Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Wordpress Security

Featured Replies

Hi Folks,

 

I have recently become a user of WordPress. I am slowly, but surely, setting up a website to contain a portfolio of my work, a blog and links to some scripts and stuff that I have.

 

So I was quite alarmed when a newsletter dropped on my virtual doormat telling me all about how prevalent and covert the hacking of WordPress blogs is.

 

I had a good read through the materials and thought I'd share.

 

For a quick and easy 3 (and a half) step guide to securing your WordPress blog read here:

http://www.mattcutts.com/blog/three-tips-t...s-installation/

 

The following are links to 3 parts of a series on WordPress hacking:

1. http://blog.cre8asite.net/bwelford/2008/02...ss-blog-hacked/

2. http://blog.cre8asite.net/bwelford/2008/02...wordpress-blog/

3. http://blog.cre8asite.net/bwelford/2008/02...ogs-are-hacked/

 

I'm intending to search for a little more detailed info, because I'd like to know exactly what methods are being used, which plugins are insecure and such like so I can take extra precautions.

 

- Eris

  • 4 weeks later...

I'm surprised no one has replied yet, as security is an overlooked feature of websites.

 

Thanks for the info Eris, I'm going to read through and see how secure my new website/blog is :)

some interesting info there.

 

great find.... I shall do some research into some of what's mentioned

Thanks for the tips, it's pne of these jobs I always mean to look into but never seem to get time - going to start tonight!

Another tip which I don't think I saw mentioned in the above links (I only scanned quickly) - is to put your database connection details into a file that you store in a non-web accessible directory of your server. Then edit wp-config.php and include your new db details file from there.

Another tip which I don't think I saw mentioned in the above links (I only scanned quickly) - is to put your database connection details into a file that you store in a non-web accessible directory of your server. Then edit wp-config.php and include your new db details file from there.

 

Seems a bit over the top, though, as you can't view a PHP file that has no output anyway. Well, not unless something fudged up on the server and PHP turns off, but then people have access to every single PHP file, so they could easily work out another way to scrape your user/pass.

  • 3 weeks later...
Seems a bit over the top, though, as you can't view a PHP file that has no output anyway. Well, not unless something fudged up on the server and PHP turns off, but then people have access to every single PHP file, so they could easily work out another way to scrape your user/pass.

If you know what you're doing you can download a PHP file from a web server as a text file. See this article on protecting wp-config.php.

Security is one of the reasons I rarely use opensource scripts. Good as WP is you only need one badly written plugin to leave your site wide open :(

  • 3 weeks later...
  • Author

Oooh I only just noticed this got some replies! It was at 0 for aaaagesss, and I couldn't understand why when so many people here use WP.

 

I think that there is a level of trust in things like WP amongst web designers, which is ill placed. You must always watch your back.

 

@Aaron Russell I don't remember if that tip is mentioned but I have always used it anyway for all database connections. It just seems wrong leaving the info out in the open!

  • 4 weeks later...

ErisDS, I've only just become aware of the kind mention of some blog posts I wrote on this. My own working approach is based on the view that some hackers are incredibly good so if they really want to attack your blog they can probably find a way. Therefore you should make sure that your blog is as strong as it can be so that hackers will go and attack other blogs that are not so well protected. There are hordes of insecure blogs out there, some with significant traffic, so any smart hacker can find what he or she wants.

 

Having said that, I think it's important to:

a ) Make database and blog backups on a regular basis

b ) Always upgrade to the latest version of WordPress so that you're protected for any vulnerabilities that may have been found.

c ) Be extremely vigilant particularly during weekends and statutory holidays, when some of these attacks seem to take place. That means checking the source code to make sure no malware code has somehow been added.

 

There are more specific hardening tips that are given in what Matt Cutts and I wrote and those are useful too.

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.