Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,148,038 members, 7,799,523 topics. Date: Tuesday, 16 April 2024 at 11:43 PM

How To Protect Your Wordpress Site From Trending Hacking Attack - Webmasters - Nairaland

Nairaland Forum / Science/Technology / Webmasters / How To Protect Your Wordpress Site From Trending Hacking Attack (706 Views)

The Easiest Way To Clean Your Wordpress Database. / Hacking: How To Back Up Your Wordpress Site To Google Drive And Restore Easily / How To Protect Your Site From Such Attacks That Likely Brought Nairaland Down (2) (3) (4)

(1) (Reply)

How To Protect Your Wordpress Site From Trending Hacking Attack by inpeace: 11:24am On Jun 27, 2013
Recently, millions of self hosted WordPress installations on virtually every major host in the world, were targeted by a huge bot network (having over 90,000 IPs) with the sole aim of brute hacking the installations to gain admin access by using the common default “admin” username and multiple passwords

Last year and a half taught us that WordPress security should not be taken lightly by any means. Between 15% and 20% of the world’s high traffic sites are powered by WordPress. The fact that it is an Open Source platform and everybody has access to its Source Code makes it a tempting prey for hackers.

Interestingly, at least 2 of the IP addresses used heavily in the attacks trace back to Nigeria, the more prominent one of the two being 41.203.67.53 which is the shared IP used by most of Globacom Nigeria’s internet users and also 41.206.1.5 which formerly belonged to VGC Communications which MTN Nigeria bought in 2007 and now uses to power its fixed lines and WIMAX (hynet) services. In both cases, it is likely that the attacks were carried out via remotely triggered malware on customers or the company machines.

Most attacks are coming from Bangladesh, Russia, Germany, Poland and India including, but not limited to:

SQL Injections
Clickjacking
Cloaking
Blackhole Exploit Kit attacks
Password and Login brake efforts

Truth is, if a capable master of the script targets your site, there is really no way to prevent an intrusion. What you are about to read below are some precautionary actions you can take to quickly minimize the risk to an acceptable level. If your WordPress site is well protected chances are a hacker would prefer picking another, easier victim.

Starting with the more obvious ones:

http://www.sealworld.com.ng/blog/web-design-hosting/how-protect-your-wordpress-site-trending-hacking-attack


1. Forget about using “admin” as your username.

Many of the attacks target the default WordPress username with bruteforce, password cracking robots. First step is to change your “admin” or “administrator” username from the WordPress Administration Panel.

- Go to mysql tool (phpmyadmin)
- Find your database
- Go to wp_users and browse for “admin”
- Under user_login column, change it to something else.
This naturally leads to the following…

2. Choose a strong password

Choose a password that includes multiple upper and lowercase letters, as well as symbols such as ”!@#$%^&*()” Go to Users–>Your Profile and change it through the “New password” field at the bottom. This will make it way harder to crack it down. Make sure you do the same for your ftp Cpanel hosting account password and don’t use the same one you used in WordPress.

3. Frequently backup your database

You heard this one before. Do regular backups or you will eventually regret it. You may lose all of your work if being hacked. Also, remember to backup every time you make changes. You can do that through the use of a plugin or manually.

4. Always Update your WordPress

There is absolutely no reason to stay on the older versions when there is a new one available. WordPress updates contain bug fixes, vulnerability fixes and cover security flaws discovered by the vast WordPress community. Same goes for updating themes. It is easy and efficient. Actually, it is the best and easiest way to prevent your page from malicious activities, which are most likely as result of a compromised and not fully updated application, site, exploitable php scripts, etc. All the old versions of your applications can be considered as a potential security holes. They can simply be used by the attacker, who is (most of the time) an automated spider.

5. Protect your WP-CONFIG.PHP file.

Move your wp-config.php file one directory up from the WordPress root. WordPress will look for it there if it cannot be found in the root directory. Also, nobody else will be able to read the file unless they have SSH or FTP access to your server.

There are a number of important plugins you should consider installing:

6. Login LockDown

This is very useful plugin, protecting you against brute-force password-crack attacks. It keeps track of the IP address of every failed login attempt. You can configure the plugin to disable login attempts for a range of IP addresses when a certain number of failed attempts is reached.

7. Secure WordPress

Secure WordPress is an easy to install comprehensive plugin taking care of number of things, including:
- Hides your WP version.
- Removes error information on login page.
- Removes core update, plugin update and theme update information for non-admins.
- Blocks queries potentially harmful to your WordPress website
- Adds a virtual index.php plugin directory.
- Many others…

8. Bullet Proof WordPress Security

Crash resistant, comprehensive plugin, covering many aspects of an attack – XSS, RFI, CRLF, CSRF, Base64, Code Injection and SQL Injection hacking attempts. According to the official description – “The BulletProof Security WordPress Security plugin is designed to be a fast, simple and one click security plugin to add .htaccess website security protection for your WordPress website.” This pretty much sums it. A must have!

9. Exploit Scanner

Exploit Scanner goes through the files on your website database, comment and post tables in search of anything suspicious. It also notifies you for unusual plugin names. It does not remove anything, it simply warns you for potential threats.

10. WordPress Firewall

This is another must-have security plugin.
- Investigates WordPress web requests in attempt to block obvious attacks.
- Black and whitelists pathological-looking phrases based on which field they appear within, in a page request. (unknown/numeric parameters vs. known post bodies, comment bodies, etc.).

Implementing all of the above will probably take less than an hour to complete, while making your WordPress site much more resistant to intrusions. Over 1 million WordPress sites were cracked last year, mainly due to easily preventable security gaps. Have yourself prepared and you are likely to be on the safe side.

http://www.sealworld.com.ng/blog/web-design-hosting/how-protect-your-wordpress-site-trending-hacking-attack
Re: How To Protect Your Wordpress Site From Trending Hacking Attack by inpeace: 7:45pm On Jun 27, 2013
lets discuss this

(1) (Reply)

How To Advertise On Nairaland / Which Logo Is Better? / Get Your Own Free Website Now!!!

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 19
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.