Paul's Tech Talk

Menu

  • Home
  • About me

WordPress Security Tips — For the untrained :

PaulJune 10, 2009

I was reading over at Malware Diaries, about a hacker that doesn’t secure his exploits.  What gets me is that I am so surprised that he did that, then I thought about it and I read what Trend Micro had to say about it:

Creating a website is indeed a big task but, considering the present threat landscape, monitoring it and keeping it secure from attacks is a bigger one.
Website administrators have the responsibility to keep their systems malware free, secure web server files from unauthorized access, and keep their website clean of malicious codes, for their own sake and most especially, their visitors’.

[via Trend Micro blog]

[ad]Now admittedly Trend talks about the [intlink id=”3578″ type=”post”]Gumblar[/intlink] and how they compromise websites with either a FTP password stealer or and SQL Injection.  These are a common practice with hackers and thief to get the credentials to use your server for their means.   So I wanted to talk about some things you can do to better protect your WordPress blog.   Since I have a WordPress Blog this was something I know about.

  • WordPress Security Scan —  This is a great plugin to help you identify and also suggests how you can fix them to prevent a hacker from getting in the first place.
  • Block Wp-Folders from being Indexed —  This can be done by going to your robots.txt file and making sure it says:
  • Disallow: /wp-*

  • Protect your Wp-admins folder — Attackers can use brute force attacks to without much waiting to get access to your Wp-admin page so you should:

  1. Login Logger Plugin — This is good to see if anyone is trying to login and keeps a log for those instances where you might need to block a certain IP in the .httpaccess file section.
  2. Limit Login Attempts plugin — This has a set amount of login before that IP is locked out for a certain amount of time.  You can have it set to what you want an hour or more, it just depends on your preference.
  3. Bad Behavior — This is a good little plugin to help with spam such as referral spam and comment spam. I’ve been using it for the past few months and my referral spam has dropped drastically to almost Zero.

These are just a few things I’ve done to help protect my blog and protect my community and users.   I will not disclose everything because I have to keep those bad guys from getting in but I have I hope started you in the right direction.   I would also suggest using something like [intlink id=”2646″ type=”post”]Roboform[/intlink] that comes with a password generator to use that with your wordpress login password.  This will also help prevent from gaining access easily.

Share this:

  • Share on Reddit (Opens in new window) Reddit
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Email a link to a friend (Opens in new window) Email
  • Share on Telegram (Opens in new window) Telegram
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Nextdoor (Opens in new window) Nextdoor
  • More
  • Print (Opens in new window) Print

Like this:

Like Loading...
Help Support my Blog!

Follow my Blog on:
Twitter
Facebook
Posted In Hackers, Plugins, Practices, Security, SQL Injection, trend micro, Vulnebilities, Website, WordpressTagged Account

Post navigation

← Previous post: Microsoft Drops a 9 Security updates on Patch Tuesday
Next post: The Frustrations of Wordrpess 2.8 →
106 readers
Feed Statistics

RSS Feed

RSS feed

Recent Posts

  • Windows 10 was End of Life – So I decided to go to Linux Mint using ChatGPT!
  • She Said I Was the Problem… Until Everyone Saw the Truth
  • Diary of a Narcissist’s Supply: The Ugly Truth Behind the Fake Love
  • Microsoft Flight Simulator 2024 – Not recommended (Day 5)
  • The Dark Side of Job Hunting: Are You Being Tricked by Fake Interviews?

Recent Comments

  • She Said I Was the Problem… Until Everyone Saw the Truth – Paul's Tech Talk on Diary of a Narcissist’s Supply: The Ugly Truth Behind the Fake Love
  • The Shocking Link Between Rising Unemployment and Fake Job Listings! – Paul's Tech Talk on Prevailing winds of Job Scams being on the Rise in 2024
  • Is Pathrise the Best Career Accelerator? A Comprehensive Review on Navigating the Job Market Maze: How Pathrise Can Guide you to your next Career!
  • Navigating the Job Market Maze: How Pathrise Can Guide you to your next Career! – Paul's Tech Talk on Job Hunting 101: Mastering the Art of Applying for Positions
  • More signs of Economic Trouble for the US! – Paul's Tech Talk on In Depth Investigation of the Job Market and How it looks

Archives

Categories

The form you have selected does not exist.

© 2026 Paul's Tech Talk. BlueBird Theme by JGT.
Back To Top
%d
    Verified by ExactMetrics
    Mastodon Mastodon