<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Race For A Million &#187; Security</title>
	<atom:link href="http://www.raceforamillion.co.uk/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.raceforamillion.co.uk</link>
	<description>First Steps Over The Starting Line</description>
	<lastBuildDate>Wed, 28 Oct 2009 11:33:40 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>How To Knock £100 Off Of Anything</title>
		<link>http://www.raceforamillion.co.uk/how-to-knock-100-off-of-anything/</link>
		<comments>http://www.raceforamillion.co.uk/how-to-knock-100-off-of-anything/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 09:06:11 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Money Making]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.raceforamillion.co.uk/?p=321</guid>
		<description><![CDATA[Ok, before I go into this, let me state that I have not done this &#8211; its a wee bit naughty if you ask me, but the theory itself is sound as a pound&#8230;just don&#8217;t let the lions know I let on to this secret. This idea can, in theory, allow you to get £100 or more [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Ok, before I go into this, let me state that I have not done this &#8211; its a wee bit naughty if you ask me, but the theory itself is sound as a pound&#8230;just don&#8217;t let the lions know I let on to this secret. This idea can, in theory, allow you to get £100 or more off of a lot of things, yet it borders on the realm of the unethical. I&#8217;d like to hear your views on it, although I probably know what they will be, lol.</p>
<p style="TEXT-ALIGN: center"><strong>Ethical Protection Statement: I only provide the following below to give you an idea of how susceptible some &#8217;systems&#8217; are, and to allow you to possibly protect yourself against it</strong></p>
<p style="text-align: justify;"><span id="more-321"></span>I first came up with this idea about a year or so ago, when I was short of cash and really wanted to buy a new TV. I wanted the best TV I could get but didn&#8217;t want to pay full price either. I looked around, online and offline to try and find the best deal I could. Now what you usually find is a lot of offers and deals but never an ideal price. Well I went into one shop to just have a browse, and I noticed a sign where they claimed they had the cheapest prices on TV&#8217;s, and that if you could find a price cheaper than theirs, they would match it. Turns out a lot of shops have these offers nowadays! I looked at a couple of the TV&#8217;s in the shop and knew that they couldn&#8217;t be the cheapest prices, and that surely somewhere online would offer better rates. Then it hit me &#8211; what’s to stop me taking the HTML from an online site that sells the TV, change the price, print it off and claim that its cheaper! Surely a great idea no?</p>
<p style="text-align: justify;">Well, I thought about it some more, and then realised that printing off the page probably wouldn&#8217;t be enough proof for them. I mean, as soon as they log onto the website they will be able to see that the price is different, and will know that something is amiss&#8230;so how do we get round this? Well, its going to take some work&#8230;</p>
<p style="text-align: justify;">Firstly, go into the shop you wish to &#8216;target&#8217;, and note down the item you want, along with the model number etc. Once home, you want to start building a website that looks like an online retailer. Now there are many &#8216;ready-to-go&#8217; templates out there that you can get essentially for free &#8211; the website doesn&#8217;t have to be pretty either, it just needs to hold up to inspection. Then you want to enter a selection of products, which includes the item you want to purchase (hence whywe grab the model number etc.) - this you mark up at whatever price you wish to pay for it &#8211; so say its a £500 TV, you could mark it up as £399. Now you can print off the details of the TV, and when handed to the shop owner, they can also visit the site to check that the price matches! Ahh, but what if they try to put a purchase through, and buy the TV from you? Surely that will put you out of pocket very quickly! Well, here&#8217;s where we get even sneakier &#8211; when they try to go to the checkout, we want to change the files so that the checkout page presents a maintenance page, saying that the site is currently experiencing difficulties and will hopefully be back up soon. Here you can provide an email address &#8211; or if your feeling even sneakier, a phone number, of which on the other end is an accomplice. The accomplice can then say that they are offering the TV for that amount as they have &#8217;special relations&#8217; with the suppliers or something similar.</p>
<p style="text-align: justify;">There are flaws in this plan, as its possible that the shop you visit will say that it won&#8217;t do you the price deal because of &#8217;such and such&#8217;, so you might want to get someone to ask the shop owners for the terms of the price match/bust offer, before you start doing the above. Its important that you don&#8217;t ask personally, as they will remember you and realise that its a potential scam. If you also know the terms and conditions, and the company still refuses, you can then ask them to present their terms, of which you should be all in order with. Sadly, most of the time it is upto the seller though if they decide to go through with it. Another potential issue is the cost of setting up the site, with phone numbers etc.</p>
<p style="text-align: justify;">Well there you have it, it&#8217;s not the worlds most perfect plan, and it does have a couple of issues, but it is a method of knocking a significant price off of an item you might wish to purchase! Maybe I will set up the site for you guys and then charge a pound to list the items you want to get offline ;)</p>
<p style="text-align: justify;"><strong>Dan</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.raceforamillion.co.uk/how-to-knock-100-off-of-anything/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>How CommentLuv Can Help Find Hackers</title>
		<link>http://www.raceforamillion.co.uk/how-commentluv-can-help-find-hackers/</link>
		<comments>http://www.raceforamillion.co.uk/how-commentluv-can-help-find-hackers/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 11:29:20 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.raceforamillion.co.uk/?p=316</guid>
		<description><![CDATA[So yesterday I was catching up with what was going around on the various blogs I visit, trying out a few new ones to see how they fit and feel, when I noticed that I was having a problem with comment-luv. Now the problem wasn&#8217;t on my site, but rather it was an error when [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">So yesterday I was catching up with what was going around on the various blogs I visit, trying out a few new ones to see how they fit and feel, when I noticed that I was having a problem with comment-luv. Now the problem wasn&#8217;t on my site, but rather it was an error when I was attempting to leave comments on others websites &#8211; simply put, I was receiving an &#8216;XML error&#8217; instead of comment-luv displaying my latest post!</p>
<blockquote>
<p style="text-align: left;"><em>XML error: Invalid document end at line 261, column 1</em></p>
</blockquote>
<p style="text-align: justify;">Obviously me being the loving person that I am, and not being just out for the links (I am such an angel), I continued posting and thought of it as just a glitch&#8230;oh how wrong I was&#8230;</p>
<p style="text-align: justify;"><span id="more-316"></span></p>
<p style="text-align: justify;">I logged onto my computer again today and proceeded to look around the blogging world to drop my comments &#8211; yet again I was receiving the XML error. This time I decided to investigate into the matter at hand. I first went to comment-luv to check that the correct feed name had been placed in &#8211; which it had. I then proceeded to load up my feed, on which I discovered it wouldn&#8217;t load. So I went to my feed provider (which is the google owned feedburner), and proceeded to do a &#8216;feed check&#8217;. This repeated the error that comment-luv brought up for me, as well as all the source for my feed! On scrolling down, I found that someone had lovingly put links to various pornographic websites at the bottom of my feed, which was preventing it from loading.</p>
<p style="text-align: justify;">Now I had discovered the issue, it was a matter of <strong>where </strong>they had put the data so that I could remove it. I logged on to my server and checked my &#8217;index.php&#8217; file first &#8211; and to my surprise it was just at the bottom of that file. I promptly deleted the lines of code that had been added, and my feed was restored (once I reloaded it via feedburner). I reported the attempt to my web hosting provider (who then proceeded to break my website without asking&#8230;but that&#8217;s another story), and everything was back to normal!</p>
<p style="text-align: justify;">So what do I recomend to protect yourself from this type of hacking attempt? Well, firstly download <a href="http://www.commentluv.com/">Comment-Luv</a> as soon as you can, and comment frequently &#8211; you&#8217;ll notice any problems with your feed instantly. Even if its not the same problem, and you can&#8217;t figure out what is happening, there is a handy forum over there also you can ask questions in! Comment-Luv is a great way of keeping a good hold on your feed, as you would never normally check it yourself &#8211; why would you need to? As well as using this plugin, you may just want to check your index.php file, just to be sure that nothing had slipped its way in.</p>
<p style="text-align: justify;">Be safe out there guys!</p>
<p style="text-align: justify;"><strong>Dan</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.raceforamillion.co.uk/how-commentluv-can-help-find-hackers/feed/</wfw:commentRss>
		<slash:comments>38</slash:comments>
		</item>
		<item>
		<title>Security &#8211; The Root of The Issue</title>
		<link>http://www.raceforamillion.co.uk/security-the-root-of-the-issue/</link>
		<comments>http://www.raceforamillion.co.uk/security-the-root-of-the-issue/#comments</comments>
		<pubDate>Sun, 26 Oct 2008 16:30:37 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.raceforamillion.co.uk/?p=216</guid>
		<description><![CDATA[Now I have seen a lot of posts recently about blog security &#8211; about users who have been hacked and lost their blog contents because they didn&#8217;t back up. Now on reading these posts, I thought two things &#8211; one, I need to get some backup software! Two, no-one is discussing the root cause of [...]]]></description>
			<content:encoded><![CDATA[<p>Now I have seen a lot of posts recently about blog security &#8211; about users who have been hacked and lost their blog contents because they didn&#8217;t back up. Now on reading these posts, I thought two things &#8211; one, I need to get some backup software! Two, no-one is discussing the root cause of the issue!</p>
<p>Now through my varied searching a few weeks ago, I actually stumbled across a way that some people have been &#8216;breaking into&#8217; blogs, which would enable them to essentially delete your database. Now I&#8217;m not going to give out the <strong>precise</strong> details, but let it be known that the information needed to &#8216;delete&#8217; your database is actually available on google through a search!</p>
<p>You see, there is one file which is quite crucial to the working of your blog, and this file would be the wp-config.php file. This file contains all the information regarding your database &#8211; your username, password, and where to look for it! If an attacker knows this, then they can easily take your site down. Even worse, if they are very &#8216;talented&#8217;, they could manipulate your posts to their own ends, possibly placing harmful code on your site.</p>
<p>So what can you do? Well, a lot of you shouldn&#8217;t have to do anything, once uploaded it should be fine. However, there isn&#8217;t any harm in taking up a bit of extra security is there, especially if the unfortunate did happen, and access was someone given to your wp-config file. First, you should make sure that your CHMOD settings on that file are set to <strong>640. </strong>You can do that via any ftp program, right clicking on the file and choosing &#8216;CHMOD&#8217; on the options. A free ftp program is <a href="http://winscp.net/">WinSCP</a>. Depending on your hosting provider, you may be able to do this via some form of cpanel also.</p>
<p>A further way to protect your config file is in your .htaccess file. If you add the following to it, it will stop people from accessing the file itself:</p>
<blockquote><p>#protect wpconfig.php<br />
&lt;files wp-config.php&gt;<br />
order allow,deny<br />
deny from all<br />
&lt;/files&gt;</p></blockquote>
<p>This will protect your config file. To protect your .htaccess file, simply replace the &#8216;file wp-config.php&#8217; text with &#8216;file .htaccess&#8217;. This will help prevent people getting at your ever-so-important database information! However, I am yet unable to protect you against lions who have learnt to use the internet&#8230;they seem to have skills that are incomparable to humans&#8230;we should be scared&#8230;so very, very scared.</p>
<p><strong>Dan</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.raceforamillion.co.uk/security-the-root-of-the-issue/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
