Latest News

Showing posts with label Cookies. Show all posts
Showing posts with label Cookies. Show all posts

Microsoft Windows Security Updates, May 2016

If you use a computer that runs Microsoft Windows, you may have been affected by Microsoft supplied updates, distributed 3 weeks ago.

May 10 was the day termed "Patch Tuesday" - the day when Microsoft releases important security related patches, to its various Internet updated products. During the 3 weeks after May 10, we've seen a significant number of security related discussions, in Blogger Help Forum: Get Help with an Issue.

It appears that Microsoft updates, for May 2016, affect use of Blogger.

The Microsoft Security updates, applied May 2016, appear to have affected various Blogger features, that are known to be vulnerable to layered security.

  • CAPTCHA visibility when daily post limit is exceeded.
  • Publishing comments, or replying to published comments.
  • Quick Edit icons.
  • Followers / Reading List maintenance.
  • Stats self initiated pageviews.

All of these features are known to be affected by cookie filters, and / or by script filters.

If you are using a computer that runs either Microsoft Windows 7 or Windows 10, and you are experiencing a problem with publishing comments, or with using Quick Edit, or with blocking your own views in Stats, or similar problems, you may want to check your cookie and script filters.

I note that some of the reports mention the browser used as Chrome or Firefox. You'll want to check filter settings in Windows Security Essentials.

Being realistic, it's also possible that Microsoft broke something within Windows - but we'll have to wait patiently, for them to admit that.

If you need different or more advice, please start a new topic in Blogger Help Forum: Get Help with an Issue.



Microsoft released monthly security updates May 10, 2016 - and since that date, there have been a number of security filter related issues, reported in Blogger Help Forum. It appears that the the Microsoft Updates involve cookie or script filters, which affect use of Blogger.


Effectively Testing Reader Access To Your Blog

People reporting a problem with blog access / performance, in Blogger Help Forum: Get Help with an Issue, will be frequently advised to diagnose their problems using affinity / differential testing.

Some diagnostic advice starts with simple instructions to "clear cache, cookies, and sessions". Some people, alternately, advise "use a different browser" - and test as a reader. These different strategies, seemingly redundant, will frequently lead to different results.

When you test reader access to a blog, some experts will casually advise you to "use a different browser" or "use a second computer".

There are specific reasons why this strategy may or may not be successful, when part of affinity / differential testing. When you test blog access, you're going to see varying reliability - based on a number of browser and reader details.

There are multiple ways to test blog access, of owner vs readers.

Any experienced testing technician knows that the most reliable testing, in affinity / differential analysis, will use identical browsers, on identical and separate computers.

Very few blog owners will have use of a bank of identical computers, for testing. There are alternate possibilities, when identical computers can't be used.

  • This browser, in the primary session - after "clear cache, cookies, and sessions".
  • This browser, in a secondary session - aka "Incognito" / "Private" browsing.
  • A different browser, on the same computer.
  • The same branded browser, on a different computer.
  • Any browser, on a different computer.

All of these details will be relevant, sometimes - though not always. The differences between "always" and "sometimes" will lead to some testers using incomplete testing techniques - and cause inconsistent results.

This browser, in the primary session - after "clear cache, cookies, and sessions".

The best way to avoid environment based inaccuracy is to re use the environment, sequentially. This approach requires more time - plus development of a testing script, to keep testing procedures consistent.

It is, however, the best way to avoid confusion from inevitable testing variations.

Using the same browser, in the same browser session, one can try using a different identity. This technique starts with the apocryphal instructions to "clear cache, cookies, and sessions".

This browser, in a secondary session - aka "Incognito" / "Private" browsing.

Some browsers support multiple sessions. In Chrome, a secondary session is provided as "Incognito" mode - and in Firefox, a similar (not identical) option is called "Private" browsing. The differences between the "Incognito" and "Private" features are significant - and can cause different testing results.


This blog, displayed in "Incognito" mode.



A different browser, on the same computer.

Each different browser will have differences in the browser itself. Plus, different add-ons and settings, on the different browsers, will produce differing results.

Having both browsers on the same computer will eliminate computer setup differences, present when multiple computers are involved.

The same branded browser, on a different computer.

If the branded browser, on the two computers, is maintained identically, there is a chance for consistent results. Having two different computers involved, however, may offset the consistency gained by using identical browsers.

Any browser, on a different computer.

This is the most inaccurate testing procedure, of the choices listed. Any difference between the browsers, or computers, can lead to inaccuracy.

The differences, in testing, involve multiple details.

  • Login identity in use.
  • Cookie filters, that block identity.
  • Script filters, that block identity access.
  • Browser add-ons, that may or may not be present.
  • Browser brand and design differences.

Login identity in use.

This is the one difference that you intentionally need, to test the reader experience. In the primary session, you are logged in as the owner. You require at least one secondary session - where you are not logged in as the owner, to test your blog as a reader.

The secondary session is where the need for sequential session reuse - or use of a different browser and / or computer - becomes necessary.

Cookie filters, that block identity.

Many Blogger features - involving both the dashboard, and access to the blog - use cookies to determine identity and permissions. Cookie filters, inappropriately managed, can cause havoc with Blogger. As an example, consider commenting ability, and third party cookies.

Different browsers may have different cookie filter settings. In some cases, identity is not relevant, for testing as a reader.

If you are testing access to a private blog, though, reader identity - which is cookie based - will be essential. A cookie filter involved, with a private blog being tested, will cause problems.

Similarly, testing Google+ comments requires known identity - for both the blog owner and readers. With Google+, identity is essential, to guarantee consistent display of comments.

Script filters, that block identity access.

Many Blogger features - involving both the dashboard, and content in the blog - are JavaScript based. Script filters can cause havoc with Blogger.

Different browsers may have different script filter settings - and different browser brands may have completely different script filters.

Browser add-ons, that may or may not be present.

The Firefox browser does not have native script filters, so many computer owners who use Firefox will add NoScript.

NoScript is a very intense add-on, with a lot of options, and opportunities for confusion. If you were to use Firefox on two different computers, you would need to carefully synchronise NoScript settings on both computers, for reliable testing.

Firefox with NoScript is the best known example - but it's not the only possibility for confusion. Every browser can have script filters, which will make browser to browser testing comparison a challenge.

With Chrome, one can select each individual add-on to be present in the secondary session ("Allow in incognito") - and this will create uncertainty. Some advice to "try using a Chrome incognito window" will be successful, with other advice being useless - and the absence or presence of the necessary add-on will be one of the issues.


AdBlock, optionally included in incognito mode, will produce uncertainty in testing - and is a well known script block.



Browser brand and design differences.

Every different browser produces differences in displayed content. Even a formatting discrepancy can lead to difference in test results.

The end results.

Interpreting test results, based on comparison of different browser displays, will be a challenge for anybody trying to produce reliable conclusions. The most reliable results will come from testing using the same browser session, sequentially. This will start with instructions to "clear cache, cookies, and sessions" - a painful but necessary process.



Many #Blogger problems need to be diagnosed using repetitive testing, and affinity / differential analysis. People who don't understand organised testing will sometimes recommend testing procedures, such as use of different browser sessions - which will produce inconclusive results.

Blogger Magic - Enabling Exceptions, In Chrome

Some blog owners and readers prefer to ignore recommendations in Chrome - and block cookies and / or scripts.

Blocking cookies can cause problems with many Blogger features - and blocking scripts will cause problems with both Blogger and with Google, and with various other websites.

If you want to use Blogger and Google effectively, you need to allow cookies to be installed, and to allow scripts to be run, on your computer.

If you cannot allow cookies and scripts for all websites, you can allow cookies and / or scripts on specific websites.

With Chrome, if you are willing to selectively allow specific websites to install cookies / run scripts, you should enable exceptions for those websites.

Start with the "Content settings" wizard.


Select "Block third-party cookies and site data", and / or "Do not allow any site to run JavaScript".



Add cookie exceptions, for specific websites.


Click on "Manage exceptions" under Cookies, to get the "Cookie and site data exceptions" wizard.




To add "google.com" as a cookie exception, paste / type "[*.]google.com", and select "Allow".




Click anywhere in the wizard window, to see the addition - then click "Done".



Add JavaScript exceptions, for specific websites.


Click on "Manage exceptions" under JavaScript, to get the "JavaScript exceptions" wizard.




To add "google.com" as a JavaScript exception, paste / type "[*.]google.com", and select "Allow".




Click anywhere in the wizard window, to see the addition - then click "Done".



Remember that cookie and script filter settings, in Chrome, may not be the only settings which you need to consider - and that many filters are subject to change, without your knowledge or approval.

For more detail about cookie and JavaScript exceptions, see Chrome Help: Manage exceptions. These are settings that you must determine and install - neither Blogger nor Google can make these changes for you.



Security conscious #Blogger blog owners may wish to ignore #Chrome recommendations, and block general permission for websites to install cookies and / or run scripts on their computers.

Some websites will not run properly, without cookies and scripts. If one is to use websites like Blogger and Google successfully, they need to be trusted - and Chrome must allow those websites to install cookies / run scripts.

Blogger Magic - Enabling Cookies, In Your Browser

The Blogger dashboard, and blog displays, is less of a pair of websites - and more of an application with code that runs on our computers.

The Blogger code on our computers requires cookies and scripts, which are installed as we use the various Blogger dashboard pages. The cookies and scripts are susceptible to interference, from overly restrictive layered security.

If you have a problem with Blogger - either accessing / using the dashboard, or using / viewing a blog - one of the simplest things to check, complementing script filter settings, is the browser cookie filter settings.

The browser is the most important component, when setting up security - and cookies are a common challenge.

Cookie filters are adjusted differently, for each browser. Consider the multiple domains used by Blogger / Google - and layered security, on any computer, used by the owner and readers of any blog.

  • Chrome.
  • Firefox.
  • Edge / Internet Explorer.
  • Opera.
  • Safari.

Setting the cookie filters in Chrome.

With Chrome, you enable cookies, using Settings ("Customize and control Google Chrome") - aka the 3 bar toolbar icon.

In Settings, if necessary, click on "Show advanced settings" at the very bottom of the page. Under Privacy, click on "Content settings", which gives you the "Content Settings" wizard.

Here, you have selections for Cookies and Javascript - including "Manage exceptions" for each section. Select the recommendation.

  • Cookies: Allow local data to be set

Hit "Done" - and close the Settings tab.


From "Privacy", hit "Content settings".




Under "Cookies", select "Allow local data to be set".



If you want to enable cookies selectively, select "Block third-party cookies and site data". Then use "Manage exceptions", and add "blogger.com", "google.com", and any addresses which apply to your blog.

Setting the cookie filters in Firefox.

With Firefox, you enable cookies, from the browser menu - aka the 3 bar toolbar icon, using Preferences - Privacy.

  • Under History, select that "Firefox will:" is set to "Remember history" then "Use custom settings for history". That will give you an array of settings.
  • Check "Accept cookies from sites".
  • Close Preferences. Settings will be saved.
  • Note that any Firefox add-ons which filter cookies, and offer more detailed options, will have to be dealt with, separately.


Select "Remember history", then "Use custom settings for history".




Check "Accept cookies from sites".



If you want to enable cookies selectively, change "Always" to "Never". Then use "Exceptions", and add "blogger.com", "google.com", and any addresses which apply to your blog.

Setting the cookie filters in Edge / Internet Explorer.

With Edge / Internet Explorer, you enable cookies, using the browser menu, selecting Tools - Internet Options. Optionally, you may access the "Internet Options" applet directly from the Windows Control Panel.

  • Edge / IE uses a zone defense setting, where you designate "blogger.com" and "google.com", in Security, as being in the Trusted zone. Please note that "blogspot.com" should not be in the Trusted zone.
  • Default settings for the Trusted zone will allow proper filtering of scripts.
  • Verify proper settings, with "Trusted sites" selected, and the Security level slider control set to "Medium". Hit "Custom level", and examine the Settings list.
  • You enable Cookies under the "Privacy" tab.
  • Move the Privacy slider to the bottom, to allow all cookies.
  • Click "OK".

Setting the cookie filters in Opera.

With Opera, you enable cookies, using the Advanced tab, in the Preferences wizard. Select "Accept", to accept cookies from all sites.

Setting the cookie filters in Safari.

With Safari, you enable cookies, using the Preferences wizard. The Privacy wizard, in Preferences, contains selections for cookies ("Cookies and website data”). Select "Always allow", to enable third party cookie access.

Cookie filters cause half of the problems reported, with many Blogger features.

Maybe 50% of the problems, reported in Blogger Help Forum: Get Help with an Issue, with many Blogger features involve cookie filters.

  • Comments.
  • The Cookie Advice Banner.
  • Post/Page/Template Preview.
  • Reading List.
  • Template Designer.

Stats and the "Don't track ..." option used to involve third party cookies, for many years. In March 2016, "Don't track" was rewritten to run under the URL of the blog, when being set - and now requires enabling scripts from the blog URL.

Consider how your blog is published.

If your blog is published to "blogspot.com", consider the non "blogspot.com" alias that may be relevant to your country. If your blog is published to a custom domain, consider the custom domain URL.

Many computers have other relevant settings, which block cookies.

Many blog owners and readers will have computers, and networks, with additional protection. Cookies, in the browser, may not be the only filter that needs to be checked - but this is a start, to learning how to control the cookie filters.

Having checked and corrected your cookie filters, continue by checking browser script filters - then check cookie and script filters, outside the browser. Be aware that many settings may not be obvious - and that both obvious and obscure settings may be updated, without your intention or knowledge.

Learn more.




Many #Blogger problems are cause by overly restrictive cookie filters. If you, a blog owner or reader, are going to use Blogger successfully, you need to configure your browser properly.

Commenting Requires Login, To Suppress Spam

Some blog owners don't understand the need to identify themselves, when commenting on our blogs.

We see an occasional question, in Blogger Help Forum: Get Help with an Issue, about comment authentication.
Why, if I've selected "Anyone - including Anonymous Users" under comment settings, for "Who can Comment?", do my visitors complain of having to login?
This blog owner, like many others, does not understand the Blogger spam mitigation policy, in Blogger Comments.

Blogger lets us select who we wish to allow to comment, on our blogs.

When we do not moderate, they require authentication, to cut down on the spam. Moderated comments, with CAPTCHA ("Show word verification") not required by the owner, appear to go straight to moderation.

Comment authentication makes genuine comments more normal.

By requiring authentication, Blogger makes it more likely that a comment, awaiting moderation, will be genuine - instead of more spam. This encourages us to moderate comments more frequently - and helps us publish moderated comments, more promptly.

And more frequent moderation discourages spam - and makes it more likely that we will see actual comments, later.

Blog owners choose how to allow comments.

As a blog owner, it's your choice how / whether to allow comments.





  • Anyone - includes Anonymous Users.
  • Everybody with a Google, or an OpenID, account.
  • Everybody with a Google account.
  • Blog members only.
  • Comments disabled.

Blog readers choose how to publish comments.

Depending upon the choices that you provide, your readers choose how they may authenticate.

  • "Anyone" allows a reader to comment anonymously - or identified.
  • If they wish to comment anonymously, they login, using a CAPTCHA.
  • If they wish to comment using a profile, they login, using an account.
  • Login is generally only required, with the first comment.

"Anyone" allows a reader to comment anonymously - or identified.

"Anyone" allows anyone to comment anonymously (if they wish). To cut down on spam, anyone commenting has to login.

If they wish to comment anonymously, they login, using a CAPTCHA.

Solving a CAPTCHA lets them remain anonymous - but still identify themselves as a person, not a bot. Any comments, awaiting moderation, or published, are more likely to be genuine - not spam.

If they wish to comment using a profile, they login, using an account.

They can login, as permitted, using a Google or OpenID account. Anyone able to login with a Google or OpenID account can still publish a comment anonymously, if they wish.

Login is generally only required, with the first comment.

If someone has to login repeatedly, to comment, they have a problem with identification, and filters. With cookies and scripts properly permitted, login (with the first comment) will be remembered (with any later comments).

The Blogger / Google login status, and the ability to post comments, is sensitive to both cookie and script filters. Your readers may need to enable (stop filtering) "third party cookies", in their browser and on their computer - if they wish to comment, most easily.



Both a #Blogger blog owner - and blog readers - get choices how to authenticate when commenting. Depending upon the choices made by the owner, the readers get more, or less, choices.

Stats "Don't Track" - You Cannot Satisfy Everybody

Blogger recently redesigned the Stats "Don't track ..." option - and removed third party cookies from the picture.

The "Don't track ..." wizard is now accessed from the blog URL. The wizard still produces cookies - but they are ordinary first party cookies, which are much less feared than third party cookies.

But, every silver lining has a cloud.

In making the "Don't track" wizard accessed under the blog URL, Blogger created a new requirement - which is no more understood, by some blog owners, than "third party" cookies.

"Don't track" now runs scripts from the blog URL, instead of the Blogger dashboard.

In order for a blog to observe - and preserve - the "Don't track" setting, any computer that the owner uses has to permit first party cookies - and all scripts - from the blog, instead of from the Blogger dashboard.

Since "Don't track" is designed to be used by the blog owner, this new requirement should not be a problem. Every blog owner should be able to trust herself / himself, to not add dodgy code to his / her own blog.

Many security products block scripts from personally owned blogs.

Unfortunately, general security practice is to block scripts from "blogspot.com", "blogspot.xx" (for every "xx" for every country local domain"), and preferably for blogs published to custom domains.

You can trust scripts from "blogger.com", and the Blogger dashboard. You cannot trust the individual blogs, since you cannot trust every blog owner. Even if you could trust some people not to intentionally try to hack your computer, you cannot trust everybody to not stupidly install malicious software from a very convincing hacker, providing one more "gotta have this" blog accessory.

And since you cannot trust the individual blogs, you will have filters. And those filters have to be adjusted, to trust your own blogs - if you want to ignore your own pageviews.

Some blog owners add security software, and don't know how to maintain the filters.

There are too many Blogger blog owners who have installed protective software on their personal computers - without knowing how to adjust the filters, in the protective software. And some of those owners think that it is a Blogger responsibility, to provide them instructions, how to adjust the protective software on their own computers - when only they are capable of knowing what they installed.



The new version of the Stats "Don't track" option is an improvement, because it no longer requires third party cookies - and involves the associated security risk. Unfortunately, it now requires blog owners to permit scripts, from the blogs themselves.

This is not a security risk, in that only personally owned blogs need to be trusted - but the blog owners do need to know how to adjust the filters involved. And not everybody with a computer knows how to configure their security accessories.

The New Stats "Don't track" Option, And Script Filters

The new Stats "Don't track" option is an improvement, to many blog owners.

"Manage tracking your own pageviews", as before, starts from the Stats dashboard page. The wizard now runs from a sub directory of the blog managed by the dashboard - and uses a normal (first party) cookie.

Now, blog owners no longer must enable third party cookies, to make Stats ignore their page views. This is an improvement - but it can still present a challenge, for some blog owners.

Besides filtering "third party" cookies, not all blog owners and readers will permit complete control by content under the individual blogs.

If you want "Don't track" to work reliably, enable scripts for the blog URL.

If you want the "Don't track" option to work reliably for your blog, you now must enable scripts to run under the published URL.

We have to trust scripts run from "blogger.com" - that is the Blogger dashboard. The Blogger dashboard is produced by Blogger Engineers - and if we trust Blogger to host our blogs, we have to trust their code.

Scripts which run under the individual blogs - "blogspot.com", local country domains, and custom domains - can be added by the owner of each individual blog. Not all blog owners should be trusted.

People who mistrust third party cookies may also mistrust scripts which run under "blogspot" etc. Unfortunately, to make "Manage tracking your own pageviews" work, you (the blog owner) now have to open up any script filters, which block content run as part of your blog.

Start from the Stats dashboard page.

Click on "Manage tracking your own pageviews".



"Manage tracking your own pageviews" now runs under the blog published URL. This removes "third party" cookies from the problem.

With a custom domain published blog, you must use the wizard in "HTTP:" mode.

By default, the new wizard runs in SSL mode. This will be a problem, with blogs published to custom domains.


If the blog is published to a custom domain, you will need to change "https" to "http".




Check "Don't track my views for this blog." - then close the tab / window.



The new wizard, "Would you like to have your pageviews counted when you visit this blog?", now runs as "blogging.nitecruzr.net", for this blog.

http://blogging.nitecruzr.net/b/statsCookieManage

If you publish to a custom domain, and you can correct the URL, you will see the same, for your blog. If you publish to "blogspot", you can see the same also. This is a script - and is subject to security filters.

And yes, there is no "Save" button, or link. Just the box.

Don't track my views for this blog.

Click the box or don't. As soon as you click, it's set.

You should trust your blog - even though you do not trust other blogs, in general.

Generally, as the blog owner, you can safely trust content run under your blog. You probably should not trust "blogspot.com", and all blog publishers, however. This means that you will require multiple filter rules - for every browser and security add-on, that contains a script filter.

  • Block all "blogspot.*". (Please!).
  • Permit "yourblog.blogspot.com".

If you publish to "blogspot.com", and live in a country which has a local domain, such as the UK, you need a rule to permit the local domain alias.

  • Permit "yourblog.blogspot.co.uk".

If you have multiple blogs - and want to block pageviews from being counted, for each blog, you need permissive filter rules for each blog.

  • Permit "yourblog1.blogspot.*".
  • Permit "yourblog2.blogspot.*".
  • etc.

If you publish your blog to a custom domain, you need a rule to permit the domain URL. For this blog, I need

  • Permit "blogging.nitecruzr.net".

If you do not permit the proper URL(s) for your blog, you will find Stats counting your own pageviews. Possibly, this will happen even with "Don't track my views for this blog." checked. In some cases, the check mark will be cleared, when you close the window.




Owners of #Blogger blogs who don't want their activity tracked by Stats now see a new "Don't track" wizard. Using the "Don't track" option no longer requires enabling third party cookies - and worrying about the security issues.

Unfortunately, this now means that the "Don't track" wizard may now be vulnerable to filters which restrict scripts that run under blogspot, and any custom domains.

Comments "Lost", With Google+ Comments Selection

Besides the confusion about being in the right Circles, some Google+ comments can be overlooked, because of the comment view selector.

We see odd problem reports, in Blogger Help Forum: Get Help with an Issue.
When a friend mentioned she'd commented, I found that odd - because I couldn't find the comment anymore. It had shown up previously - but it was now gone.
The view selector is not so obvious, either. It's similar to the "Compose" / "HTML" buttons, in Post Editor.

Besides the view selector, we see another possibility for third party cookies, unwisely filtered, to cause confusion.

Displaying comments for a blog, with Google+ comments involved, requires determining the identity of the individual viewer. Viewer identity - much more specific than "blog owner" / "blog guest" - is required, to determine visibility of specific comments, published against a given blog.

Here's an example, using a post from my recipes blog.


12 comments - from Circles + Public.




Circles + Public, selected.




6 comments - from my Circles.




Circles only, selected.



Can you see the difference? Other viewers of the blog will see a completely different set of comments.

Here's a different example, from a forum topic.


The blog owner, signed in, sees a count of 27 comments.




The blog owner, not signed in, sees a count of 42 comments.



There's actually 3 possible different displays - each showing a different comment count, and a different list of comments.

  1. Not signed in.
  2. Signed in, looking at "Public" + "Circles".
  3. Signed in, looking at "Circles" only.

One might expect #1 and #2 to be the same. In some cases, it appears that #1 displays a total comments count - though #2 and #3 display a count specific to the blog owner or reader. And I would not expect that one will actually see a precisely equal number of individual comments, displayed.

And if blog owner / reader access is affected by a third party cookie filter, both the comment count - and the list of comments displayed - will be smaller than what really should be displayed.

We now have a Rollup Discussion, in Blogger Help Forum: Get Help with an Issue, where we are requesting details from anybody experiencing mysterious loss of comments, If you are losing comments, please provide your details.



Owners of #Blogger blogs that use Google+ Comments don't realise how much more important their personal identity is, when looking for comments, that should be displayed with the individual posts. Personal identity is further relevant, with the "Circles" / "Public" comment selector, a feature of Google+ Comments.

And determining personal identity is affected, when cookie filtering becomes involved.

Stats And The "Don't track ..." Option, Used With Multiple Browsers And Shared Computers

The controversial nature of Stats and the "Don't track ..." option, which requires a third party cookie to enable the option to work, continues.

Even with all possible cookie filter properly set, and a consistent cookie clearing policy established, some blog owners persist in reporting that there are problems with Stats inconsistently observing the setting to not track their pageviews.

Not all blog owners realise that the Stats "Don't track ..." cookie is unique to each different browser - except when cookies are shared between computers.

Some browsers use cookies which are maintained as part of the personal profile, on the local computer - and some people may have cookies which are shared between multiple computers.
  • Computers which are shared by multiple people may have multiple sets of cookies.
  • Computers which are part of a local network may have a single set of cookies, per person, shared across multiple computers.
  • Some blog owners may use multiple Blogger accounts.
Each of these possibilities will create differing cases where the Stats "Don't track ..." cookie, like other cookies, may or may not be present when a given person is surfing to the blog in question - and which will cause Blogger to count (or to not count) pageviews from the browser being used.

Some computers are owned by, and used by, multiple people. The operating system will encourage each different person to maintain her / his own settings and styles, and to identify herself / himself when starting the computer. The settings and styles are maintained in a personal profile - and most browsers maintain the cookies as part of the personal profile. If two people, who share a computer, also share a blog, each person will have to select "Don't track ..." consistently - or face having inconsistent counting of pageviews, when reading the blog.

Some local networks, where various computers are shared and used locally, may use profiles which are maintained in common between the various computers. Changes to the profile (including cookies), made on one computer, may transfer to other computers. Clearing or setting cookies on one computer may affect presence of the same cookies, on another computer - and may again cause inconsistent counting of pageviews, against blogs involved.

Some blog owners may use multiple Blogger accounts. Similar to the issue of blogs shared by different people / used on shared computers, blogs read on computers used by people with multiple Blogger accounts will have the "Don't track ..." cookie present, irregularly. This, too, will cause inconsistent counting of pageviews.

Finally, as noted, clearing of cookies will affect presence of the "Don't track ..." cookie - and will cause unexpected counting of pageviews. This inconsistency will be more common with computers shared by multiple owners, and with computers shared across a local network.

Many blog owners use only one browser, and one computer - and own and use their own computer, exclusively. Any blog owner, noting inconsistent effectiveness of the "Don't track ..." option, however, may do well to at least consider the above issues, occasionally.

>> Top

Would Be Blog Owners Report Inability To Create A Blog

We are currently seeing frustration, in Blogger Help Forum: Something Is Broken, about new blog creation.

Would be new blog owners have various concerns
I can't create a blog - the "Create" button is grey (inoperative)!
or
It keeps saying
Verifying availability
when I enter a blog name!!
or even
It said
This blog address is available.
until I hit "Create blog!" - then it changed to
Sorry, this blog address is not available.

Each of these problem reports - and others - may come from people who don't read the instructions, for using the wizard. Alternately, some folks may be complaining about yet one more case of over done layered security.

The most obvious problems, in the blog creation process, come from people who don't understand how to use the "Create a blog" wizard.

Not every would be blog owner understands that 3 things must be done, to make the "Create blog!" button operative - and all 4 must be done, before the blog is actually created.
  1. Enter a Title for the blog.
  2. Enter an acceptable and available Name for the blog.
  3. Select a Template for the blog.
  4. Hit "Create blog!", with "This blog address is available." displayed.

When you choose a Name (aka "address" or "URL"), enter your choice properly.
  • Only enter the "xxxxxxx" part of "xxxxxxx.blogspot.com".
  • Only use lower case alphabetic characters ("a" - "z"), numeric characters ("0" - "9"), and dashes ("-").
  • Do not use a trailing dash (You cannot publish "xxxxxxx- . blogspot . com").

Besides the syntax issues when entering a blog name (URL), there is the unfortunate issue of competition in the creation process. Blog owners who are anxiously creating a new blog, based upon a current event - maybe a popular movie star, or an important political campaign - will be dismayed to see
Sorry, this blog address is not available.

If you are competing in real time, with other would be blog owners, for the name of your choice - and you take too long between Steps #1 - #3, and Step #4 - you may still see
Sorry, this blog address is not available.

Many people want to setup a blog, based on that blog name. Some may see the bad news, repeatedly, leading to one frequently seen complaint.
All the good addresses are taken!
And sometimes, to a more imaginative suggestion.
How do I get Blogger to re issue me the dormant address?
The latter question is one of futility.

Finally, the anxious blog owner may see
Checking address availability
for some time - possibly forever - if an overly ambitious cookie / script filter, or an intrusive security add-on is installed in the browser. In this case, the magical advice to
Clear cache and cookies!
or
Try a different browser!!
will be effective - though absent any attempt to diagnose the problem, one may not ever know what actual underlying problem may have caused the plaintive cry
I can't create my blog!

Blog Readers Report Comments, Supposedly Published Using A Mobile Computer, Appear To Disappear

Recently, we've been seeing a few problem reports in Blogger Help Forum: Something Is Broken, mentioning problems publishing comments on Blogger blogs, when using mobile computers.
My readers tell me that they can't comment on my blog, using an iPad. Comments disappear, when they try to publish them.
As with a previously explored problem with comments on a non mobile computer, this problem may involve unfamiliarity with the publishing sequence.

The dialogue involved in publishing a comment, when using a desktop computer with a full size display and a non mobile Blogger template, is not simple. Depending upon the various commenting options selected by the owner, the publishing sequence may be even more complex. Blog owners may need to consider the additional details involved in comment publishing, when using a mobile computer.

Using Blogger on a mobile computer involves various compromises - and the comment publishing process on a mobile computer even more compromises.
  • The small display size, on a mobile computer, makes finding the various controls involved a challenge. Both the small size of everything involved, and the necessity of repeatedly scrolling around the screen, looking for the controls used in comment publishing, is frustrating.
  • The "mobile template" is an attempt to make up for the small display size. The mobile template puts the various controls on a series of displays, with various buttons and links used to move from display to display.

People unaccustomed to the sequence of steps involved in the comment publishing process may not see all of the controls required, when using a mobile computer. Neither the wide non mobile template, nor the deep mobile template, displays the comment publishing sequence easily. People who are not very experienced with the comment publishing process, in general, might become confused with the displays.

As an example, let's look at the basic comment entry dialogue. So simple - when you are used to it, and can see all of the components.
  • On a desktop / full function display, you'll see an entry box, and a "Publish" button beneath the box. You use the keyboard and / or mouse to enter text into the box, then click on the "Publish" button.
  • When the required display space is larger than the physical screen space, you'll have a horizontal and / or vertical scroll bar, indicating that scrolling is required, to locate other display content. You'll use the mouse to manipulate the scroll bars, and make other portions of the display visible.
  • A mobile display will have an entry box, and an on screen keyboard. The onscreen keyboard will occupy a fixed amount of display space, with the entry box occupying the available remainder.
  • The mobile display won't have scroll bars - if other portions of the display are not immediately visible, you'll use your finger to scroll around the screen. If you are not familiar with screen layout, you'll have to scroll around, aimlessly.
  • The "Publish" button will be somewhere near the entry box - but depending upon screen size and orientation, may not be immediately visible. You may have to scroll around the screen to find the "Publish" button.
  • People not used to using a mobile computer may be unable to find the "Publish" button. Finding other display content that may appear to replace the "Publish" button, they may be confused when their comments are not published, and report that their comments disappeared.

Both the authentication sequence (when authentication is required), and the CAPTCHA entry sequence (when a CAPTCHA is involved), when involved in mobile computing commenting, will make the comment publishing process even more complicated. The authentication sequence may be more complex, if the browser in use has a problem with Blogger authentication - and "third party" cookies.

Since most blogs are designed primarily for non mobile computer use, commenting using mobile computers may not be obvious, for a while. Many readers may simply not publish comments, to the same activity level, when using their mobile computers.

>> Top

Stats And The "Don't track your own pageviews" Option On Mobile Computers

As mobile computing becomes more popular, we're starting to see questions about use of the Blogger dashboard on mobile computers (iPhone / iPod, PDA, smart phone), in Blogger Help Forum: Something Is Broken. Most recently, we're seeing people trying to use Stats, and the "Don't track my own pageviews" option, with Blogger on mobile computers.

Problems with Stats and the "Don't track ..." option are not unknown, in the past. We've helped many blog owners with this setting, which is sensitive to cookie and script filtering in general - and to "third party cookies" in particular. "Third party cookies" may be filtered in any of several places, any which will interfere with "Don't track ...".

The "Don't track ..." option, when seen as a problem with "full size" computers (desktop, laptop / notebook), may involve any of various "layered security" settings. In general "full size" computers use a somewhat standard software infrastructure. While any of several operating systems (Apple / Macintosh, Chrome, Linux, Microsoft Windows), and various browsers (Chrome, Firefox, Internet Explorer, Opera, Safari) make use of Blogger an occasional challenge on "full size" computers, there is some common features between the various operating systems and browsers.

With the various "operating systems" and browsers on mobile computers, we're seeing more discrepancies in features offered. In particular, not all "mobile computers" have explicit settings to allow / disallow "third party cookies" - or even cookies and scripts, in general. If these settings are not present, it's likely that these computers do not support such details as "third party cookies".

Without the availability of "third party cookies", Blogger can't support the "Don't track ..." option. Here, I'll note that this option is specific to each individual browser, on each individual computer. One must set the option - and browse the specific Blogger blog - using the same browser, for the option to work. This is not an option that can be set on a per user basis, and apply to all browsers used by a specific user.

>> Top

Backtrack 4 Download for Windows VMWare & Torrents

BackTrack is a live CD Linux distribution that focuses on penetration testing. A merger of two older security-related distros — Whax and Auditor Security Collection — BackTrack bundles more than 300 security tools.

BackTrack is based on the SLAX distribution (a live CD derived from Slackware) and runs a patched 2.6.20 kernel. It offers users both KDE and Fluxbox desktop environments.
To start using BackTrack, download the ISO image and burn it to a CD. Insert the disc and boot your machine. Once booted, the system start at runlevel 3 (text mode), where you must log in as root and choose whether to start KDE or Fluxbox or just use the terminal.

BackTrack provides clear, concise instructions for logging in, starting the window manager, and configuring the video card before you see the login prompt. If you’ve never used BackTrack before, use a graphical environment, since it will help you understand how all the included applications are organized and let you take advantage of some graphical utilities. When the window manager comes up you’ll find some ordinary desktop programs, such as Firefox, Gaim, K3b, and XMMS, within a nice environment with beautiful wallpaper and window transparency.

Don’t let the attractive appearance fool you — BackTrack packs a punch. The security tools are arranged inside a Backtrack submenu. This is a big improvement over older releases, because you can easily follow an attack methodology: starting by collecting information and end by hiding your actions.

The tools are arranged in 12 categories, such as vulnerability identification, penetration, privilege escalation, radio network analysis, and reverse engineering. Among the more than 300 security tools you’ll find such familiar names as the Metasploit Framework, Kismet, Nmap, Ettercap, and Wireshark (previously known as Ethereal).

One of the core points of this release is the attention to detail. For example, when you choose most of the programs from the Backtrack menu, a console window opens with the output of the program’s help. Some tools have been bundled with scripts that in a few steps configure and run the program for you. For example, if you run the Snort intrusion detection application, a script asks for some passwords and then sets up MySQL, Apache, Base, and Snort itself so you can easy browse alert logs via a Web browser.

If you open Firefox or Konqueror you’ll find some useful security-oriented bookmarks. In the Documents submenu the developers have included PDF manuals for the ISSAF and OSSTMM security methodologies. There are also some tools that you wouldn’t expect inside a live CD; for example, you have a popular debugger for Windows, OllyDbg, which runs fine through Wine, so you can even debug .exe files.

If you like the live CD, you can install BackTrack to a hard drive (decompressed, it requires 2.7GB of space) or USB memory stick (compressed, 700MB) using a graphical wizard.
While BackTrack is an excellent tool, nothing is perfect. Unfortunately it doesn’t include Nessus, the popular security scanner, due to license problems. I tried to start PostgreSQL from the Services menu, but it gave an error. And it seems as if the developers forgot to update the Backtrack menu in Fluxbox, because it offers the previous version arrangement. Tools like VMware and Nessus appear on the menu but are broken links because they have been removed from this release.

Despite a few little bugs and problems, BackTrack is the best distribution I’ve found for handling security-oriented tasks out of the box.

Download Links :

Last Update: 11.01.2010
Description: Image Download
Name:: bt4-final.iso
Size: 1570 MB
MD5: af139d2a085978618dc53cabc67b9269



Description: VM Image Download
Name:: bt4-final-vm.zip
Size: 2000 MB
MD5: 733b47fad1d56d31bc63c16b3706a11c



FOR OLDER VERSIONS CLICK HERE

To learn HOW TO USE BACKTRACK & for all BACKTRACK TUTORIALS & COMMANDS: CLICK HERE & JOIN THIS FORUM

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code