10 of the Coolest Earth Day Facts

Earth Day - April 22 2015

The annual event that raises the consciousness of the environment in people’s minds across the world is fast approaching again. Earth Day has been a pivotal expression of our concern for the planet we share since it was started 45 years ago this coming April 22nd. Perhaps no secular event has ever had a bigger impact on people’s lives in terms of its influence on environmental laws and how people behave with respect to the environment in their daily decisions. Here are some of the 10 coolest facts about this important day and how it has influenced us all.

1. It Is the Largest Secular Holiday in the World

It is the largest secular holiday in the world. The Earth Day Network works with over 20,000 partner organizations in 192 countries to coordinate events for this day. It is estimated that over a billion people take part in Earth Day activities around the world, which makes it the largest secular event on the planet.

Continue reading

Top 10 Worst Passwords That You Should Never Use

worst-passwords

Each year, millions of internet users’ data is stolen—whether it’s because of hackers, data breaches or North Korea, it’s important to keep your information safe. The following passwords are some of the worst ones you can use, and you should avoid using them at all costs.

We’ve developed an easy to use random secure password generator that you can use to ensure that you never use some of the hilariously insecure passwords for your critical information.

1. 12345

The overuse of 12345 dates back many years. Before the internet, before hackers and before internet data breaches, 12345 was a popular locker number, bike lock passcode, briefcase passcode and code to the Dromedia air shield in the movie “Spaceballs”. In the words of Rick Moranis, “That’s the worst passcode ever.” It still is. It’s surprising how many people actually still use this password for their email, banking and other secure online accounts. In fact, CNN reported it was the third worst passcode of 2014 that a person could choose. If 12345 is your password, change it immediately.

2. Your Social Security Number

The second worst password is a social security number. Although you may think you’re the only person with your social security number, you’re not. Thought it’s not easy to obtain this information, it’s not impossible. Think about how many times you filled this information out in the past year. Insurance companies, credit card approvals, banks, school loans and tax forms all have your social security numbers on them. When this information is submitted to a company, it sits in the database. If the information is on paper, it eventually gets sent to a warehouse for safe keeping. In 2014 alone, major companies like Target were victims of data breaches where hackers stole credit card numbers and social security numbers. Don’t make one secret number another secret number.

3. Any Password Without a Number or Symbol

The stronger your password the more secure it is. People who use one word like “hotdog” are more likely to be victims of a data breach. Using an alphanumeric code with symbols is the best way to keep your information safe. Instead of “applesauce” try @PPles@uce786. The more complex your code, the harder it is for hackers to get a hold of it. If you’re having a hard time remembering such a code yourself, use something that is personal to you—that no one else knows. For example, if you knew a girl in high school who you didn’t get along with, you hate Brussel sprouts and your childhood home was 82 Highland Park Drive, your password could be Colleen&BS82. It includes capital and lower-case letters, symbols and numbers. Who could forget Colleen? She was so mean. How could anyone forget the terrible taste of Brussel sprouts? How could you forget your childhood home? Your mom drilled that number into your head so many times.

4. StrongPassword

This one is almost as bad as 12345. If you use it, it’s almost like you’re trying to dare people to hack into your account. When you type a password into the password box, and the site rejects your password because it’s too weak, do not simply type in StrongPassword. It’s shocking how many people use this password a year. If you must use StrongPassword, at least use StrongPassword12345. Try a strong password generator to find a better password.

5. password

This password also made CNN’s top list of terrible passwords for 2014. It was actually number two on the list. This one is so bad, it was number two on CNN’s list in 2013 too. Password is the most obvious password in the bunch. Usually reserved only for sites that do not use pertinent information or you only plan on using for a few minutes (but force you to create an account), “password” won’t even make it past the password minimum requirements for most websites and will be rejected as soon as you click “next”.

6. 696969

Come on guys, grow up. It’s laughable how many people use 696969 as their password. Who was the first person to think this number was one that would be unique that no one else would guess? 2014 was the first year it even made it on to CNN’s list of worst passwords, so it must have taken awhile to catch on. One can only wonder how many CEOs and hedge fund managers use it on their briefcases. Let’s hope they don’t use it to log on to their online accounts.

7. Your Name

Your name is one of the worst passwords you can use. It’s a no-brainer for people trying to steal your information. It’s the first thing your kid would try if he wanted to steal your password. If your name is your password, your kid is probably at home looking at god-knows-what as we speak. Along these lines fall your kids names, birthdays, your current street name and your pets names—all information others can easily access.

8. Dream Board Passcodes

Okay, so you want to win a million dollars. Don’t make it your password in hopes that it will come true if you think about it enough. Also leave off other dream board ideas, like Corvette, Lose30Pounds, BodyLikeMollySimms and other passwords that people think they’re the only ones to think up. If you’re really having a hard time coming up with password names, use a strong password generator to help get your ideas flowing.

9. The Website Name

Don’t make your password Target12345 if you’re shopping at Target.com. Don’t make it Walmart, VictoriaSecret or any other name of a website that you’re shopping at. It’s easy to guess, and if you’re using the Password Target12345, there’s a good chance you’re using Walmart1234 for your Walmart account. Now someone not only has your Target password, they have all your passwords.

10. Your Old Password

When a website asks you to change your password, change it; don’t try to use your old password again. They may have asked you to change your password for security reasons, because their system was breached or because of several other reasons—but they did it for a reason. It’s for your safety.

Blind SQL injection vulnerability found in WordPress SEO plugin by Yoast

Yoast-Wordpress-SEO-Plugin

 

Over a million websites that use WordPress SEO by Yoast are at risk due to a blind SQL injection vulnerability found.  WPScan Vulnerability Database released an advisory after it had disclosed the vulnerability to the plugin’s author.

“The latest version at the time of writing (1.7.3.3) has been found to be affected by two authenticated (admin, editor or author user) Blind SQL Injection vulnerabilities.

The authenticated Blind SQL Injection vulnerability can be found within the ‘admin/class-bulk-editor-list-table.php’ file. The orderby and order GET parameters are not sufficiently sanitized before being used within a SQL query.”

Yoast quickly responded with a patch and released the version 1.7.4:

“Fixed possible CSRF and blind SQL injection vulnerabilities in bulk editor. Added strict sanitation to order_by and order params. Added extra nonce checks on requests sending additional parameters. Minimal capability needed to access the bulk editor is now Editor. Thanks Ryan Dewhurst from WPScan for discovering and responsibly disclosing this issue.”

Immediate Update Recommended

GreenGeeks real-time security scanning is already protecting our customers from this vulnerability. While GreenGeeks has real-time monitoring in place to catch such vulnerabilities and pro-actively protect our customers from exploit, we strongly urge all of our customers to update their WordPress SEO plugin by Yoast immediately to avoid any potential issues in the future. Best practice is to ensure that all of your plugins and WordPress core files are up-to-date at all times.