For Windows

Microsoft has always been criticized for not adhering to Open standards and not being active in Open-source community. However, it looks like Microsoft has tried a fair bit of things to ensure that their products work well with popular web applications. I personally believe that Microsoft’s web servers aren’t good enough for PHP/MySQL driven websites and moreover, the security concern is one of the biggest factors to avoid Microsoft Windows. When Linux servers aren’t safe then no doubt, it’ll be a bigger pain to manage Windows Servers for .

is another topic, coming back to the point of Microsoft & WordPress, I was a bit surprised to see how Microsoft has bundled in Web Platform Installer along with various other popular web applications like Drupal, Joomla etc. Check out the list of application in the gallery. Although, I was happy to see that Microsoft has made this move, this should give confidence to those who find working with Linux web servers and web applications a bit difficult.

Microsoft & technologies shake hands!

1. on SQL Server : With the help of IIS 7, SQL Server Express and on SQL Server distribution, its possible to run easily on Windows Vista, Windows 7 etc. It’s not the simplest way to install it, however this great guide by Zach Skyles Ownes should take you home.

2. SilverLight Gallery – Microsoft has been trying hard to make SilverLight popular among developers and end users. This plugin can surely help them achieve this goal. If this gets adopted by bloggers, then the end users will have to install SilverLight in order to ensure that they can view the image gallery on their browsers.

3. SilverLight Bing Maps – This integrates SilverLight & Bing Maps with . This lets bloggers to put their location with interactive maps like Google Maps on their .

4. Windows Azure Storage for – This lets users to store their media files and static files on Windows Azure platform whose more popular alternatives are Amazon Web Services or Rackspace Cloud Files.

Why is Microsoft doing this?

The first question that comes in mind that why is Microsoft trying to make its technologies work with , Drupal or other PHP/MySQL driven web applications. Well, Zach has already answered this question -

I’m a PHP-bred Technical Evangelist at Microsoft, and I love the fact that PHP now runs great on Windows, SQL Server, Windows Azure and SQL Azure.  It’s exciting to see how Microsoft technology can light up , whether it’s through Silverlight image gallery , Bing Maps integration or future opportunities with technologies like our information service, Dallas.

Business sense says that Microsoft is using these popular web applications to make its existing or new technologies popular amongst end users, bloggers and developers. However, the interesting part will be to see that how many bloggers & developers [the ones not sold to Microsoft's technology] will be keen in adopting these? I personally welcome this move by Microsoft, although practically I doubt that I would use any of these technologies as I’m already comfortable with the setup that I currently have. What do you think about this move from Microsoft?

Bookmark and Share

vaultpress.jpg

From last couple of weeks, I’ve been trying to ensure that how WordPress can be secured enough to avoid any kind of malware attack. In the course, I found lot of new information about securing web applications and realized that how small and little settings can make and break things. While my struggle to know more about was going on, I came across the launch post of VaultPress, a backup and protection service from Automattic.

Please note that the service has been announced in beta and is available for only few users. One can apply for the invite over here. It’ll be a service and while signing up you can also mention that how much are you comfortable in paying for this kind of a service. If I were to decide the price, I would keep it around $10/month. I’ve not tested the service myself, however we could gather all the information about VaultPress from the coverage it has received from the biggies like TechCrunch, ReadWriteWeb, Silicon Alley Insider, VaultPress blog and finally my favorite WordPress Tavern.

Features of VaultPress

1. Focused on .org users.com is one of the most powerful and secure services around. However, same can’t be said for the users who use self hosted version on their own servers. There have been many horror stories in the past where many self hosted installs got infected from malware and much hoopla was created. VaultPress has been designed to work with self hosted to ensure that they can also get the quality backup and service to avoid any mishap.

2. Real Time & Complete Backups – VaultPress is an all-in-one backup package. It will backup posts, categories, tags and rest of the data along with themes, files etc. Jeff @ Tavern reckons that VaultPress will face stiff competition from Backupify, BackupBuddy and other backup plugins. According to Matt, founder of , VaultPress will be able to make the backup instantly as soon as one would publish the changes on the or website.

3. Safeguards against Zero-Day Attacks – This is one feature that I would be most interested in as this is one feature that no one else is offering. VaultPress will be able to safeguard your against the Zero-Day Attacks focused towards . It will also monitor your site to alert you against any suspicious or hacking activity.

Well, keeping these features in mind. We can install few that can help us achieve similar level of protection and that too free of cost. We just need to ensure that we configure the in the right manner. Here’s the guide …

Get VaultPress Features Before Hand!

wordpress-backup.jpg

1. Automatic BackupThis little plugin saves all the important files including themes, and database on Amazon S3. The allows you to schedule the backup of the database or just files or if you want you can ask for the complete backup as well. The will send you the confirmation messages over the email, so you will constantly be aware of the happenings. Amazon S3 can be used as a backup service for your ’s important files and believe me in most of the cases this will not cost you more than $5/month. Only in case of large publishers this cost can be more than $15/month i.e. the indicative price of VaultPress. By the way, Amazon S3 can help you in improving the site load time as well, don’t forget to check our guide on how to optimize the WordPress blogs.

2. Firewall – This nifty plugin monitors changes in the files, attacks based on various Zero-day patterns. Of course, this is not the ultimate solution however, our experience has been pretty neat with this . It did alert me whenever I tried to make any change in the theme files or files. It didn’t allow the change until and unless I approved the change. Make sure that if you are planning to install this, then you may get lot of notifications. So keep the settings appropriate or use GMail filters for ease!

3. OSSECossec-security.jpgOSSEC is an Open Source Host-based Intrusion Detection System. It performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. Of course, this is something which will not be as easy as installing , however investing a little time on this can ensure that you’ll have real peace of mind in future!! There is enough documentation available for avoiding initial hiccups!

Of course, the first two won’t ensure that you are getting instant and real time backups. However, a regular and weekly backup will ensure that you’ll be able to bring your back from a situation where nothing will look nice in the world. I hope you understand the point that i’m trying to make here! If you install OSSEC then I’m sure one could easily compare this setup with something that VaultPress will offer in future!

Isn’t it neat that you can enjoy the VaultPress like features even before you can get a hand on it or if VaultPress looks out of budget!

The success of VaultPress will depend on the following factors; 1) what will be the cost involved for end users and 2) how effective its monitoring system will be. I’m sure the takers of this service will be much more than any other similar service as it directly comes out from the makers of . However, personally I’ll be willing to test other services if they offer similar features at a competitive price. What are your initial thoughts on VaultPress.

Bookmark and Share

multi-author-blogging.jpg

[Image Credit - Hongkiat ]

Some of the most successful blogs that we see on Technorati Top 100 blogs are multi-authored blogs and most of them are powered by . Most of you can imagine that if running a successful single author can be a daunting task then how difficult it will be to manage a that has multiple authors. Be it advertising, metrics or logging activity there are various factors that a webmaster has to look into and with help of these , it’ll only become easier -

Must Install for Multi-Author Blogs

1. Author Advertising Plugin – This allows admins to create a revenue sharing program utilising one of the many advertising programs out there i.e Yahoo, Google Adsense, Amazon, Allposters etc. It can also be used as a banner manager, author photo/website widgets etc.

2. Members – Members is a that extends your control over your . It’s a user, role, and content management that was created to make a more powerful CMS. The is created with a components-based system — you only have to use the features you want. The foundation of the is its extensive role and capability management system. This is the backbone of all the current features and planned future features.

new-roles.jpg

3. Blog Metrics – This displays number of posts per month, average number of words per post and various other metrics in the dashboard. The reports are generated of overall statistics and is extremely useful in multi-author blogs as the reports are generated for individual authors as well.

4. Co-Authors Plus -Allows multiple authors to be assigned to a Post or Page via the search-as-you-type inputs. Co-authored posts appear on a co-author’s posts page and feed. New template tags allow listing of co-authors. Editors and Administrators may assign co-authors to a post. Additionally, co-authors may edit the posts they are associated with, and co-authors who are contributors may only edit posts if they have not been published (as is usual).

5. Author Exposed – Author Exposed is a simple that allows your visitors easy and elegant way to see more details about the post author. This pulls the author’s details from the profile and is linked to a hidden layer (div). By clicking on the author link the layer pop’s up with author info gathered from the profile page, plus gravatar photo, if author email is assigned with one.

author-exposed.jpg

6. Quick Notes On WP Dashboard – If you with multiple persons, you can leave a message for the others. In the file, you can determine, what capabilities a user must have to read the notes, and what capabilities he must have to write/modify them. By default, Authors and higher can write, and every registered user can read. Great Add-on for true collaboration.

7. BuddyPress – BuddyPress makes the whole as a social networking site. It literally adds Facebook like features in a install. It’s a great for a with multiple authors.

8. WordPress to SyslogWelcome to the Home of OSSEC.jpg – WPsyslog2 is a global log for . It keeps track of all system events and log them to syslog. It tracks events such as new posts, new profiles, new users, failed logins, logins, logouts, etc. It also tracks the latest vulnerabilities and alerts if any of them are triggered, becoming very useful when integrated with a log analysis tool, like OSSEC HIDS.

9. Future Calendar – It adds a simple month-by-month calendar that shows all the months you have future posts for (and the current month no matter what), it highlights the days you have posts for, and as an added bonus if you click a day the Post Timestamp boxes change to that day, month and year (although it doesn’t check the edit timestamp box to avoid accidental changes).

10. User Photo – Allows a user to associate a profile photo with their account through their “Your Profile” page. Admins may add a user profile photo by accessing the “Edit User” page. Uploaded images are resized to fit the dimensions specified on the options page; a thumbnail image correspondingly is also generated. User photos may be displayed within a post or a comment to help identify the author.

11. Post by Author – This will show the last X posts by the current author either at the bottom of every post, or where you manually specify in each post. Using the built-in options page, you can choose the number of posts to show, set the header text, choose to show the post dates, select the format of the date, and choose whether or not to include the current post in the list.

Bookmark and Share

Spam In Blogs

I am sure, I don’t need to explain anything about Spam over here. spam is nothing new and there have been already many articles written about it. However, I still get questions like “What is the best strategy to avoid spam comments?” Just to kick start things, I would like to mention the definition that has been given in everybody’s favorite website i.e. WikiPedia -

Spam in blogs (also called simply spam or comment spam) is a form of spamdexing. It is done by automatically posting random comments or promoting commercial services to blogs, wikis, guestbooks, or other publicly accessible online discussion boards. Any web application that accepts and displays hyperlinks submitted by visitors may be a target.

How to fight comment spam

There are various although in my four years of experience as professional blogger, I’ve come across only handful of that have done wonderful job for me. They have been shared by lots of experienced bloggers over and over again and here I am, who would like to share it with you one more time!

akismet.jpg

1. Akismet – This wonderful service from has been consistently helping thousands of bloggers in fighting spam. Not only it is available for , it has been extended for various other platforms like Movable Type, Drupal etc. There is no reason, why I would not suggest this to any person who is using .

WP-SpamFree.jpg

2. WP-Spam FreeScott Allen has rightly described it as an Extremely Powerful Anti-Spam ! Its so powerful that it literally makes your secure from all the comment spam. Although, this is infamous for using extra resources from server. If you have a high traffic and get lots of spam comments, then there is no reason why you shouldn’t be using this . Personally, its my favorite among all the that I’m listing over here.

3. SI CAPTCHA Anti-Spam – Another wonderful for fighting spam on blogs. It not only helps to fight comment spam. It also can be extended to fight automated registrations and automated contact form submissions. This uses a familiar trick of fighting comment spam i.e. CAPTCHA verification. It has lots of configuration options and if you don’t want to rely on automatic anti-spam like & WP-Spam Free then this will easily serve the purpose for you. [Plugin Homepage]

stop-bad-behavior.jpg
[Photo Credit - ScoopDog]
4. Bad Behavior – This wonderful script has been developed to fight against spam bots. It’s not specific to and is available for other content management systems. Its pretty light on servers and has been made available on plethora of CMSes. It has done a wonderful job in keeping this spam free from long time and will continue to do so!

recaptcha.jpg
5. reCAPTCHA – reCAPTCHA is a service that is used by thousands of popular websites to fight spam bots. The service can be easily integrated in a with the help of this plugin. I like this service/ because it definitely has proven its effectiveness to fight the spam bots and also because it helps in digitizing various books. Here’s what they have to say about digitizing the books part -

While the world is in the process of digitizing books, sometimes certain words cannot be read. reCAPTCHA uses a combination of these words, further distorts them, and then constructs a CAPTCHA image. After a ceratin percentage of users solve the ‘uknown’ word the same way it is assumed that it is the correct spelling of the word. This helps digitize books, giving users a reason to solve reCAPTCHA forms.

I hope that you’ll find these useful enough (just the way I have) to keep you spam free!

Bookmark and Share

wp-plugins.jpg

is the best blogging platform and there is no doubt about that, other than that it is also becoming the first choice CMS (content management system) for corporates too. One of the major reason for the same is that is pretty simple and even though it has got less inbuilt features, there are thousands of that are available for free and extend the it to match the existing CMS. It’s simplicity attracts thousands of developers and is one of the fastest growing CMS at the moment.

read full article →

Bookmark and Share

I know when it comes to English, I’m not the best person to bank upon – heck you can’t bank on me when it comes to even Hindi. I know that I constantly make mistakes while writing English and the worst part has been that I don’t try hard enough to improve it. Hopefully, now I won’t have to do that either – as Team has recently bought this cool company that does proof reading of your posts and that too for free!

read full article →

Bookmark and Share

I’ve upgraded our to WordPress 2.8.2 without any glitches and issues. I used the core update feature of , after I noticed that due to one XSS vulnerability one could get redirected from the admin dashboard to URL mentioned in the comment forms. I would strongly suggest everyone to update their installation as it hardly takes a minute to upgrade.

read full article →

Bookmark and Share