#1   Report Post  
Old 05-02-2009, 08:00 PM
hasan_889's Avatar
hasan_889 hasan_889 is offline
Newbie
 
Join Date: Nov 2007
Location: London
Posts: 46
hasan_889 is on a distinguished road
iTrader: (0)
Default How to protect your WordPress blog?

Wordpress is the most popular blogging platform all over the world. As you become popular in search engine and getting traffic, you may be inviting hackers to test your protection system against them. Hacking can be happened any moment, so you should not wait it to happen and then take action.

When I was checking my Wassup traffic details this morning, I found that 3 suspicious records trying to get access using SQL Injection. Thankfully nothing happened and they got tired trying. However, I searched online for Wordpress protection and got some tips for it. I compiled all the tips and came with the following:


Always Update
Updating Wordpress became very easy now. From Wordpress 2.7+, you can now update your blog with just a click. So don't feel lazy upgrading your blog – as soon as they release any updated version, try to upgrade your blog. If you are using older version, you can use Wordpress Automatic Upgrade plugins and update to the latest version.


Update Your Plugins Too
As plugins are developed by third-party programmers, they may be more vulnerable than Wordpress itself. I would suggest you to check plugins profile to read the comments and stats before using any. Update your plugins regularly as well.


Protecting Your Admin Profile
Create a new user and give it full administrative privileges. Once you have done that delete your old "admin" user's profile. As a result hacker has to crack both your user name and password.


Stop Creating Guest Account
If your blog is not Multi User blog, there is no need to allow visitors to create Guest account. Uncheck Settings > General > Membership > Anyone can register option.


Use Strong Password
Don't use any obvious words sequence, numbers sequence, your name, town, date of birth etc as password. Try to use a combination of small letter, capital letter and numbers in your password. You can use Strong Password Generator for create your password. This website also give you easy way to remember your password.


Protect Your wp-admin Folder
You can add a .htaccess file in your wp-admin folder and block all IP addresses except the IP address you use, may be your home IP, office IP etc.


Backup Regularly
Even though most of the Hosting providers offer regular backup, still you should not rely on them. Couple of months ago, I found my website was unavailable and I contacted GoDaddy support. They informed they are resolving the problem and they took 5 days to fix. Horribly on 3rd day they informed me that all my records has be wiped out, so I may not get my database and files back. Fortunately, I had my website backup in my pc, and they fix my problem, I already transferred my website to Hostgator and kept my website running.


Use Login Lockdown Plugins
Login Lockdown Plugins records each failed login attempts and lock a particular IP for a while for a number of failed login attempts.


Delete Wordpress Version
Hackers may find out your Wordpress version and exploit its vulnerabilities. You may want to delete the Wordpress version from your website source. Go to Appearance > Editor and choose the Header.php file and delete <meta name="generator" content="WordPress <?php bloginfo('version'); ?>" /> from the source code to hide your Wordpress version.


Move the wp-config.php file
Also since version 2.6, WordPress allows you to move the wp-config.php file to a higher level. Because this system file contains by far more sensitive information than any other, and because it is difficult to access the parent file server level, it certainly makes sense to store it outside of the actual installation. WordPress automatically looks at the highest underlying index for the configuration settings file. Any attempt by users to adjust the path is thus useless.


Use Security Plugins
If you found that you are being targeted frequently, you can use security plugins to ensure more security for your blog. You can find some useful security plugins for wordpress here

Source: How to protect WordPress blog?
Reply With Quote
Sponsored Links
  #2   Report Post  
Old 05-13-2009, 09:14 AM
tanya1177 tanya1177 is offline
Master
 
Join Date: May 2008
Location: London
Posts: 301
tanya1177 is on a distinguished road
iTrader: (0)
Default

Great article; thanks for sharing.
But can you please help me: "How can I delete in wordpress theme "Meta" "Categories" and "Login" button?"
Reply With Quote
  #3   Report Post  
Old 05-13-2009, 10:00 AM
Himanshu's Avatar
Himanshu Himanshu is offline
Newbie
 
Join Date: Feb 2009
Location: Miami
Posts: 11
Himanshu is on a distinguished road
iTrader: (0)
Default

CHMOD - The chmod command is a shell command which when executed, the command can change file system modes of files and directories and can allow and forbid access to your files and folders. In this case, your files and folders of your blog.

Thanks for sharing your knowledge.

Himanshu
Reply With Quote
  #4   Report Post  
Old 05-14-2009, 11:18 AM
Londoner's Avatar
Londoner Londoner is offline
Newbie
 
Join Date: Apr 2008
Location: London, United Kingdom
Posts: 44
Londoner is on a distinguished road
iTrader: (0)
Default

The only thing I really do to secure my blogs is updating the version of the WP - it is easier as the WP develops...
__________________
Ever tried call girls services? Available anywhere Asta La Vista outcall escorts girls & amateur escorts of London
Reply With Quote
  #5   Report Post  
Old 05-14-2009, 05:27 PM
deluxdon's Avatar
deluxdon deluxdon is offline
Catch Me If you Can....
 
Join Date: Oct 2007
Location: www.travelwitheaseblog.com
Posts: 1,634
deluxdon will become famous soon enough
iTrader: (4)
Default

Quote:
Originally Posted by Londoner View Post
The only thing I really do to secure my blogs is updating the version of the WP - it is easier as the WP develops...
Yeap thats true.

DON.
Reply With Quote
Sponsored Links
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 04:08 AM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

Ad Management by RedTyger