Solved

Wordpress Editing

Posted on 2013-06-12
23
449 Views
Last Modified: 2013-11-13
Hi Experts,

I have a friend who has a Wordpress blog page setup for her charity, and has asked me to do some editing on the site as she has not been able to contact the original designer/maintainer for several months.

Now, I should point out that I have a little programming experience from university, but nothing in PHP and/or Wordpress - to be honest I had never heard of Wordpress before she asked me to look!  My experience is mainly in Java and Perl.. but very limited as was a long time ago!!

All that she has given me is a frontpage login to Wordpress that would allow me (if I wanted to) add and edit the blog.. and an FTP login for ALL of the files related to the site, including PHP and JS files.  I do not have administrator privileges to the frontend change the theme or anything like that, so I'm not sure exactly how far I would be able to take this anyway!

She has asked if I could put the sponsors logos on the sponsors section of the blog - which from what I can work out is just a #-section of the site - the sponsor part on the sidebar point to a section in the blog, that when you click it, it takes you to that section.  I want to know where I find the PHP file to edit this and insert the logo into this section.

Also, she has asked me to allow them to archive the blog by date - this one I don't even know where to start!!!

Any help please?  Would be greatly appreciated.

Also, my initial response when she explained that the original designer and bloke who is meant to be maintaining it has been uncontactable, was to completely redesign the site with Joomla! (which I am learning for part of my job).. unfortunately this isn't currently an option because it would mean setting up another domain name (as we don't have access to the current domain, or cPanel).. and as it is for charity, I don't want them to have to change/lose all of their advertising efforts simply because the domain has changed from theircharityattempt.com to theircharityattempt.org or whatever :(

Thank you
beefstu123
0
Comment
Question by:beefstu123
  • 12
  • 10
23 Comments
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243349
So what exactly is your question?
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243374
How do I do it.. how do I find the PHP files I need to edit to get the sponsor logos where they need to be, and is it possible to archive the blog by date?
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243388
Wordpress stores its content in the database, so if all you have to do is add logos to a certain page, you login to the backend and locate the specific page and edit it. Once you are in edit mode, you can upload and insert logos using the add media button in the visual editor.

For the archive, Wordpress automatically creates archives by month and year of Posts (not Pages) so all you need to do access them or embed them into your menu or widget area.

I strongly suggest you take a few hours and read through the Codex, especially the Getting Started section.

http://codex.wordpress.org/
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243389
Yes, I understand all of that, but I don't have backend access.. only FTP access to the individual PHP files and such..

The old maintainer of the site isnt able to be contacted which is a massive pain!!
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243398
This is a problem then.  There isn't a single file that you can edit like a standard web site that will make the change you describe.  

Do you have any access to the database at all?  If not, do you at least know the admin username?
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243401
I know :(

no and maybe.. I MIGHT have the username - but only from a blog entry he created when he first created the site - as I mentioned, I have full access to the files via FTP, and limited access to the frontend editing of the blog.. which basically allows me to create a blog entry and the like..
0
 
LVL 70

Accepted Solution

by:
Jason C. Levine earned 500 total points
ID: 39243403
All you need is the admin username and FTP access to hijack WordPress :)

Try this:

http://codex.wordpress.org/Resetting_Your_Password#Through_FTP
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243406
If the above doesn't work, a few more scripts to try :

http://kuttler.eu/code/wordpress-password-reset/

http://www.jojojoson.com/forgot-wordpress-administrator-e-mail-and-username.html/

Have not tested either of the above, use at your own risk.
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243407
AWESOME!!!

I will give this a go (with the permission of the owner of the site).. and let you know how I get along :)
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243431
Just another quick question before I do any of this.. would his admin username be the same name that would have edited the blog in the very first days that it was setup??
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243450
Maybe. You can set how you display to the world on a user by user basis but if you see a single-word, all-lowercase author name on a post, you may have it.

Wordpress defaults to "admin" but most smart users don't use the default.

What you can do (maybe) is go to site.com/wp-admin and click the Recover Password link there.  You can then feed the resulting form your username guesses.  If you guess right, you will get a success message and can then use one of the methods above to reset the password.
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243452
There's another way to do this via the database but it requires a bit more work, some guessing and a lot of luck.  We'll hold that one back and see if this works.
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243485
so, if I got a "check your e-mail for the confirmation link" then I have the username correct??
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243492
I'm guessing yes, because I just tried a random name - that wouldn't be in the system and it said "Error: invalid username or e-mail"

Just waiting for the final approval from the site owner before I change the password.  It sucks how much stuffing around had to happen to gain access to something that is actually hers in the first place!!
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243494
Yep.  Now try http://codex.wordpress.org/Resetting_Your_Password#Through_FTP and hope the user is ID #1.  

Again, clever people change the user ID of the first admin from 1 to something random precisely to render this method useless :)
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243496
It sucks how much stuffing around had to happen to gain access to something that is actually hers in the first place!!

Yes, but this is as much her fault as the other guy.  She should be learning a lesson to always, always demand full administrative-level access to anything she has created on her behalf.  Never trust the developer will be responsive and own your own IP.
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243508
Yes, but this is as much her fault as the other guy.  She should be learning a lesson to always, always demand full administrative-level access to anything she has created on her behalf.

Oh she will learn!! haha this guy is a friend of a friend of hers so I will be sure to rub it in every time I speak to her :)

Fingers crossed the user ID is 1
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243524
Alright, that was weird.. I put the line of code in, and attempted to login with his username and the new password, and it simply went back to the login screen - no error saying wrong password or anything.. have I done something wrong?
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39243527
BINGO - took the line back out and successfully logged into the full administrator control panel!!

THANK YOU SOOOOO MUCH!!
0
 
LVL 70

Expert Comment

by:Jason C. Levine
ID: 39243587
Great.  Don't forget to close the question.
0
 
LVL 2

Author Closing Comment

by:beefstu123
ID: 39243594
Thank you again for an excellent and speedy response :)
0
 
LVL 11

Expert Comment

by:RedLondon
ID: 39244835
I know the question is closed, but it sounds like you (or at least the charity) has another storm brewing

If they're paying the guy who did a disappearing act for the domain name and hosting, there's only a finite time before it expires.

www.charity.com/cpanel with the FTP details will get you logged into cPanel but that's not going to do you any good once the hosting account expires.  Take a backup while you can, via cPanel - files and databases will go into a tar.gz which you can download and keep.

The time to start working out who is actually asking for money to keep it going and renewed is now, rather than the day it stops working.  Another cpanel webhost will be able to restore your account using that backup file, but you'd still need to change the DNS on the (renewed) domain name.  Good luck.
0
 
LVL 2

Author Comment

by:beefstu123
ID: 39246242
Thanks RedLondon - I did actually realise this and had a look at the expiry date of the domain and hosting and it actually falls AFTER the charity event..  

I will, however, take a full backup of the site because if he decides to get nasty about someone (me) taking over and doing his job, he could just cancel the hosting plan and leave them without anything!!  So, thank you again for your suggestion :)
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
spacing 5 31
Adding Pipe Delimeter  between buttons in css 4 17
Hide vba in gp 7 43
How can I do a Select All on this page? 8 12
In order to have all security and back ups taken care of, WordPress users can sign up for services with WP Engine.
If you’re thinking to yourself “That description sounds a lot like two people doing the work that one could accomplish,” you’re not alone.
The purpose of this video is to demonstrate how to set up an RSS Feed on a WordPress Website. This will be demonstrated using a Windows 8 PC. Feedburner will be used for this demonstration. Go to your WordPress login page. This will look like the…
In this fourth video of the Xpdf series, we discuss and demonstrate the PDFinfo utility, which retrieves the contents of a PDF's Info Dictionary, as well as some other information, including the page count. We show how to isolate the page count in a…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now