Skip to content
Irish Mountaineering Club IMC, Cumann Sléibhteoireachta na hÉireann
  • Facebook
  • Instagram
Join Now
Book the Hut
Members Login
  • About
    • Introduction
    • Contact Us
    • Documents
      • Constitution
      • Privacy Policy
    • Expeditions
    • Kindred Clubs, Handy Hostels
    • Library
    • People
  • Join
    • Introduction
    • New Membership
  • Blog
    • Article
    • Obituary
    • Review
    • Route Info
    • Training
    • Trip Report: International
    • Trip Report: Ireland
    • Other: Bottom of Home Page
  • Events
    • Introduction
    • Calendar
  • Hut
  • Publications
    • Introduction
    • Books
    • Newsletters
      • 2010-now
      • 2000-2009
      • 1990-1999
      • 1980-1989
      • 1970-1979
      • 1960-1969
      • 1950-1959
    • IMC Archive
    • Videos
  • Training
    • Overview
    • Introduction to Trad climbing Programme
Irish Mountaineering Club IMC, Cumann Sléibhteoireachta na hÉireann
  • Log In
  • Join the IMC
  • About
    • Introduction
    • Kindred Clubs, Handy Hostels
    • Library
  • Blog
    • Article
    • Obituary
    • Review
    • Training
    • Important Information
  • Events
    • Introduction
    • Calendar
  • Hut
  • Publications
    • Books
    • Newsletters
      • Newsletters 2010-2018
      • Newsletters 2000-2009
      • Newsletters 1990-1999
      • Newsletters 1980-1989
      • Newsletters 1970-1979
      • Newsletters 1960-1969
      • Newsletters 1950-1959
    • IMC Archive
    • Videos
  • Training
    • Overview
    • Introduction to Trad Climbing Programme 2026
Join Now
Book the Hut
Log in
  • Webmaster Handbook

    Webmaster Role

    The role of the webmaster is to maintain the IT infrastructure and manage access e.g. Website, Social Media, Groupspaces. The actual content is owned by the Publicity Officer. Having said that it is good if you can contribute content and encourage others to do so.

    This Document

    Please maintain this document to simplify any future handover and as a resource in case anyone else needs to temporarily look at this stuff…otherwise you will have to do this job forever.

    Routine administration

    • Keep the website secure (backups, blocking suspicious activity)
    • Maintain official email addresses
    • Manage Permissions (Committee)
    • Maintain website pages
    • Keep WordPress+Plugins Up-to-date
    • Keep hosting and domain current
    • Moderate Comments
    • Manage Social Media Acounts

    Logins

    WordPress:

    • username: IMCWM2016
    • address: https://www.irishmountaineeringclub.org/wp-admin/

    Hosting:

    • address: http://cp.blacknight.com
    • username: irishmc

    SQL

    • 172.16.3.45
    • u1015344_root
    • Database db1015344_wpimc
    • Legacy database:db1015344_mambo

    FTP:

    • address: irishmountaineeringclub.org
    • username: imcftp16

    Groupspaces
    Membership List
    This is managed by the Membership Secretary.
    this is the master list of club members. It is unrelated to the web site but try to keep it in sync.
    Occasionally audit website users and remove non-members

    Facebook:

    • address: https://www.facebook.com/IrishMountaineeringClub

    Twitter:
    @irishmountclub
    Note: Twitter account was created in a past with an automatic feed of forum posts. In the aftermath of NorthfacejohnGate this was shut down as forum post were removed from public domain, so there is very little traffic or followers. It’s really up to yourself if you want to promote this.

    Website statistics:

    • address: https://cp.blacknight.com/awstats/418/cgi-bin/
    • username: irishmountaineeringclub.org

    Technologies

    The site is based on WordPress. It is mostly wordpress plugins and layouts. There are a few php scripts that can be used to customize the presentation.

    Common Tasks

    Save Minutes

    Encourage secretary to do this themselves but if they are unwilling..
    Normal:Edit page Minutes. Upload media item and add a link to page.
    AGM:Edit page AGM Minutes. Upload media item and add a link to page.

    Add/Remove a Committee Member

    See Committee Handover section below

    Enable @imc mailbox

    If people want to use an @imc mailbox then on Blacknight reset the password on their officer@imc email and send it to them with a link to email-setup details that’s in the committeee section of the site. They will need to set up their mail client themselves (so they need to be somewhat tech savvy) When they are up and running you can remove their personal email from the redirect list.

    Publish Newsletter

    WP-Admin – Edit the Newsletter Page
    Add PDF as a media item and add a link to the content. Create a table of contents (see Below).
    Publish a link to the Newsletter on Facebook.
    Tweet a link to the Newsletter on Twitter.

    Reset Passwords

    If users have problems you may need to edit the user in the WP-Admin users page, generate a password and save it then email it to them.
    Note: There is a “forgot” link which may work but its very flakey.

    Renew Subscriptions

    There are Blacknight subscriptions both for hosting and also for the domain name. The Treasurer will pay these but may need a gentle reminder.

    Review Security

    See details of plugins below (section 13)

    Backups

    Good to take a dump of database and files regularly. (You could omit wp-content and just do this occasionally as it huge) Details below,

    Change Splash Page Images

    WP-Admin – FWB Slider Pro – Slide Settings – +
    Enter the URLs of the images here
    Usually swap in some snowy pictures during winter.
    Nag the Publicity Officer to find some fresh ones

    Monitor Facebook Messages

    If people message the FB page ask the appropriate officer to respond.

    Facebook Content

    Share stuff members post to their personal accounts.(or encourage others to)(you might need to first ask people to set privacy on these items to public)
    Share climbing stuff of interest.(or encourage others to)
    Create Facebook events to advertise public events (or encourage others to i.e. Meets Secretary)
    Share stuff user posts to our wall wall if of interest.(otherwise it’s hidden on lhs under the fold)
    Delete any spammy/irrelevant posts
    Encourage people to contribute.
    Recruit other to edit the page.
    Change the banner image from time to time.
    Post links to Newsletters when published on IMC site.
    Post links to any non-trivial blog when published on IMC site.

    Things to watch out for

    Backups:
    This can be done manually
    Files:

    • Using an app such as FileZilla
    • Connect with FTP to the remote site and sync WebSpace content locally (2GB+)
    • For a partial backup omit the wp-content files

    SQL:

    • Script the SQL DB in MySQL
    • Login To https://cp.blacknight.com/
    • Databases – WordPress(wpimc) – Browse – Export
    • Select All – Check Save As File – Zipped – Go
    • Save file generated in Downloads to an archive location

    Suspect activity: There is suspect activity on the site all day every day. The “hosts, last visit” page in the “website statistics” section shows all recent activity. Normal activity is indicated by the “hits” figure being much higher than the “pages” figure; others (apart from the web server) are likely to be spam/hacking attempts. You can block suspect addresses by editing the .htaccess file. Alternatively use security plugins.(See Below)

    Website user levels: The webmaster user account in the website has “administrator” privileges. Other committee members have “Editor” privileges which allow them access to the “committee” section.

    https://www.irishmountaineeringclub.org/wp-admin/users.php

    Uploading files: Should be done using the WordPress Media functionality. https://www.irishmountaineeringclub.org/wp-admin/media-new.php

    Archiveing Forums: On the old Mambo forum performance would degrade when post volume exceeded 300. The WordPress-BBforum appears to perform OK so folders have not been archieved.

    Moderating forum: When signed in to normal site as the Webmaster you will see extra links above all posts to edit,move,spam, or delete them. Sometimes user post duplicates…delete one of these. You may also want to delete anything deemed offensive or inappropriate. It would be preferable to edit posts if possible. You may need to edit posts to clean up broken links or image tags.

    Protecting Content: When you create/edit pages in the wp-admin site there is a “Word Press Access Control” panel on the right that you can use to restrict access. Members (Signed in users only) Members: Editor + Administrator (Committee Only)

    Public: Blog Members: Forum, Information, Profile+Pay,Sub+Library are registered Committee: Committee

    WordPress/plugin Versions: Keep these as up to date as possible or you will be letting yourself vulnerable to hacks. It upgrades break anything in doesn’t matter, just throw away that content.
    Be very circumspect in installing any plugins. Make sure that they are well maintained code from a reputable source.

    Manage Users

    https://www.irishmountaineeringclub.org/wp-admin/users.php

    Select a user and Delete or Edit

    Click on a user to change permissions

    Standard User – default for anyone who has confirmed their email Editor – All user name should be the users real name. Update this for any bashful new users or just delete them is they are unrecognized. Delete any obviously spammy accounts created.

    You may want to ocassionally cross reference WP-users with Groupspaces. Drop anybody who is not a member. There is a “user” callled “ex-member” who you can assign content.

    A handy way to review new users is to open Blacknight – SQL – WordPress-DB – wp_users table – sort by user-activation (descending). This will show you recently added users. If the display_name is not the users name the update it of delete the user. You can also cross-reference this with groupspaces member list.
    If you are deleting users there is a dummy account “ex-member” that you can assign content to.

    Email Accounts

    Open cp.blacknight, menu-email To redirect an address: Click on It, Forwarding, Forward List(In Green Bar),

    You can either use mail as a simple redirect or else enable the mail box if people wish to send mail from that account.

    Committee@ is a group mail and need to reflect any committee changes All@ is linked to a CriticalPath account that does not work so is currently not in use as the process is undocumented and broken. Groupspaces is used for broadcast mails and is managed by the publicity/membership officer.

    Facebook

    Page https://www.facebook.com/IrishMountaineeringClub

    Roles

    Admin Panel – Edit Page – Manage Admin Roles Use the page to add/revoke/update role access.

    e.g. Typically Admin = Webmaster & Publicity Officer Editor = Secretary + Meets Secretary + Any others you wish to add. The more people who contribute the better. If people are active Facebook users try and recruit them as content editors. (btw To add a person to a page role they need to be your friend)

    Posting To Wall

    This is currently open to public. You can change this permission in privacy settings if it becomes an issue.

    Sharing Content

    If sharing content such as club members photo albums make sure that their album privacy is set to “everyone” and not just “friends” or this won’t work

    Events

    Keep in mind that access is essentially public. Please state if events are open to public (e.g. Slideshows) or Members Only (eg Meets). Don’t add private information for member only events…just say “look at website for details”

    Post, Comment, Like As

    Facebook allows you to switch between your personal profile and IMC. Please us IMC when managing content. Please do not “Like” any IMC content as IMC as this just looks pathetic. (You can like stuff as yourself if you really want to). When adding new editors ask people to set their default attribution as follows
    Open IMC Page https://www.facebook.com/IrishMountaineeringClub/
    Click on “Settings” (on the right hand end of the top white menu)
    Click on “Post Attribution” (4’rd item in the left-hand-menu)
    Set the default to be “Post as #your-name# “

    WORDPRESS MANUAL FOR IMC WEBSITE ADMINSTRATOR

    1.LOGGING IN

    Log-in a the front end and the type in this url in a separate window in the same browser: www.irishmountaineeringclub.org/wp-admin. You will see a dashboard screen now.
    (Note: You must log-in to the site to use the dashboard, you cannot directly access it (for security reasons))

    2.DASHBOARD

    You can now see dashboard screen that has all the options available. There is some main WordPress features here plus additional which are selected plugins that are responsible for extra features.

    WordPress standard features are: posts, media, pages, comments, appearance, plugins (that is where you add plugins), users, tools, settings

    If any new updates are marked as available install them. There are over 35,000 know exploits to attack wordpress so keep everything as current as possible.

    3.MANAGING PAGES

    All the pages that are visible in the site, except blog, news and forum are stored, managed and added through ‘Pages’ tab on the main menu. Click on it and you can see on the right hand side a list of all the pages. Some of them have a little padlock on the right. Those pages can be only visible to logged in members. If you hover over a title you will see a small menu showing under it which will allow you to edit every page.

    More info: http://codex.wordpress.org/Pages_Screen

    ADDING NEW PAGES

    To add new page click on to ‘Add New’ under ‘Pages’ tab in the menu. This works exactly like ‘Posts’. Add page title, content, image and save. In top right corner you can choose if this page will be only visible by logged in users. Use ‘no sidebar page’ template from ‘Page Attributes’ below to make sure you have no side bar in your new page. Scroll down and make sure that you disable ‘Allow comments’ and ‘Allow trackbacks and pingbacks’ in ‘Discussion’ section. You can choose to write some code if you like in your content. To do that just switch between tabs ‘Visual’ and ‘Text’ that you can find at the right top corner of the content box.

    EDITING EXISTING PAGES

    To edit one of the existing pages hit ‘edit’ from the menu below the page title in the list of all pages. You will see that page with all the content. You can switch here between tabs ‘Visual’ and ‘Text’ to see how things look different. Some of the pages are easier to manage in ‘Text’ as there is a lot of formatting and you need to make sure that what you adding is in the right section otherwise you can break the arrangement of the page. If something like that happen you can always go back to previous version. All the versions you can find under ‘Revisions’ just under content box. I will go through some of the pages to explain how add additional content to them.

    NEWSLETTERS – newsletters are organized in 4 pages. Each page is representing a tab which lists different decades.

    This page is easier to update in the ‘Text’ editor where you can easly see all the different elements.

    Each page has the same first few lines and navigation/list of tabs which are enclosed in a <div class=”news-nav”> This element has to stay untouched on all those 4 pages for it to work. To change year heading on the news-menu from 2014 to 2015 you can change number 4 to 5 no problem just remember to make that change on all 4 pages.

    Now to add new newsletters – Each separate newsletter is locked in a table. To start new table just use this one to open [table] and [/table] to close. The inside of the table is separated by a coma. Make sure there is no additional commas in the text as they will render as another column in a table.
    Having added a newsletter it is good to publish a link to it on Facebook and Twitter.

    COMMITTEEContent restricted to committee members. (not only content is restricted and linked media is in the public domain)
    The Committee-FAQ is something the publicity officer created. If issues arise for committee users it would be good to document them here.

    CLUB – DOCUMENTSAnything that doesn’t fit anwhere else.

    IMC HUT – In this page content is divided into two columns. They are wrapped within div tags so to see it you have to go to ‘Text’. In here you can see <div class=”hut-left”></div> and <div class=”hut-right”></div>. Make sure all the changes that you make are in a right section and that those div tags stay the same.

    JOIN IMC – similar to ‘IMC hut’ page there is <div class=”join-left”></div> and <div class=”join-right”></div> You can see those if you switch to ‘Text’ editor.

    TRAINING – same as the above there is <div class=”train-left”></div> and <div class=”train-right”></div> that is visible in ‘Text’ editor.

    EVENTS, FORUM, REGISTRATION, USER PROFILE – those pages are ruled by plugins so if you open one of those you can only find there a shotcode referring to particular plugin but all the content is added and maintained through the plugin itself.

    HOME PAGE – This page has very little text. If you go to ‘Text’ editor you can see that those lines are wrapped in divs and spans. This text is carefully positioned on the page so be careful about changing as it may not fill into the container anymore and will have to be adjusted in css.
    If you do edit this check the layout in multiple browsers/devices especially Microsoft IE/Edge.
    This is effectively a splash page…all that’s missing is the “click here to enter” button. There is no facility to display any dynamic information to users unless you do some kind of hack. Think of it as being back in 1995.

    4.MEDIA
    This is where you can see all the media that has been added to the site. In Library there are stored all the images, videos, pdf and word documents. To get the url for each of them hover over the title and click edit. You add Alt tag in here for each image with help SEO.
    Media is uploaded into monthly folders so it is a real pain in the ass to find anything previously uploaded.
    N.B.All media uploads are in the public domain. There is no security in wordpress. Do not upload any sensitive or private information.
    More info: http://codex.wordpress.org/Media_Library_Screen

    5.COMMENTS
    In here you can see all the comments left at the blog section (the only section that is allowing comments). From here you can delete comments, add to spam, edit or approve them.

    More info: http://codex.wordpress.org/Comments_in_WordPress

    6.FORUM
    This is a plugin – if you click Topics you can add an additional forum item or a topic to the list of already existing so members use them. Don’t forget to set visibility to private so its only visible by logged in members.

    More info: http://codex.bbpress.org/step-by-step-guide-to-setting-up-a-bbpress-forum/

    7.USERS
    Here you can see all the users that are register to the site. Hover over User name and you can delete or edit – change their privileges. You can also manually Add New User. Use ‘Search Users’ to easily find who you are looking for.
    It is the policy of the club that all forum users must use their real names on the forum. If anybody violates this just update their account and set their “display name” to their real name. If they are not happy with this just delete them from the forum.
    More info: https://codex.wordpress.org/Roles_and_Capabilities

    8.MENUS
    To see menu structure go to ‘Appearance’ -> ‘Menus’

    All the pages that have been chosen for the menu are listed on the right hand side. You can delete items from menu and add them again. You can add items from list of pages, links, categories and few others that you can see on the left hand side. After you finish changing ‘save’. Be careful with adding to many elements to menu. It gets cluttered and less readable. It’s not a good practice to have lengthily menus.

    More info: http://codex.wordpress.org/WordPress_Menu_User_Guide

    9.WIDGETS
    To get to this section go ‘Appearance’ -> ‘Widgets’
    You can find in here sidebar and footer content.
    On the right hand side there is a list of available widget locations.
    More info: https://codex.wordpress.org/WordPress_Widgets

    CONTENT SIDEBAR – that’s an area that is located next to blog posts in blog section. You can see there search, related posts and archives.

    HOME FOOTER – that is the black strip line at the bottom of each page. When you open it you can see the text widget there with a short line of text. You can update year in here.

    PAGE FOOTER – this is a thick footer that you can find on each page except home page. We have 3 widgets here. Facebook and 2 text widgets. Be careful with adding more content to this 2 text widgets as they are designed to a specific size.

    FOOTER WIDGET AREA – This is home page thick footer area. With Upcoming Evens and Latest News. They are configured to fit into a space that they are placed so be careful with playing with settings.

    PULLOUT WIDGET CONTAINER – this is where the LOG IN pull out widget sits.
    All widgets have a lot of custom css assigned to them to get the desired look. Making changes may require adapting css to fit new conditions.

    10.PLUGINS
    This is where you can add new plugins or deactivate and delete unused. Every now and then you will be asked to update plugins. It’s ok to do so as my custom css that I additional wrote is separate and shouldn’t get affected. The only plugin that I don’t want you to update ever is ‘Floating Social Media Icon’.

    11.FWB SLIDER PRO
    This is the sliding background images that are on the home page. To change slides go to ‘slider settings’ in here hit ‘browse’ to add new image. Images that I used are 1400px X 800px – if you can keep this dimensions for any future images it would be best. Make sure that images have

    12.AAM
    This is where you can change what sort of privileges each of the level has.

    Click on the level you wan to edit on the bottom right hand side. Click on each of the section that you have in the middle to open tabs to make changes in each. Save your changes. There is no need to make changes to anything else than Admin menu but if you wan to explore more there may be some more useful features there.

    13.1.Exploit Scanner
    Will return a lot of false-positives. May need to download a hash file from git if you update the wordpress version. Running a scan (Plugins – Exploit Scanner – Scanner Settings – Run The Scan) may help identify malicious code

    13.1.iThemes Security
    Configure with Dashboard. You might want to whitelist yourself.(menu Security)

    13.1.Wordfence
    Schedules scans.
    “Live Traffic” is usefull…Logons/Logouts will identify hackers you can block
    “Blocked IPs” does what it says on the tin.
    “Options-Login Security Options” is a good place to block any hacker usernames you notice appearing repeatedly.

    In general WordPress code is rancid with exploits so the more you lock down the better.
    Wordfence does generate mails listing file changes that are useful to monitor. Most are benign and are triggered by updating plug-ins etc. Beware of any unexpected core files updates. EMails are also triggered for Admin logins, password resets, lockouts. You may want to blocky IPs with dodgy activity or advise the Membership Secretary if there are new users struggling with login process.

    You might want to add/remove security plugins…it really whatever works for you.

    14.CODE EDITOR
    Code editing with in the wp-admin pages is disabled as this is hugely insecure. Code must be edited offline and uploaded.

    15.TEAM MEMBERS
    All the team members profiles can be found under ‘Team Members’ on the menu in dashboard. You can edit each of them by hovering over the name and clicking on ‘edit’. Hit ‘save’ once you happy with changes. To change profile picture go to ‘Featured Image’ at the bottom. Remove current image and upload new. Display order is an attribute on RHS of page that can be edited.

    16.GALLERY
    This pages displays a number of high quality images that are used on the splash page carousel. It would be great if you can get new images (Landscape not portrait and reasonable high-res) (if too high-res performance will degrade badly especially on mobile so be careful. (Publicity Officer should supply).
    Note: On occasion the Meets Officer has organized a photo competition in an attempt to get some fresh content. Unfortunately the general standard is usually atrocious, but you might get one or two usable images.
    Note: In the past there were also user gallerys hosted on the site. These fell by the wayside as nobody used them in the last 10 years since Facebook/Instagram etc. took over the world. The content is still online /wp-content/uploads/zoom. Occasionally you will get somebody suggesting that “we should host a gallery” on the site. Best to knock this kind of luddite nonsense on the head. Users can share pictures on the forum, but its a bit of a usability horrorshow. Blogs are much easier to manage, so I’d encourage users to share their pictures as a blog instead (or use facebook)

    17.Presentation
    The apperance of the site is based on a WordPress template. (Twenty Fourteen)
    This can be customized by editing the css

    Committee Handover

    Facebook

    Update the about section.
    Add remove editors as appropriate (Note: You can only add friends)
    Send an Intro mail to new editors
    Post a status listing new officers

    Who We Are Page

    Get Portraits of new officers
    Update Roles(WP_Admin – Team Members – Role) – Change names(Team Member Details->Role) and upload/update “Featured Images” Check if person is mentioned in content and update if necessary.

    Website Admin Access

    Open WordPress Dashboard
    Users – Find New officers and change role to “Editor”
    Users – Find ex officers and change role to “Standard User” (Maybe allow a week overlap before doing this)
    Check all new officers can see committee content.

    Email ReDirects

    Open Blacknight Dashboard
    E-Mail Addresses
    For-Each Email
    Open Forwarding & Add new Office Holder
    Remove previous incumbent (Maybe allow a week overlap before doing this)
    For ordinary committee members just add their personal email to the committee redirect list.
    If user want to use an @imc mailbox then reset the password of the mailbox and advise them (also send link to how-to page on committee section of website. Turn off redirection to personal mail when they are sorted)

    Groupspaces

    You need to add/remove both manager priviledge and committee DL membership…

    Managers – Add new incumbent as a manager, remove the predecessor. (Members – Edit Managers)
    (Members – Manage Members – Find the person – More-actions dropdown – Group Management-Make Manager)

    MemberList – Committee – Add new incumbent, remove the predecessor. (Members – Your member Lists – Committee)
    (Members – Manage Members – Find the person – More-actions dropdown – Add To List-Committee)

    Pharma Hack

    fyi The site was hacked as follows in 2016…
    A backdoor was uploaded /wp-admin/network/classmedialanguage.php. This was used to upload/edit content. A single file was uploaded /wp-includes/wp-cloud-ocean.php and a one line change made to the system file class-wp-error.php to execute wp-cloud-ocean.php.
    The “cloud-ocean” code sniffed the user-agent string and had no effect unless it detected the googlebot to which it served a load of viagra-for-sale link spam. It was purely designed to steal our page-rank. It never changed the modified dates on file it edited.
    To see the effects you needed to change your browser setting to user the googlebot useragent string. Our search results on google were badly mangled and we were marked as “probably hacked site” and had to request a reset after it was cleaned up.
    It appeared to originate from this canadian IP 184.107.30.153

    Future Enhancements

    User Management

    There is no joined up thinking here. Groupspaces is a standalone process. We have no accurate records of user details or history. User management should be integrated in the site. Joining process should be automated. Contact lists should be automated. Statistics and status queries should be automated.

    Usability

    In general this is poor as cosmetic appearance is deemed more important.

    Mobile Support

    Apart from some responsive widgets built in to WordPress no consideration is given to mobile access. Intermittent issues have been reported and there is no optimization for mobile support.

Postal Address

Irish Mountaineering Club
Glendasan
Glendalough
Co. Wicklow
A98 EY91
Ireland

Follow us on Social Media

  • Facebook
  • Instagram

IMC Website

  • Contact Us
  • Introduction
  • Hut