Plugin is crashing sites (11th July 2022)

Important for WordPress Website Owners using WP Crontrol Plugin

This does not apply to everyone, but I do use this plugin to help debug and analyse websites. It has been stable for a long time with no issues, however over the past 12 hours an update has been released which is causing a critical error on websites. If you see a white screen with either Error 500 or a message about a critical error has occurred on your website, then this is likely cause. 

I am currently working my way around all sites and removing it. Once removed the site continues work ok. 

If you have noticed that your site has a critical error, or have not checked recently, please take a look and let me know by return if you are affected. Those that let me know will be dealt with first. I will go through all sites over the next two days and remove it. 

What does it do?

It is an analysis tool which allows you to check the condition of the wp-cron function in your website. It lists the tasks that need to be executed, and when. I use it from time to time to determine if the website is behaving normally. It is not a critical component in your website. Removing it will not affect the core functionality. 

Any questions please give me a call. 

Home-Start Volunteer Diary Form

Over the years I have been asked several times if I can build a Home-Start Volunteer Diary form online. To do a one off is prohibitively expensive, and I have not bothered to look at it in any detail in the past. 

I have had a recent request, and based on my experience using Contact Form 7 and the layout manager plugin I have built a demonstrator. You can try this form out for yourself. It will send a message back to your email address with up to 122 different items of data formatted in an email. 

You can locate the page here:  https://wingrove-media.uk/vol-diary/

If this is of interest to your organisation (most likely a Home-Start) then please send me an email letting me know, and I will keep you in the loop as it develops. 

There is already 6.5hrs work in this form and over 870 lines of code. It is outside of mainstream website development and maintenance, but if there is significant interest, I can share the development cost across multiple organisations which would make it more attractive as a development project. 

Home-Start Resources Page

I currently host around 40 Home-Starts with a couple more in the pipeline. I also started working with Matt Hann and Tanya Freedman (HSUK) and look after another 40 sites there on a three month rolling contract. The additional 40 sites are based on one promoted by Rutland Online who are no longer developing sites for HSUK. These sites are also in the same hosting you are in, just in a different account. My role is to maintain them each month. 

I have hit quite a few problems in the way these new sites were set up. To help people there is a page you can also use here https://wingrove-media.uk/hsuk/ which lists those websites, but of greater importance, at the bottom of that page are some self help guides. You are free to use these if you wish. Some relate to the way that the hosting works, some relate to specific issues in that design of website. Many are relevant to you as well.

#BehindTheMask

I have just added one which contains a specially built slider to add the existing slides used on the Home-Start home pages to help promote #BehindTheMask. Please do help yourselves and download your copy of the pre-built slider and the instructions. It only takes 5 minutes and I have done the hard work for you. Note that the dimensions of the sliders used on your sites are different to the ones used on the HSUK sites. I have done two sets, just take care to pick up the right one. 

I also have a couple of posts prepared which you could also import and publish including the graphics. Contact me for more information. 

Page Redirect crashing some websites

On most websites I use a plugin which redirects a user to a Thank You page after they complete a form. This is a trivial function, and not one you might think could bring a website down.  I have had six cases over the past week where sites have stopped working due to an upgrade of this plugin.  It appears that the authors have substantially rewritten it, and there is probably a bug in there somewhere causing the problem. Can you all check your websites and let me know if you have a message about a critical error has occurred. 

That is the symptom. It is easy for me to fix and will take a few moments to do so, but right now I have not been through all of the websites.  You can help me to help you. 

Normally this type of incident is very rare, and it is clear that not all sites are affected either, so it is probably a combination of things. Around a year ago WordPress made some changes to error monitoring, where a site may have continued to work in the past with some issues, they seem to stop working now.

You may occasionally see a 500 error on your website, these are transient and indicate that the server cannot respond. They will clear themselves. You should never see CRITICAL ERROR. If you see that flag it to me immediately and I will sort it out for you. 

Another Phishing Scam – You may be targeted

It has just been brought to my attention that there is a phishing scam going on where people who have websites at 20i.com (I have your a reseller account here) are being sent phishing emails. It works like this:

The hacker has done some research based on name servers and then identified the websites that are hosted at a data centre. They then visit the website and scrape an email from it. They then take a screen shot of a legitimate page from the parent hosting company and attach that into the body of a an email.  

Fortunately none of you receive any emails from 20i.com directly, so hopefully your suspicions will be raised immediately. However it would be possible for me to automate the accounting side of my reseller package and you would receive emails like this. I have just never bothered to set it up. 

In the image below I shown the email which someone had kindly detected and flagged to me. I recognised it immediately as a 20i message. You would never receive one of these unless you had your own account with them. 

I have also placed my cursor over the image so you can see where the link goes to. You can see immediately it does not go to 20i.com, it goes to a server in Spain. 

This is a classic Phishing Scam. What they are after is maybe payment, or a username and password to log into the system. Either way it is a criminal act. 

Ways to detect these types of scams

When you look at the image above, it does look genuine on first glancing at it and not looking closely. It is actually based on a real message that they send out, but I am the only one that might get one, not you. 

There is a glaring error on the first line where they have adapted the message. “…. will expire within the next days.”  The actual number of days is missing. That is so they can create a reusable block of text for anyone. There are also special characters embedded in it which do not display correctly and if you look at the punctuation it is incorrectly spaced as well. 

Bottom line

If you receive a message and it does not look right, it probably is not right. The general give away is not much context and a link, or a lot of credible context, but the link is through an image. You can always find where a link goes to in most mail programs by placing your cursor on top of the link but not clicking.  In this case you would be passing information to a hacked server at http://……clinicapodologiabarcelona.es  (I suspect a foot clinic in Barcelona). 

Invoices relating to your services

You will only ever receive a message directly from me, it will not contain any links for you to login somewhere else. You would never receive a message from the hosting provider I use directly unless you had an account with them. 

Please remain vigilant, and drop me a line if you are unsure about anything, I would rather spend time replying than see anyone caught out, there is a lot of this going on right now. 

 

Phishing Case 3 – What happened?

The following is something else that happened to me, I spotted it, and still clicked on a link!  Here is what happened. 

One of my clients I am moderately regularly in contact with sent me a message. I have copied it below. What is unusual about this message is other than the graphic, it contains no context. Most communications where you need someone to do something, you provide some context on what you want to them to do, when you want them to do it and why.  An email with not much more in it than a link is always suspicious. Even though I know the person sending it. 

On receiving this I sent back the following message:

“Is this from you? What is it for?”

“I would never open an attachment without a message accompanying it. Spam often looks like this and carries malicious links.”

Mark

I immediately got a reply back:

With that assurance, although there were still questions in my head, I took it at face value and clicked on the link. Note the link is obfuscated, which means you have no idea where it will go. But I trusted the sender. The only legitimate reason for obfuscating a link is to make a long link shorter.

When I clicked on the link this happened:

I use ESET Smart Security Premium on my systems for this very reason. My computer detected that the website was suspect before I got there. So no damage was done.  ESET Smart Security Premium manages the connections in and out of your computer as well as checking what is happening on any web accesses and performing virus checking. So more comprehensive than your normal AV program. 

Taking it all apart

There was a clue in the original email if you check it by scrolling back up. It was not sent to anyone. I missed that. It was sent to a lot of people who came from the person’s address book, they were all on the BCC line of the email. 

The response I got back allegedly from the “manager” was actually the hacker who was in the email account and monitoring it at the time. The real manager played no role in this at all. Even though they were logged into email as well. 

If you think about it, what was happening here was a hacker had got hold of someone’s email address and password. They silently logged in and were passively monitoring the inbox after the message went out. That is really what makes this, and other examples of it quite scary. 

In the response back the graphic had changed to an obfuscated link. There would be no reason to hide where it was really going to. 

What did I do next?

I tried to independently contact the manager, I was unsuccessful because the office was closed, that is twice this has happened on different occassions when the parent organisation was closed, was that a deliberate ploy?  I then tried several other people and eventually made the organisation aware of what was going on.  It turns out my wife, who handles my accounts under a different email address also got one of these messages, and several other people as well.  So it does look like the hacker was working through an address list associated with the account. 

What can you do?

This really is a very worrying example of a trend that is increasing at the moment. Most of us would not know if someone else was passively monitoring our email account. The fact that they had the address book as well is also of concern. 

My advice is as follows:

  • Be super vigilant on any emails, text messages or anything else carrying a link, particularly if there is no message or context, even if it is someone you know. Don’t just assume it is ok. 
  • Was the email addressed to you, or is the to line empty?  If it is empty it is likely to not be legitimate, because the true addresses are hidden on the bcc line. It is a broadcast message. 
  • If you are even 10% unsure, independently ring them up and check. I trusted email, and ended up being mislead by the hacker. 
  • Be particularly vigilant if you are on Outlook.com, this was targeting Sharepoint users where you would need to login with your Outlook email address. 
  • If you do go to a phishing site, they will generally look official and familiar. However check the website address. The example above was sending me to https://canyouheal.org. Which is probably an innocent site that a hacker has got into and placed a phishing page in there, unbeknown to the website owner. 
  • Make sure your device is protected by a good quality (aka NOT FREE) Anti Virus AND Security product. If all else fails that will likely save you. 
  • If it happens to you, first change your password to a strong password containing upper and lower case letters and numbers, and even symbols.  Next run your anti virus application to make sure your machine is clean. 
  • Communicate:  If you have seen it, tell everyone to warn them. It is highly likely that others may be exposed as well. 
  • Check your sent messages folder from time to time. A careless hacker may leave an evidence trail behind if he has intercepted some message threads. 
  • If you are affected by a Phishing site (where you put your email address and password in and nothing happens), after you have recovered your password with a new one, bear in mind, you also need to change the passwords for any critical interfaces and websites you have access too. Especially if you use your email address to recover a password!

This is becoming a very dangerous trend over the past few months. 

It is also wise to change your main email address password regularly as a precaution against this type of risk. 

 

 

Phishing Case 2 – What happened

The following story came from a friend of mine, it is another example of what can happen when an email system is compromised. 

A business owner is regularly in contact with their accountant. There are invoices which need to be paid, are regularly passed between the two parties.  One day the accountant calls the business owner to check on an email they received which looked like a copy of another one. Both carried invoices. It was a sanity check. 

It turns out that the second copy of the email carried a modified invoice with a different account on it. So someone had infiltrated an email system somewhere between the two parties and was now trying to commit fraud by inserting their bank account into the transactions between the two parties. 

It was only through the vigilance of the accountant in this case was it spotted. 

How is it done?

Very often it is simply achieved by tricking someone to click on a link in an email which takes them to a seemingly official website and inviting them to log in. If they log in with their email address and password, that information is passed to a third party. Now the third party can get into the person’s account. It is quite possible that if they do this passively the person who has their email account compromised may be unaware of it. 

Change your passwords regularly.

 

Phishing case 1 – what happened

Over the course of the summer I have witnessed the outcomes of three phishing attacks. It is worth reflecting on these, because the same thing could happen to you, or someone in your organisation. If it did how would you handle it?

Case 1. 

A company that I have had a long relationship with, who provided a residential security service would invoice me once a year. In this case I anticipate an invoice, and from time to time contact the company to discuss account changes or servicing. Everything was fine for 24 years until June of this year. 

The timing here is probably significant. On a Saturday morning I receive a message from the company that appears to have originated from the company and it carries some previous correspondence including my account, my bank details and a new invoice attached to the document.

I say the timing is significant because it is Saturday and they are closed, the office is only manned during the week. 

I use an Anti-virus/ security program called ESET Smart Security. It does more than monitor for viruses. It warned me that the email with the invoice carried a virus. I had not tried to open it, the program monitors mail as it comes in  and checks it. 

I looked at the email more closely and found that while the message appeared to originate from the company, it was actually sent by someone else. Checking the email headers, it was clear it did not actually come from the company at all. 

How did they get my personal information?

It was clear that a data breach of some form had happened at this company, and now someone was working through old email threads and trying to propagate a virus payload hidden in the invoice. 

I rang the company support line and asked them to escalate this to the directors of the operation because I was concerned that other people with less adequate protection might actually download and install the virus by accident.  I tried three times and even wrote a letter.  Nothing happened for around 6 weeks!  In the meantime I received several more invoices carrying the same virus payload. 

No security breach here!

I received a very poorly worded broadcast newsletter that had not been checked by the company stating that an incident had happened which had been traced to the administrators computer. A virus had been installed on it, which had permitted a third party to read email on the computer. One can speculate that the “bad actor” copied the administrators email box and could see threads for all sorts of things, and could subsequently continue those threads by spoofing the email address.  It does not take a rocket scientist to appreciate that the administrator in question probably had access to all sorts of systems through her email account, so you do not really know what happened, or how much information escaped. 

The newsletter reporting the incident played it down, assured everyone there was no problem, and everything was under control. They provided an email address if you had any questions. 

Naturally I asked one. The email bounced!  So I called and asked to speak to a director. I was assured that there had been No Security Breach, all that had happened was an email account was compromised.  I challenged this because the email in question that I had received contained my name, address, bank details and other information on. I also pointed out that possibly many of their customers now have viruses on their computers. 

Conclusion

I don’t think this incident was taken seriously by the organisation, or reported to the ICO. Ironically the company in question specialism was “security”. They had little knowledge of IT security, and inadequate protection on their computer systems.  The main thing I took issue with was they did not inform their client base of the potential risk of clicking on an attachment allegedly from them carrying a virus. This virus, no doubt just extends the problem to affect more people. 

The company in question is no longer providing services to me. I cancelled the contract renewal and have gone elsewhere. 

What would you do?

Within the policy framework of your organisation how would you handle something like this? Would you be proactive and inform your correspondents about the problem, or would you keep it all quiet and hope nobody notices?

Could you cope if this happened when your main office was closed?

 

 

Many of the organisations I work have comprehensive and online policies. Most don’t though. When I look at some of the activity in this area with one client group who seem to be adopting security measures more aligned with MI5 than a small regional charity, this type of problem is more likely to happen than a laptop being stolen. 

Beware of the peaks!

For much of the past month I have been working my way around sites and making sure the sites are updating correctly. In some cases they have not been doing this without additional input. I have not got to the bottom of why, some of it is related to the Divi template. I spent a very tortuous 2 days seeking support to find out why. It would have been more productive watching paint dry. 

However I digress, I looked at around 70 of the sites I am hosting. I had to make changes to them to get the last version of WordPress to manage the updates. After I have done this the sites should in theory look after themselves. 

In the dashboard of most sites is a Google Analytics summary of the last 30 days of activity on your site. I noted the image below which has a strange peak in it on one of the sites. 

This is not normal

Then I found another one

And another one

And another one

Unravelling the thread

I found five in around 70 sites, so it was not everywhere. But what is it? I chose one site and decided to check Google Analytics to see what it recorded.  The peak in most cases occurred over a 5 minute period when allegedly around 350+ people from around the world decided to visit your website at 9am in the morning. And I do mean from around the world, not just in the UK. Any country in the image below that is a shade of blue, means people (allegedly) came from that country. 

The image on the left shows the top 31 countries and how many computers in each country.  Click on the image to see a larger version.  Not listed here, but I did check, looking at Russia countrywide, the visits did not come from one computer, but came from many across Russia.

What is going on?

Given the attack which is still going on some 4 weeks after I was notified on another site, I am very conscious of how long that took to sort out. I checked in with the hosting company to ask about these and what they thought they were. I did not get a straight answer, other than any attack will be handled by special measures in the hosting and the site will continue to work despite this.

It is unlikely that these sites were affected in any way, the visits in this case were no different to UK based visitors. The only difference is they came from everywhere in a very short period of time, apparently altogether or in quick succession.

Speculation

A few years ago I witnessed an attack on one of my sites while with another hosting company. I documented it at the time in this site. The site in this case had a protection mechanism built in that if there were too many visitors arriving at once, or trying to log in, they delayed any further activity from that IP address. As soon as one was blocked another one started. When that was blocked another one started, and they skipped all around the world in a few minutes.

The site was not taken down, but this is basically known as a DDoS or Distributed Denial of Service attack. The expectation being that if enough computers hit your site it will consume the server resources and your site will grind to a halt.

 

Click on the image to see a larger version

BOT Network

It is highly likely that I was witnessing a Bot network which is a set of compromised servers from around the world controlled by one central resource and they were testing it. When I last came across this I had all of the IP addresses of the computers, and could do a geo location search and also identify the owners of the computers (if they were a server for example). In many cases they were corporate servers owned by respectable companies that probably had no idea that there were additional processes running off of their computers. 

The system might be targeted at some point on a corporate server and financial demands made to turn it off. 

Things for you to think about

If you see a massive peak in your statistics that you cannot account for, let me know ASAP. I will look into it. If you have one of these it means your statistics for that period are no longer valid. So do not use them in any promotional documentation. 

You may have seen in the past messages like “We checked your website and it was not getting many visitors pay us ££££ and we will increase the number of visitors to your site”  Well this is one way of doing it. It will not however generate any more business because the visitors are not real.  

I can selectively turn off countries from accessing your website and take some other measures with the hosting company if you see anything like this. 

However it should not really impact your website, or your existing visitors. If you are not sure about something; drop me a line. 

Social Media Strategy or just winging it?

During my business career, from around the mid 1990’s there was a phrase that used to be passed around in “Marketing Speak” which was “Work Smarter not Harder”. 

This article and the corresponding PowerPoint attached below is really all about this. I have come across examples where there is either a lot of effort going into administering and keeping a social media feed up to date, and nobody is paying attention to the website, or both are working independently. 

The discussion looks at the problem from a number of angles, and asks several relevant questions in terms of what you think you are trying to achieve. For example if you have a facebook group, do you realise that this facebook group is similar to a congregation and you are preaching to the converted?  Really what you want to be doing is extending the reach of your organisation and growing the interest in your website (and facebook group). 

It is not difficult to do, but it does encourage you to stand back, see what is happening and then ask yourself is it yielding dividends for the organisation, or are you just doing what you think everyone else is doing without understanding why. 

The Social Media Strategy ppt explores ways of helping you to reach further, and grow your viewers. The website is central to everything and is like the Oracle, it contains all knowledge about your organisation and news. You copy links from your site to social media. That means you do not have duplicated effort, so you can now work more efficiently. 

Anyway enough of my marketing, if it encourages you to think out of the box and ask why, it was worth putting together. Drop me a line if you have any questions or seek clarification. 

 

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)