New Posts
Live Radio
Welcome guest, is this your first visit?
  • Login:
Kingdom Of Poker
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Wannabe Balla
    My Status
     

    Add as a friend
    Join Date
    Mar 2009
    Location
    Ireland
    Posts
    2,203
    Blog Entries
    1
    Feedback Score
    26 (96%)

    Default Improving Security on a Wordpress Site

    Sorry if this is in the wrong area, but it's obviously a big issue for affiliates. One of my sites was also hacked some time in the past few days.

    Is there any kind of noobs guide to increasing security on a Wordpress site? I'm pretty new to WP as a CMS and have a load of sites on that platform, so it's probably best to get them all sorted asap!

    Thanks.
    PM me for:

    English/Chinese translation.
    PSD to WP/Custom WP Plugin Creation
    Swap MB for Paypal

  2. #2
    Bingolady
    My Status
     

    Add as a friend
    Join Date
    Jan 2009
    Location
    In a galaxy far, far away
    Posts
    87
    Feedback Score
    0

    Default

    • Always have the latest wordpress install, update it at once when updates are available
    • Download only trusted plugins
    • Update your plugins frequently when update is available
    • Put a htaccess file in your wp-admin directory and make your wp-admin available only from fixed IPs
    • Make sure your server displays "Access Denied" when browsing directories in browser (e.g. if you type in mysite.com/wp-content/plugins for example then you cannot see a directory list but an Access Denied. If you see the directories, then put an empty index.php into that directory or put a htaccess file
    • Always use trusted themes. Before you activate a theme look through the php files it uses in the theme, so there is no malicious code in the files
    • Change the admin login name. Go to phpmyadmin and browse your database, and manually change the admin's username to something else
    • Install WP Login Lockdown plugin, it will prohibit excessive login attempts
    • Change the table names in the WP database. You can do this with one click with the help of WP Security Scan plugin. It will also show you what other weakness you have
    • Hide your WP version. WP by default will display in the code what WP version you use with wp_header(), there are some plugins that can remove this making the attacker's work a bit harder by not giving them what each WP version's have in vulnerability
    • Also remove the readme.html and license.txt from your root install directory, so they cannot be visible from a browser, or make a htaccess file where you deny to serve these files in a browser
    • Make sure you have the proper file and directory permissions in place, do not use the built-in plugin updater as it requires ftp access and unnecessary file permissions. Update your plugins and WP by hand through an SFTP connection
    • Move your config.php to a non-web directory, there is another file that calls for the config, I don't remember which one, you need to modify that too, on the wordpress forum you will find answers
    • If you know that you won't use your wordpress site though XML RPC then rename the xmlrpc.php file in the root install directory to something like xmlrpc.php.disabled. The latest wordpress attacks happened through this file.

    And maybe the most important: backup your content often, through the WP xml export and through a database sql dump too. This way you can ensure that your site won't get lost.
    Hope this helps.
    USA bingo
    UK bingo sites
    "Its great to see that Hugh Heffner isn't the only one building and running his empire in his PJ's!" -SeoPants@AGD

  3. #3
    Wannabe Balla
    My Status
     

    Add as a friend
    Join Date
    Mar 2009
    Location
    Ireland
    Posts
    2,203
    Blog Entries
    1
    Feedback Score
    26 (96%)

    Default

    Man that is an awesome reply. Really appreciate it!
    PM me for:

    English/Chinese translation.
    PSD to WP/Custom WP Plugin Creation
    Swap MB for Paypal

  4. #4
    Senior Member
    My Status
     

    Add as a friend
    Join Date
    Nov 2008
    Location
    USA
    Posts
    426
    Feedback Score
    8 (100%)

    Default

    Where's that thanks button again?

    Great post sipka.


 

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. New Found AP/UB Security Risks
    By pokerprop in forum General Poker Affiliate Forum
    Replies: 34
    Last Post: 05-25-2010, 11:09 AM
  2. Wordpress Security & Backing Up A Site
    By leporello in forum Wordpress - Web Design - Coding - Technical
    Replies: 3
    Last Post: 04-19-2010, 04:26 PM
  3. Improving typing speed
    By Fastlane in forum General Poker Affiliate Forum
    Replies: 12
    Last Post: 01-13-2010, 10:15 AM
  4. Improving my grammar
    By Unknown Webmaster in forum General Poker Affiliate Forum
    Replies: 2
    Last Post: 08-03-2009, 04:25 PM
  5. Website Security Services
    By wjb316 in forum General Poker Affiliate Forum
    Replies: 0
    Last Post: 05-27-2009, 04:06 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Powered by vBulletin® Version 4.1.5
Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.
SEO by vBSEO 3.6.0
Affiliate Program Consultant