February 27, 200818 yr Hi Folks, I have recently become a user of WordPress. I am slowly, but surely, setting up a website to contain a portfolio of my work, a blog and links to some scripts and stuff that I have. So I was quite alarmed when a newsletter dropped on my virtual doormat telling me all about how prevalent and covert the hacking of WordPress blogs is. I had a good read through the materials and thought I'd share. For a quick and easy 3 (and a half) step guide to securing your WordPress blog read here: http://www.mattcutts.com/blog/three-tips-t...s-installation/ The following are links to 3 parts of a series on WordPress hacking: 1. http://blog.cre8asite.net/bwelford/2008/02...ss-blog-hacked/ 2. http://blog.cre8asite.net/bwelford/2008/02...wordpress-blog/ 3. http://blog.cre8asite.net/bwelford/2008/02...ogs-are-hacked/ I'm intending to search for a little more detailed info, because I'd like to know exactly what methods are being used, which plugins are insecure and such like so I can take extra precautions. - Eris
March 23, 200818 yr I'm surprised no one has replied yet, as security is an overlooked feature of websites. Thanks for the info Eris, I'm going to read through and see how secure my new website/blog is
March 23, 200818 yr some interesting info there. great find.... I shall do some research into some of what's mentioned
March 26, 200818 yr Thanks for the tips, it's pne of these jobs I always mean to look into but never seem to get time - going to start tonight!
March 26, 200818 yr Another tip which I don't think I saw mentioned in the above links (I only scanned quickly) - is to put your database connection details into a file that you store in a non-web accessible directory of your server. Then edit wp-config.php and include your new db details file from there.
March 26, 200818 yr Another tip which I don't think I saw mentioned in the above links (I only scanned quickly) - is to put your database connection details into a file that you store in a non-web accessible directory of your server. Then edit wp-config.php and include your new db details file from there. Seems a bit over the top, though, as you can't view a PHP file that has no output anyway. Well, not unless something fudged up on the server and PHP turns off, but then people have access to every single PHP file, so they could easily work out another way to scrape your user/pass.
April 11, 200818 yr Seems a bit over the top, though, as you can't view a PHP file that has no output anyway. Well, not unless something fudged up on the server and PHP turns off, but then people have access to every single PHP file, so they could easily work out another way to scrape your user/pass. If you know what you're doing you can download a PHP file from a web server as a text file. See this article on protecting wp-config.php.
April 11, 200818 yr Security is one of the reasons I rarely use opensource scripts. Good as WP is you only need one badly written plugin to leave your site wide open
May 2, 200818 yr Author Oooh I only just noticed this got some replies! It was at 0 for aaaagesss, and I couldn't understand why when so many people here use WP. I think that there is a level of trust in things like WP amongst web designers, which is ill placed. You must always watch your back. @Aaron Russell I don't remember if that tip is mentioned but I have always used it anyway for all database connections. It just seems wrong leaving the info out in the open!
May 25, 200818 yr ErisDS, I've only just become aware of the kind mention of some blog posts I wrote on this. My own working approach is based on the view that some hackers are incredibly good so if they really want to attack your blog they can probably find a way. Therefore you should make sure that your blog is as strong as it can be so that hackers will go and attack other blogs that are not so well protected. There are hordes of insecure blogs out there, some with significant traffic, so any smart hacker can find what he or she wants. Having said that, I think it's important to: a ) Make database and blog backups on a regular basis b ) Always upgrade to the latest version of WordPress so that you're protected for any vulnerabilities that may have been found. c ) Be extremely vigilant particularly during weekends and statutory holidays, when some of these attacks seem to take place. That means checking the source code to make sure no malware code has somehow been added. There are more specific hardening tips that are given in what Matt Cutts and I wrote and those are useful too.
Create an account or sign in to comment