Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
February 09, 2012, 05:14:44 PM

Pages: [1]   Go Down
  Print  
Author Topic: Best WordPress Security Tips and Tweaks  (Read 1443 times)
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« on: September 03, 2009, 11:28:26 AM »

I often get PM'ed via the forums here asking my opinion on how you can "secure" WordPress, and make it less vulnerable to attack.  I did some searching around, and these are probably my three favorite resources to share on the topic.  


Have any other WordPress related security tips or situations that you have learned from?

Hope these come in handy to all that need them!
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
SilviuB
Spaceship Captain
*****
Offline Offline

Posts: 123


« Reply #1 on: September 07, 2009, 04:51:32 AM »

Thanks Mitch ... I'll start hardening my 5 wp sites.
Logged
Mitch
Berserker Poster
*****
Offline Offline

Posts: 12838


WWW
« Reply #2 on: September 07, 2009, 05:00:59 AM »

Not a problem, always happy to pass along the goodies when I find them.  Also, it is worth mentioning there is a new WordPress security threat out there for people not using the latest version 2.8.4. 

WordPress Attack Underway: WordPress Users Must Upgrade [ALERT]

Quote
There are two clues that your WordPress site has been attacked.

There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”

The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account.

I am usually pretty fast with upgrading, so think all my sites are safe - however if you haven' upgraded WordPress yet, now might be the time to do so.
Logged

New to Web Site Hosting? Check Out the Lunarpages Blog Hosting Guide!


Follow us @lunarpages on Twitter!
Important Threads: Read This Before Posting! | Lunarforums Rules! | Mitch's Link of the Day!
Also, be sure to check out and subscribe to the Lunartics Blog and the Lunarpages Newsletter !

Need Web Hosting Help? Check out the Lunarpages Web Hosting Wiki. It has tons of tips, tutorials and resources!
Pages: [1]   Go Up
  Print  
 
Jump to: