't been seen in years, and that $12.8 million in electrical equipment was sitting unused, as Defense and USAID each expected the other to install it.
Afghanistan is an exceptional case, given the scale of the spending and wartime conditions. But it also has the scrutiny of a special inspector general and a large U.S. presence. Security assistance to other countries has far fewer eyes on it – or a clear idea of what the objectives for the aid are. Empowering local police and armies can have more severe political and human rights repercussions than digging wells. "It engages us with a bunch of countries where our interests are at best opaque," said Adams.
Some programs are designed for political and diplomatic reasons (as was long the case with arm sales to Egypt), while others are meant to build up a country's ability to help the U.S. in its aims, such as countering terrorism or drug-dealing. In other words, giving a country what it wants, versus what the U.S. thinks it needs. (In fact, the Government Accountability Office found that branches of the military differ on which programs are supposed to do what.)
In a February testimony, the GAO said that few of the military's training programs had looked carefully at long-term impacts. "Reporting on progress and effectiveness," had in some cases "been limited to anecdotal information." For example, while Yemen has received over $360 million from two of the military's new counterterrorism programs, due to security concerns the Pentagon has yet to evaluate whether that money's had any effect.
The House bill's sponsors believe it could help with these problems of planning and communication. The bill "is not designed to be hostile or adversarial for the Pentagon and State Department," said Representative Connolly. "It's designed to provide them with a more cogent rationale for these programs."



Want to add to this story? Let us know in comments. You can share ideas for stories on the Open Wire.

Lesson of Navy Yard shooting echoes lessons of Camp Liberty,

Lesson of Navy Yard shooting echoes lessons of Camp Liberty, Fort Hood

Author
By Neil W. McCabe (Bio and Archives)  Tuesday, September 17, 2013
Comments | Print friendly | Subscribe | Email Us
Yesterday’s shooting spree at Washington’s Navy Yard reminds us that disarmed military personnel are made-to-order victims for spree shooters.
When Army Maj. Nidal Malik Hasan opened fire Nov. 5, 2009, on soldiers preparing to deploy overseas, I was at Camp Basra, Iraq, a combat historian mobilized with the Army Reserve.
To the soldiers in my circle, it was similar to the May 5, 2009 shooting spree at Camp Liberty, Iraq, when a joe burst into that camp’s combat stress center (!) and fatally shot five other soldiers.
Understand: All military personnel in Iraq were armed, with either a rifle or a handgun, and sometimes both. Living in a universally armed society created an unspoken atmosphere of respect and caution in personal relationships. It also meant any spree shooter inside-the-wire was instantly surrounded by equally armed personnel.
Unless you went to a combat stress center, where the soldiers turned in their “pole” for their visit. There were other places one left their weapon at the door, such as the gym or chapel. But at the combat stress center, there was also a good chance that the guns belonging to the clients had their firing pins removed—a precaution that allowed the a soldier to go about his day as if he could be trusted with his weapon, as he sought help.
The Fort Hood victims were absolutely unarmed. This is normal for garrison life, even for soldiers deploying, who may have a weapon, but no rounds. It was also a certainty for Hasan, who would have known that Clinton-era rules severely restricted military personal carrying firearms on duty.
The lesson of the Camp Liberty and Fort Hood shootings was that disarmed soldiers are just as vulnerable as anyone else to a spree shooter exploiting the fish-in-a-barrel opportunity of a “gun free zone.”
More details will emerge from the Navy Yard shooting, but we already know everything we need to know. The criminal justice system had the shooter in its control, but for whatever liberal impulses were at play that day, this dangerous man was released.
Maybe, like with many criminals, officials were waiting for him to do more serious harm to people and property before they looked up from their doughnuts and coffee and made an effort to keep us safe.
We also know that in addition to the Navy Yard being full of disarmed military personnel, it sits in a city with one of the tightest regimes of gun control in America.
That does not mean that Washington streets are immune from gun violence. It only means that the government of the District of Columbia has allied itself with the criminal elements to ensure victims cannot defend themselves.
More to the point, sailors stationed at the Navy Yard hear more gunfire in the South East neighborhood of our nation’s capital than they would ever hear stationed anywhere else.
Put another way, if the shooter, instead of rampaging inside walls and gates of the Navy Yard, went berserk up 8th Street SE towards Eastern Market or even more brazenly across the Anacostia River to that ward that takes its name from the river, he would have soon found himself surrounded by equally armed Americans—and put down.
On their last morning on earth, the Navy Yard dead went to work comforted in the lie that disarmed Americans are safer than armed Americans—and that all the security gates and armed guards would protect their lives.
If we truly respect their sacrifice and their families’ suffering, we will all have the courage to call out this lie and change the laws and regulations that consign Americans serving America to victimhood-in-waiting.

Comments
Neil W. McCabe is the editor of Human Event’s “Guns & Patriots” e-letter and was a senior reporter at the Human Events newspaper. McCabe deployed with the Army Reserve to Iraq for 15 months as a combat historian. For many years, he was a reporter and photographer for “The Pilot,” Boston’s Catholic paper. He was also the editor of two free community papers, “The Somerville (Mass.) News and “The Alewife (North Cambridge, Mass.).” Email him: neilwmccabe@gmail.com Follow him on Twitter: @neilwmccabe.