![]() |
| Domain Name Sales | Domain Software | Calculate UK Domain Drop Dates | Domain Registration | NameDrive | Domain Parking | Subscribe to our Domains For Sale newsletter |
| | ||||||
| Home | Register | Rules | Membership Upgrade | Domains For Sale | Domain Name Escrow | Mark Forums Read | Domain Classified | Chat Room |
| Wordpress Wordpress Blogs |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 (permalink) |
![]() | Best Wordpress Security
Hi Everyone I am hoping this thread will not only help me but others. Yet again a number of my blogs have been hacked and some idiot and pointless hacker has messed up some great sites. I had an attack on my Job Quick site on Saturday and I managed to fix all the hackers rubbish, but tonight another Hacker defaced 8 more sites, including the one I had just managed to fix. Has anyone got some good tips on the best ways to secure your wordpress site, I use pluggins like login lockout etc. but I am sure you guys have some best practise ways to do this and stop hackers Thanks everyone. |
| |
| | #2 (permalink) |
![]() |
The majority of hacks recently have come via an exploit timthumb, so first port of call would be to install the Timthumb Vulnerability Scanner (plugin) and run it.
|
| |
| | #3 (permalink) | |
![]() | Quote:
Will do that one, great tip rep-plus given, I have been busy tracking the hacker down, just found them... not sure how responsive Saudi ISP's are though | |
| |
| | #4 (permalink) |
![]() |
Some thoughts: * change all your passwords * hackers often upload a few backdoors when they hack a website - check for this (review all recently modified files). Also check the first line of the wp-config.php file - many hacks inject some obfuscated php code there * Change your wp-content -folder name * Install 404 logger plugin to see if bots are testing your website for security vulnerabilities * Follow these steps: http://www.mattcutts.com/blog/three-...-installation/
__________________ .......... |
| |
| | #5 (permalink) |
![]() |
I'm surprised that the WP developers haven't implemented much of this security stuff. As a start, they should stop using defaults and ask the user for more custom install parameters, like DB prefixes and directory structure. Okay, so they provide defaults and many of them may be changed, but they could at least warn people of the ramifications of using defaults. https://www.google.com/search?client...oe=utf-8&gl=uk |
| |
| | #7 (permalink) |
![]() |
Not security as such but "Limit login attempts" is a nice one to just have in place. Can customise to suit your level of lock outs if passwords are entered wrongly. |
| |
| | #9 (permalink) |
![]() |
Thanks everyone, I have had full scans run and one of the biggest sites is going to take ages to repair, so far I have found a few things that suprise me, like premium pluggins like WP robot has vulnerable elements. I know the defaults are a problem and you can change them, it would be good to be able to change these as part of the install. I am seriously invested in premium tools for my WP installs but it just shows you can do more. If anyone runs WP I would say a maldet scan is good if you have new pluggins, even found all-in-one-seo-pack is vulnerable and I have used this for ages. I have a busy week ahead, lol |
| |
| | #10 (permalink) |
![]() |
Just thinks before I moan about pluggins, do you think that the hacker installed some backdoors in all-in-one-seo-pack and WP robot pluggins, would be interesting if anyone also found gzbase64.inject.unclassed results in thier installs after running a malware detect scan on thier server. Oh and thanks for all the tips everyone, I am certain these will help me and others |
| |
![]() |
| Bookmarks |
| Tags |
| protect wordpress, stop hackers, wordpress security |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Domain Name Community | Replies | Last Post |
| How Wordpress Themes Work | admin | Wordpress | 0 | 16-11-2011 01:11:45 PM |
| High quality free Wordpress themes | springer | Wordpress | 0 | 05-01-2010 02:48:31 PM |
| (Dot) Org Domain Names to Get Security Boost - Security Management | RSS | Domain Name News | 0 | 03-06-2009 06:59:03 PM |
| Free Wordpress Theme Gallery - Submit YOUR theme! | bizcorp | Domain Appraisals | 2 | 20-02-2009 03:42:46 AM |