Wordpress Hacking Prevention Guide

Page 1

The Blogging Institute

Download Your $97 Gift >>>> Here


The Blogging Institute This eBook Is Brought To You By Alexis Kenne Dot Com This eBook Comes With Free Giveaways or Resale Rights, However You May Not Change The Contents In Any Way

“Wordpress Hacking Prevention Guide�

LEGAL NOTICE The Publisher has strived to be as accurate and complete as possible in the creation of this report, notwithstanding the fact that he does not warrant or represent at any time that the contents within are accurate due to the rapidly changing nature of the Internet. While all attempts have been made to verify information provided in this publication, the Publisher assumes no responsibility for errors, omissions, or contrary interpretation of the subject matter herein. Any perceived slights of specific persons, peoples, or organizations are unintentional. In practical advice books, like anything else in life, there are no guarantees of income made. Readers are cautioned to reply on their own judgment about their individual circumstances to act accordingly. This book is not intended for use as a source of legal, business, accounting or financial advice. All readers are advised to seek services of competent professionals in legal, business, accounting, and finance field. You are encouraged to print this book for easy reading.

Download Your $97 Gift >>>> Here


The Blogging Institute My name is Alexis Kenne and I’m the owner of TheBloggingInstitute.com . Over the last few months I’ve gone from being a LOSER affiliate to finally starting on the path of becoming a SUPER AFFILIATE and Expert Blogger! I shared some of my experiences on my blog I quickly realized how important was a mailing list in an online business. I then did everything to learn in the shortest time possible to send a ton of free targeted traffic to my main site at HomeBusinessFirePower.com and to my blog plus by making some small split tweaks to my conversions (opt-in rates) I’ve also managed to capitalize on the amount of traffic I do get. More Traffic = More Opt-ins = More Sales If you are struggling to get traffic to your site and /or struggling to make money online then I can help. Check out my site for access to my free affiliate marketing success kit, or visit my blog for some of the hottest affiliate marketing and traffic driving tips.

Download Your $97 Gift >>>> Here


The Blogging Institute

One last thing before you begin reading the rest of the guide, I actually offer a FREE 7 day ecourse on how to make money blogging. You can get access to it at theblogginginstitute.com

Additional Useful Links

My Facebook Fan Page My Twitter Page My Youtube Channel My Articles at ezinearticles My LinkedIn Account My Google+ Account

Download Your $97 Gift >>>> Here


The Blogging Institute

Introduction Unfortunate as it may be, just doing a search on the Warrior Forums for the terms “wordpress hack” will bring up a LOT of results. This is a real problem that people need to be aware of. And more importantly, they should be aware of the steps that they can take to prevent it from occurring in the first place. Securing your WordPress site is not a complicated process at all, and given the trouble that a hacked WordPress site will cause you, it’s absolutely worth taking the precautions that I’ll be describing to you. There’s a lot of information out there regarding the best ways to protect your WordPress-based site. With this short guide, I’ve attempted to condense the best of this information, and share with you the most efficient methods that you can use to secure your site.

Download Your $97 Gift >>>> Here


The Blogging Institute

Use a Strong Password This is a pretty obvious step. However, it’s something that’s very easy to neglect as well. Your password should be at least eight characters long (preferably more), and should be a combination of upper-case letters, lower-case letters, numbers, and symbols in order to have the maximum effectiveness. A lot of people assume that this old piece of advice is simply to keep people from “guessing” your password. Not true at all. Hackers will have a more difficult time cracking some of the more complicated passwords. Additionally, as an extra security measure, you’ll want to change your password on a regular basis.

Change Your User Identity It seems like everyone and their mother uses the name ‘admin’ to log into their site. Don’t be everyone and their mother. Change ‘admin’ to something a little less obvious. To do this, go to the Users tab, and create a new user. You can set it up the same way you did your previous user. Make this new user an administrator. Then, log out of your WordPress account, and log in as the new user. Finally, delete the user known as ‘admin’. When you’re prompted whether to delete the posts made by admin or transfer them to the new user, make sure to transfer!

Download Your $97 Gift >>>> Here


The Blogging Institute

Keep your WordPress Up to Date If you’ve been using WordPress for awhile, then you’ve probably seen occasional notifications at the top of the page prompting you to update the version of WordPress that your site is running on. It’s always worth it to make this update—not just for the extra features and interface improvements, but because newer versions of the software may fix security holes. Though it might seem like an enormous pain if you’ve got a number of sites running on WordPress, updating regularly is a solid way to ensure that hackers have a lower probability of being able to crack your site. In addition to keeping your WordPress software up to date, be sure to keep any plugins that you’ve installed up to date as well. Particularly the more popular plugins. And on that note…

Be Careful What Plugins You’re Using Attempt to keep the number of plugins that you’re using on your site to a minimum. The more plugins you’ve got installed, the greater the chance someone could take advantage of a security hole in one of these plugins. Perhaps even more important: Be cautious of the plugins that you choose to install. Try to install only plugins that have a user rating of at least 4 stars, and a large number of reviews. Unfortunately, there are some shady people out there who will release plugins for the primary purpose of gaining access to parts of your site that you didn’t intend for them to access. You’re better off not taking chances on unproven plugins. Also, Download Your $97 Gift >>>> Here


The Blogging Institute be wary of older plugins that haven’t been updated in a long time. And though this should be obvious from what I’ve just stated, please be extremely cautious of plugins that you’ve downloaded off of the internet, and aren’t available directly from WordPress’s plugin database.

Install Security Plugins I’ve found some excellent plugins to help you protect your site from attacks. Any of these can be found easily by searching through WordPress’s plugins database. The first of these you’ll want to grab is BulletProof Security. The description reads: Website Security Protection: BulletProof Security protects your website from XSS, CSRF, Base64_encode and SQL Injection hacking attempts. One-click .htaccess WordPress security protection. Protects wp-config.php, bb-config.php, php.ini, php5.ini, install.php and readme.html with .htaccess security protection. One-click Website Maintenance Mode (HTTP 503). Additional website security checks: DB errors off, file and folder permissions check... System Info: PHP, MySQL, OS, Memory Usage, IP, Max file sizes... Built-in .htaccess file editing, uploading and downloading. Whew! My guess is that you’ve found this to be more than a little confusing, but just know that it will do a lot to help protect you from attacks. Just make sure to read the instructions and set it up properly (don’t fret, it’s not difficult). Next, you’ll want to install ‘WordPress Firewall 2’. This one doesn’t require any setup on your part. This extra layer of security is most definitely worth having. Download Your $97 Gift >>>> Here


The Blogging Institute And last but not least, you’ll want to check out a plugin called ‘Login Lockdown’. If too many login attempts from the same IP range are discovered within a short period of time, then the login function will be disabled for this range of IP addresses for a certain period of time, effectively cutting down on brute force attempts at password cracking.

Back Up Your Files It’s an extremely good idea to back up your files on a regular basis. You can accomplish this fairly easily through the Backups function on your cPanel. If something bad were to happen to your site, you could restore it to its previous state simply by re-uploading a backup from your hard disk. There are also plugins available that can automate this process even further by creating a backup of your WordPress site at certain intervals and e-mailing it directly to you. I would recommend checking out either ‘Online Back for WordPress’ or ‘BackUpWordPress’.

Keep an Eye on Recent Changes For this step, you’ll want to use a solid piece of FTP software. The completely free FileZilla comes to mind. If you’re not already using real FTP software, consider this a great opportunity to start! It’s much more intuitive than the interface offered by cPanel. Check for any recent changes that have been made to your site on a regular basis. If you discover something fishy, then you’ll be able to act accordingly. And you’ll likely have a very clear idea of exactly where the hack occurred. This can be a vast Download Your $97 Gift >>>> Here


The Blogging Institute help to you (or the support guy at your web hosting company) in cleaning up after an attack.

Download Your $97 Gift >>>> Here


The Blogging Institute

Conclusions Protecting your WordPress site from attacks is something that shouldn’t be taken lightly. It’s easy to say “oh, well that could never happen to me”, but the unfortunate fact is that it does happen, and it happens on a regular enough basis that taking precautions to prevent it should be a concern of yours. While doing these steps might initially seem like a minor pain, much of this will become second nature as you continue to build and maintain websites. If you have read this guide and completed the steps described, congratulations! You are now less susceptible to an attack (not to mention more prepared to deal with one) than 95% of WordPress site owners. So enjoy the feeling of security! Best of luck in your endeavors!

Download Your $97 Gift >>>> Here


The Blogging Institute

Thank You

Alexis Kenne Special Unadvertised Bonus Access Below

Download Your $97 Gift >>>> Here


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.