A webmastery interlude

by Diane Duane

(Non-technically inclined people, look away now. Or skip down to the bottom of this where it gets less technical.)

I have a lot more screenplay stuff to do today, but I had to take an hour or so off from that after having a quick look at the “Out of Ambit” log files on arising, and noticing that someone had been trying repeatedly to access pages on my site that didn’t exist. The URLs they were trying to reach had all the telltale signs of attempted SQL injection attacks, which I hate as they mess up my tidy logs. So I spent a relatively pleasurable short time watching the Doctor Who episode “The Girl in the Fireplace” on UK Gold while getting things fixed. (There was a certain enjoyable resonance to watching the Doctor blowing up robots while I dealt with other people’s bots to their detriment.)

I am not going to reproduce the actual string in question, but info about it and a detailed analysis of the string and the attack are here. If you’re a webmastery-type person, or you run a blog or website and are technically capable of dealing with problems of this kind, you should have a look at your logs and see if you’ve been having this sort of attack. Then decide how you want to deal with it — redirects, blocking via your .htaccess file, whatever.  (IP blocking is of no use because the attacks are coming from all over the place.)

Since I didn’t feel like spending all day futzing around with writing redirects, I downloaded a copy of the Redirection plugin for WordPress, activated it, and created a custom redirect to deal with this problem. Works fine. The naughty people (or the poor bot-infested machines that have been dragooned into this) who come to OOA and attempt to inject this string are now being sent to a place of appropriate punishment.

That’s all the techie bit for today.

The only other thing of interest that’s happened is that (after finding myself thinking how long I’ve liked the Doctor, and liked him a whole lot) I got vaguely curious about the whereabouts of an article I wrote for a Balticon program book many years ago: a discussion of the uses of imagination (among other things). It was called “Meetings on the Stair”. I dug it out, updated and cleaned it up a little, and posted it so I can find it later if I want it for something: it’s here, if anybody’s interested. I suppose I’ll also stick it up as a pre-dated blog posting, so it won’t screw up the present blog entry sequence.

Now then… back to that script.

