Membership is FREE, giving all registered users unlimited access to every Acorn Domains feature, resource, and tool! Optional membership upgrades unlock exclusive benefits like profile signatures with links, banner placements, appearances in the weekly newsletter, and much more - customized to your membership level!

Best Wordpress Security

Status
Not open for further replies.
Joined
Oct 17, 2007
Posts
487
Reaction score
6
Hi Everyone

I am hoping this thread will not only help me but others.

Yet again a number of my blogs have been hacked and some idiot and pointless hacker has messed up some great sites.

I had an attack on my Job Quick site on Saturday and I managed to fix all the hackers rubbish, but tonight another Hacker defaced 8 more sites, including the one I had just managed to fix.

Has anyone got some good tips on the best ways to secure your wordpress site, I use pluggins like login lockout etc. but I am sure you guys have some best practise ways to do this and stop hackers

Thanks everyone.
 
The majority of hacks recently have come via an exploit timthumb, so first port of call would be to install the Timthumb Vulnerability Scanner (plugin) and run it.
 
The majority of hacks recently have come via an exploit timthumb, so first port of call would be to install the Timthumb Vulnerability Scanner (plugin) and run it.

Thanks Peter

Will do that one, great tip rep-plus given, I have been busy tracking the hacker down, just found them... not sure how responsive Saudi ISP's are though
 
Some thoughts:

* change all your passwords
* hackers often upload a few backdoors when they hack a website - check for this (review all recently modified files). Also check the first line of the wp-config.php file - many hacks inject some obfuscated php code there
* Change your wp-content -folder name
* Install 404 logger plugin to see if bots are testing your website for security vulnerabilities
* Follow these steps:
http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/
 
When you fixed the site after the hacking, what steps did you take?
 
Thanks everyone, I have had full scans run and one of the biggest sites is going to take ages to repair, so far I have found a few things that suprise me, like premium pluggins like WP robot has vulnerable elements.

I know the defaults are a problem and you can change them, it would be good to be able to change these as part of the install. I am seriously invested in premium tools for my WP installs but it just shows you can do more.

If anyone runs WP I would say a maldet scan is good if you have new pluggins, even found all-in-one-seo-pack is vulnerable and I have used this for ages.

I have a busy week ahead, lol
 
Just thinks before I moan about pluggins, do you think that the hacker installed some backdoors in all-in-one-seo-pack and WP robot pluggins, would be interesting if anyone also found gzbase64.inject.unclassed results in thier installs after running a malware detect scan on thier server.

Oh and thanks for all the tips everyone, I am certain these will help me and others
 
Reinstall all in one SEO and rerun the scan. That should tell you. As far as I'm aware out all in one SEO doesn't have any vulnerabilities or been exploited.
 
Just been running the Timthumb Vulnerability Scanner looks and a few sites have been compromised ba**ard hackers.

Strange thing is though files seem to have been changed on themes that were installed but not actually in use so hadn't been updated.

A few question for any security experts now they have there code in can they have compromised any file in any of the sub accounts of my hosting I run a fair few domains from the same account.

If so is there a tool I can use to scan everything on the server
 
You need to harden the site with the htaccess file as well, there's a whole host of stuff you can do like stopping sql injection, etc.
 
Nice tips everyone.

You need to harden the site with the htaccess file as well, there's a whole host of stuff you can do like stopping sql injection, etc.

Dashu - Do fancy sharing that .htaccess trick?
Thanks
 
Very useful thread this. Thanks to everyone who have highlighted certain plugins to look at. It's made me think more about security in regards to my wp sites.
 
Seriously had enough of these pointless hackers now, and I did find they used Tim Thumb on the latest attack, I have all of them on 5 minute monitors now with a restore ready for them, so when they brag about it online its back to normal....

I hope that the WP theme developers find some kind of fix soon.
 
Have you got the tim thumb vulnerability checker installed?

Also, do you really need to be using tim thumb anyway? Pretty sure that its only functionality is to resize images.

If you've upgraded all your tim thumb files to the latest release, it sounds like you might not have cleared the original hacking attempt(s) up successfully...
 
Status
Not open for further replies.

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Members online

Premium Members

Latest Comments

New Threads

Domain Forum Friends

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators
General chit-chat
Help Users
  • No one is chatting at the moment.
      There are no messages in the current room.
      Top Bottom