Buy Sell Discuss UK Domain Names at AcornDomains.co.uk

Today's Drop Dates are: 19-02-2012 or 26-02-2012   All times are GMT. The time now is 03:19:25 PM.
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Registration NameDrive Domain Parking Subscribe to our Domains For Sale newsletter
Go Back   Domain Forum Acorn Domains Buy Sell Auction UK Domains > Website Design and Promotion > Content Management Systems > Wordpress
Connect with Facebook

Wordpress Wordpress Blogs

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 28-11-2011, 11:13:45 PM     #1 (permalink)

 
FutureDomain's Avatar
 
Join Date: Oct 2007
Location: Solihull
Posts: 482
FutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond repute

Best Wordpress Security

Hi Everyone

I am hoping this thread will not only help me but others.

Yet again a number of my blogs have been hacked and some idiot and pointless hacker has messed up some great sites.

I had an attack on my Job Quick site on Saturday and I managed to fix all the hackers rubbish, but tonight another Hacker defaced 8 more sites, including the one I had just managed to fix.

Has anyone got some good tips on the best ways to secure your wordpress site, I use pluggins like login lockout etc. but I am sure you guys have some best practise ways to do this and stop hackers

Thanks everyone.
FutureDomain is offline  
Old 28-11-2011, 11:20:24 PM     #2 (permalink)

 
peter_w's Avatar
 
Join Date: Nov 2008
Location: Leeds, UK
Posts: 470
peter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond reputepeter_w has a reputation beyond repute

The majority of hacks recently have come via an exploit timthumb, so first port of call would be to install the Timthumb Vulnerability Scanner (plugin) and run it.
__________________
You'll find me on LinkedIn, Twitter and Google+.
peter_w is offline  
Old 29-11-2011, 01:01:05 AM     #3 (permalink)

 
FutureDomain's Avatar
 
Join Date: Oct 2007
Location: Solihull
Posts: 482
FutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond repute

Quote:
Originally Posted by peter_w View Post
The majority of hacks recently have come via an exploit timthumb, so first port of call would be to install the Timthumb Vulnerability Scanner (plugin) and run it.
Thanks Peter

Will do that one, great tip rep-plus given, I have been busy tracking the hacker down, just found them... not sure how responsive Saudi ISP's are though
FutureDomain is offline  
Old 29-11-2011, 03:01:56 AM     #4 (permalink)

 
Join Date: Oct 2007
Posts: 591
atlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond reputeatlas has a reputation beyond repute

Some thoughts:

* change all your passwords
* hackers often upload a few backdoors when they hack a website - check for this (review all recently modified files). Also check the first line of the wp-config.php file - many hacks inject some obfuscated php code there
* Change your wp-content -folder name
* Install 404 logger plugin to see if bots are testing your website for security vulnerabilities
* Follow these steps:
http://www.mattcutts.com/blog/three-...-installation/
__________________
..........
atlas is offline  
Old 29-11-2011, 05:23:43 AM     #5 (permalink)

 
aZooZa's Avatar
 
Join Date: Nov 2005
Posts: 3,980
aZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond reputeaZooZa has a reputation beyond repute

I'm surprised that the WP developers haven't implemented much of this security stuff. As a start, they should stop using defaults and ask the user for more custom install parameters, like DB prefixes and directory structure. Okay, so they provide defaults and many of them may be changed, but they could at least warn people of the ramifications of using defaults.

https://www.google.com/search?client...oe=utf-8&gl=uk
aZooZa is offline  
Old 29-11-2011, 09:05:59 AM     #6 (permalink)

 
Blossom's Avatar
 
Join Date: Oct 2010
Location: UK
Posts: 903
Blossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond reputeBlossom has a reputation beyond repute

When you fixed the site after the hacking, what steps did you take?
__________________
Jenni | Blossom | Video Tutorials
Blossom is offline  
Old 29-11-2011, 11:19:33 AM     #7 (permalink)

 
golddiggerguy's Avatar
 
Join Date: Apr 2007
Location: Hullywood
Posts: 3,407
golddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond reputegolddiggerguy has a reputation beyond repute

Not security as such but "Limit login attempts" is a nice one to just have in place.

Can customise to suit your level of lock outs if passwords are entered wrongly.
golddiggerguy is offline  
Old 29-11-2011, 11:37:36 AM     #8 (permalink)
Administrator
 
admin's Avatar
 
Join Date: Jun 2004
Posts: 8,601
admin has disabled reputation

try "Better WP Security" plug-in, has loads of features.

and if you want to track (in real time) what users are doing on your site try "WassUp" plug-in

Admin

Last edited by admin; 29-11-2011 at 11:41:36 AM.
admin is offline  
Old 29-11-2011, 09:25:21 PM     #9 (permalink)

 
FutureDomain's Avatar
 
Join Date: Oct 2007
Location: Solihull
Posts: 482
FutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond repute

Thanks everyone, I have had full scans run and one of the biggest sites is going to take ages to repair, so far I have found a few things that suprise me, like premium pluggins like WP robot has vulnerable elements.

I know the defaults are a problem and you can change them, it would be good to be able to change these as part of the install. I am seriously invested in premium tools for my WP installs but it just shows you can do more.

If anyone runs WP I would say a maldet scan is good if you have new pluggins, even found all-in-one-seo-pack is vulnerable and I have used this for ages.

I have a busy week ahead, lol
FutureDomain is offline  
Old 29-11-2011, 09:38:13 PM     #10 (permalink)

 
FutureDomain's Avatar
 
Join Date: Oct 2007
Location: Solihull
Posts: 482
FutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond reputeFutureDomain has a reputation beyond repute

Just thinks before I moan about pluggins, do you think that the hacker installed some backdoors in all-in-one-seo-pack and WP robot pluggins, would be interesting if anyone also found gzbase64.inject.unclassed results in thier installs after running a malware detect scan on thier server.

Oh and thanks for all the tips everyone, I am certain these will help me and others
FutureDomain is offline  
Closed Thread



Bookmarks

Tags
protect wordpress, stop hackers, wordpress security

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
How Wordpress Themes Work admin Wordpress 0 16-11-2011 01:11:45 PM
High quality free Wordpress themes springer Wordpress 0 05-01-2010 02:48:31 PM
(Dot) Org Domain Names to Get Security Boost - Security Management RSS Domain Name News 0 03-06-2009 06:59:03 PM
Free Wordpress Theme Gallery - Submit YOUR theme! bizcorp Domain Appraisals 2 20-02-2009 03:42:46 AM

75% off Domains at Network Solutions®.


All times are GMT. The time now is 03:19:25 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0 RC 2
All content on Acorn Domains is member generated and is not moderated before posting. All content is viewed and used by you at your own risk and AD does not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributors and not necessarily those of AD. Please contact us to report any issues or send a PM to "Admin".