NetBuilders

Members in Chat:

You are welcome to look around. You will have to register before you can post a message, create a blog, chat live with our members, or add a site to our directory.



Reply Learn SEO from Aaron Wall
Old 5 July, 2009, 08:32 AM   #1 (permalink)
Super Moderator
 
Hellas's Avatar
 
Location: Bosnia
Thanked 234 Times in 167 Posts
Posts: 1,168
$NetBucks: 782
Join Date: Dec 2008
Last Online: 7 September, 2010 07:04 AM
Send a message via Skype™ to Hellas
Default Secure your wordpress site

Quote:
Originally Posted by Lastbutnotleast View Post
I wanted to share this article (not mine) with you.

So, here are 5 plugins to keep WordPress secure:

1. Limit Login Attempts : This plugin blocks a user for 20 minutes after he enters wrong password 4 times (default values, can be changed). It is good way to avoid Brute Force attack .

2. Sabre :If you own a WordPress powered blog where users can register freely and see a lot of fake registrations, this plugin can stop fake user registration by bots. It can add image verification or math test to registration process among other measures to make sure fake users are not created.

3. Semisecure Login : This plugin increases the security of login process by using a public key to encrypt the password on client side. The server side then decrypts the password using the private key. Requires Javascript and PHP.

4. Bad Behavior : It checks the visitor’s IP against Project Honey Pot Database to see if it’s a spammer’s. If malicious, it can block that IP from accessing your blog.

5. Secure WordPress : This plugin keeps your WordPress installation secure with the help of little functions. It hides information regarding your WordPress version from non-administrators and plugin directory from visitors by dropping a blank index.php file.

All of these are Wordpress 2.7 compatible.

Source: 5 Plugins to Keep WordPress Secure

Maybe this can be helpful to some of us
Just copy/paste from somewhere.
  Reply With Quote
Thanked by:
ankit (5 July, 2009), m42 (5 July, 2009), Oranges (5 July, 2009), sam (5 July, 2009)
Old 5 July, 2009, 09:38 AM   #2 (permalink)
Net Builder
 
Oranges's Avatar
 
Location: Netbuilders
Blog Entries: 1
Thanked 23 Times in 20 Posts
Posts: 253
$NetBucks: 65
Join Date: Jan 2009
Last Online: 1 June, 2010 12:48 PM
Default

Hmm, Nice! Here are my own steps:-

1.One of the most important security issue with wordpress is to protect wp-admin folder, So always password protect it for prevention from Hack Attack.

2. After installing wordpress always change your Mysql databse prefix from wp_ to something else, to avoid SQL injection attacks.

3. Upload blank index.php files in your wp-content/theme and wp-content/plugins to avoid getting hacked from Iframe attacks.
__________________
Custom Wordpress Themer
- Wordpress Portals & themes -
  Reply With Quote
Thanked by:
sam (5 July, 2009), sturat (5 July, 2009)
Old 5 July, 2009, 12:46 PM   #3 (permalink)
Über Moderator
 
TopDogger's Avatar
 
Thanked 339 Times in 222 Posts
Posts: 775
$NetBucks: 1,239
Join Date: Jan 2009
Last Online: Yesterday 23:24 PM
Default

Good tips

Quote:
Originally Posted by Oranges View Post
2. After installing wordpress always change your Mysql databse prefix from wp_ to something else, to avoid SQL injection attacks.
This is easier to do before you install WordPress. Just make the change in the wp-config.php file when you enter the database info. There are a few plugins that you can use to make the changes after WordPress is installed.

If you change the prefix manually after installing WordPress, then you will have to manually make changes to several table rows. Otherwise, WordPress will not work.

WordPress › Support How to change table prefix

An additional important step is to always change the admin username from 'admin' to something that is not easy for a hacker to guess. This one is easy, just open the users table using phpMyAdmin and change the user_login field in the first row.
__________________
You can have it fast, good or cheap. Pick any two.
Phoenix Managed Services :: Free Car Shipping Quotes
  Reply With Quote
Thanked by:
Oranges (6 July, 2009), Will.Spencer (6 July, 2009)
Old 6 July, 2009, 14:15 PM   #4 (permalink)
Net Builder
 
Oranges's Avatar
 
Location: Netbuilders
Blog Entries: 1
Thanked 23 Times in 20 Posts
Posts: 253
$NetBucks: 65
Join Date: Jan 2009
Last Online: 1 June, 2010 12:48 PM
Default

@ TOpdogger - Thanks for clarification, Yes it will work perfectly as well if we edit wp-config.php before installation.
__________________
Custom Wordpress Themer
- Wordpress Portals & themes -
  Reply With Quote
Reply

Bookmarks

Tags
secure, site, wordpress

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Wordpress Site Hacked - Upgrade to WordPress 2.8.4 bogart Wordpress 14 30 August, 2009 02:33 AM
Keeping Your Blog Secure Jesse Wordpress 8 10 July, 2009 21:44 PM
How do you legally secure your own software? firetown Tech-Talk 1 12 April, 2009 10:42 AM
How secure is Joomla? firetown Programming 7 12 January, 2009 22:48 PM


All times are GMT. The time now is 11:10 AM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios