![]() | | ||||||||
| | #1 |
| Walking on the wild side War Room Member Join Date: Sep 2008
Posts: 178
Thanks: 112
Thanked 25 Times in 20 Posts
|
Warriors, I'm so much concerned. I have this great idea on mind about my new blog that I gonna launch soon. I have prepared many stuff, and have so many ideas to write about in my new blog. I know so much about many things, but as you know... Nobody knows everything! One of the things that I'm not good at is.. Security! What if I got that amazing wordpress theme, and then I started to write articles and beautiful posts on my blog day after the other, and aside working on doing lots of SEO and increasing visitors to my site... RSS Subscribers, Twitters, etc... What if after a year passes, and I have a decent traffic to my site and readers reading my articles everyday.. Then someone hacks my site! You know... The more popular your blog becomes, the more invasions will occur from spammers, hackers and others. Have any of you warriors faced this issue? How do you go around it? How do you protect your blog and make sure that NOBODY will be able to break your site and mess with it... or possibly hacking your password and destroy the whole thing for you, including your posts and domain and hosting. I know backup is always good... but what if someone simply got over your blog overall? Can this happen? and if yes... please let me know the best ways to avoid this from happening, and how should I act if that really happened someday. Thanks. |
| | |
| | #2 |
| Guest
Posts: n/a
|
It's simple secure your blog and do not rely on wordpress to do it for you ... It is an open source platform which means hackers have access to the full code, including any updates. It will never be secured unless you take that security into your own hands and modify the coding so the hackers do not know what was changed. Nothing is 100% secure but I rather depend upon my own self vs some company that will not secure their scripts.. James |
|
| | #3 |
| Active Warrior Join Date: Sep 2007 Location: Canada.
Posts: 59
Thanks: 1
Thanked 10 Times in 10 Posts
|
If your blog is that popular , I strongly suggest hiring someone to do the secruity on your hosting.
|
| | |
| | #4 |
| Wordsmith (& Skepchick) War Room Member Join Date: Sep 2008
Posts: 13,656
Thanks: 7,516
Thanked 9,554 Times in 4,952 Posts
| I don't use Wordpress. It's the same logic as not using Outlook (or Outlook Express) for email: most email viruses are designed to attack through Outlook (Express). Just not using it probably removes 90% of the potential problems. Similarly with blog hackers. I don't say that anything else is any better made or more hacking-resistant. The reality is just that most hackers hack Wordpress blogs. Just one of the little downsides that you don't often see mentioned. |
| Alexa Smith ... ... writes stuff that snaps, crackles and pops - even if it's only about cauliflowers. | |
| | |
| | #5 | |
| Welsh Warrior Join Date: Apr 2009 Location: UK
Posts: 457
Thanks: 21
Thanked 36 Times in 28 Posts
| Quote:
![]() Oh wait, I just remembered I have no coding experience, does that mean myself and others who don't know how to code, are screwed? | |
| | ||
| | |
| | #6 | |
| Walking on the wild side War Room Member Join Date: Sep 2008
Posts: 178
Thanks: 112
Thanked 25 Times in 20 Posts
|
Thanks for the tip James. Well actually the last time I created a website it was very successful and I was getting good traffic everyday. Despite that, nobody was able to break the site because I developed it myself, and took most security issues into consideration. I got some spammers and hackers attempting to mess with the site, but they failed at the end. I have some security background, but not one that's perfect. The reason of why I am asking about wordpress security, is that I don't want to waste time on developing the website. Wordpress as you know, is a perfect platform for blogs, so I hope it's secure enough to rely on it. I really don't wish to develop a website that takes me months (since I have a regular job and can't work on it all day), where I can create the same result in Wordpress within a few hours. Quote:
| |
| | |
| | #7 | |
| Walking on the wild side War Room Member Join Date: Sep 2008
Posts: 178
Thanks: 112
Thanked 25 Times in 20 Posts
|
Good point Alexa... what you said makes sense. Do you think it's better to improve the security of the wordpress blog? And how to do that? or instead... just code the website myself and make sure there are no security gaps (basically)? Quote:
| |
| | |
| | #8 |
| a.k.a. Anne Pottinger War Room Member Join Date: Jan 2009 Location: ½ Way between California and New York
Posts: 1,407
Thanks: 1,288
Thanked 616 Times in 381 Posts
|
Just an observation. I use 2 hosting companies: BlueHost and HostGator, with 3 WP blogs hosted on each, plus various regular websites. Recently 2 BlueHost blogs have been hacked, plus one regular website and they offered me no help, simply informing me that security is my problem. On the other hand, nothing I have hosted with HostGator has been hacked. Several months ago, I installed the WP-Ban plugin on all my blogs. Now, whenever Akismet flags anything as spam, I simply add the email address / domain / IP address to the plugin list and I now hardly ever see any junk commenting at all. |
| | |
| | |
| | #9 |
| JohnLagoudakis.com War Room Member Join Date: Jul 2009 Location: Brisbane, Australia
Posts: 354
Blog Entries: 8 Thanks: 33
Thanked 48 Times in 36 Posts
|
There was a recent hack on a Wordpress vulnerability that caused the index.php to have code added which redirected your blog. When someone visited your site it would just come up as a blank page. It was fixed with a new release (version 2.8.6) but if you were on a shared server, you had to make sure that you updated all blogs otherwise all your domains would get infected. I was infected and cost me a fair bit of downtime |
| *** FREE Webinar Reveals How I Make a Full-Time Income Online! *** (see how Google stabbed me in the back) John Lagoudakis Blog Top 100 Clickbank Affiliate | |
| | |
| | #10 | |
| Welsh Warrior Join Date: Apr 2009 Location: UK
Posts: 457
Thanks: 21
Thanked 36 Times in 28 Posts
| Quote:
| |
| | ||
| | |
| | #11 |
| On the Run War Room Member Join Date: Nov 2009 Location: Peru
Posts: 66
Thanks: 0
Thanked 4 Times in 3 Posts
| |
| | |
| | #12 |
| Active Warrior Join Date: Oct 2006 Location: , , .
Posts: 34
Thanks: 5
Thanked 1 Time in 1 Post
|
Just a quick tip Use the autoupdate plugin for wordpress. WordPress › Wordpress Automatic upgrade WordPress Plugins I have found this to be a god send for all the wp installs I use. ken |
| | |
| | |
| | #13 | |
| Guest
Posts: n/a
| Quote:
That is a huge secuirty risk right there... Never use any autoupdate stuff that has access to your system. Not to mention you should "NOT" update just because wordpress released an update, many times that can be more damaging than it is good. James | |
|
| | #14 | |
| Senior Warrior Member War Room Member Join Date: Jan 2009 Location: Melbourne, Australia
Posts: 1,387
Thanks: 650
Thanked 192 Times in 130 Posts
|
Wassim, Listen to James' post. I know he isn't going to tell you to click on the link in his sig because it's against the rules but you should definitely get his product. I initially decided to create plain html sites because I was scared of using Wordpress due to all the hacking stories, however, I then stumbled across James' product and I now use Wordpress for every site I create. I know absolutely nothing about programming and the like, yet I can now have a secure blog installed in 10 mins. It's one of the best products I've bought for my business. Period. Quote:
| |
| | |
| | #15 | |
| Senior Warrior Member War Room Member Join Date: Oct 2002 Location: , , .
Posts: 1,134
Thanks: 62
Thanked 113 Times in 97 Posts
|
Dont get too comfortable. Years ago we had a dedicated server with Hostgator hacked. Hostgator was supposed to be providing security. After it happened I had a server admin pro look at the server and he found a lot of insecurities. He also discovered the person who broke in was just a kid who used some basic tactics to compromise my dedicated server Before then I was comfortable to but only because I didn't know how unsecure my server really was. Be proactive about security. Don't assume you are secure because you haven't been hacked-YET. Quote:
| |
| | |
| | #16 | |
| Guest
Posts: n/a
| Quote:
It is not the server itself, especially from hostgator as they keep their servers up to date unlike many other hosting companies. James | |
|
| | #17 | |
| Senior Warrior Member War Room Member Join Date: Jan 2009
Posts: 1,469
Thanks: 94
Thanked 264 Times in 181 Posts
| Quote:
Thanks for sharing this Pat. I didn't realize James had a product to protect WP, so I will definitely check into it. I just joined one of his sites recently and have been very impressed with everything he offers. He is really awesome about sharing info and giving support. | |
| Sizzlin' Hot - Review & Bonus TOP FIVERR GIGS BONUS OFFER - BUILD MY RANK HIDE YOUR IP, Low Price, Review, EZ to USE - HIDEMYASS VPN | ||
| | |
| | #18 |
| Bruce from Scottsdale War Room Member Join Date: Jun 2007 Location: Scottsdale, Arizona
Posts: 398
Blog Entries: 13 Thanks: 18
Thanked 101 Times in 78 Posts
|
There is a WP plugin called "WP Security Scan" by Michael Torbert (Google to find that site) that is another way of further protecting your WP blog. I have installed it on all my blogs and it is great for changing database names, passwords and other key areas where hackers can get hold of your blog. Hope that helps, Bruce |
| | |
| | #19 |
| Active Warrior War Room Member Join Date: Mar 2009 Location: Pakistan
Posts: 64
Thanks: 2
Thanked 1 Time in 1 Post
|
I always keep my blogs updates with latest version and disable registrations on your blog. That's all which I am doing as security measures.
|
| | |
| | |
| | #20 |
| Senior Warrior Member War Room Member Join Date: Oct 2002 Location: , , .
Posts: 1,134
Thanks: 62
Thanked 113 Times in 97 Posts
| It can be other factors but this was the server itself and it was Hostgator. Not to disparage them only because it's common with hosting companies that they are not as proactive about keeping their sites updated with security as they should be.
|
| | |
| | #21 | |
| Walking on the wild side War Room Member Join Date: Sep 2008
Posts: 178
Thanks: 112
Thanked 25 Times in 20 Posts
|
thank you so much Jocy Quote: | |
| | |
| | #22 | |
| Active Warrior Join Date: Oct 2006 Location: , , .
Posts: 34
Thanks: 5
Thanked 1 Time in 1 Post
| Quote:
Are you saying that the plug-in itself is dangerous, or just any sort of auto updating script? Would that include something like wp-o-matic or some other rss feeder? Also, why would you recommend against updating WP as soon as a new version comes out? I was under the impression that was a good thing in order to prevent exploits. Thanks for your input. ken | |
| | ||
| | |
| | #23 |
| Battle Scarred Warrior War Room Member Join Date: Feb 2009
Posts: 2,563
Thanks: 665
Thanked 1,780 Times in 744 Posts
|
Don't use applications that are based on interpreted script?
|
| FOLLOW ME ON TWITTER!!! @MichaelHiles Circle Me on Google+... http://gplus.to/michaelhiles >>>>>>>> GET THE STRAIGHT TALK at http://www.michaelhiles.com | |
| | |
| | #24 | |
| Guest
Posts: n/a
| Quote:
I do not recommend to update to the latest version due to the fact that is what the hackers expect you to do so they can go play in your playground with new exploits. The best thing you can do is keep the version you have secure it and do not upgrade at all.. Take action into your own hands and secure your own blog by modifiying the coding. James | |
|
| | #25 | |
| Welsh Warrior Join Date: Apr 2009 Location: UK
Posts: 457
Thanks: 21
Thanked 36 Times in 28 Posts
| Quote:
Whenever I see an update available for anything I own, I just automatically go ahead with it, because surely it is being updated for good reason. If you don't update, then how do you get access to any new features included? | |
| | ||
| | |
| | #26 | |
| Guest
Posts: n/a
| Quote:
James | |
|
| | #29 | |
| Welsh Warrior Join Date: Apr 2009 Location: UK
Posts: 457
Thanks: 21
Thanked 36 Times in 28 Posts
|
Awesome information! Thanks alot JP Quote:
| |
| | ||
| | |
| | #30 |
| Active Warrior War Room Member Join Date: Jan 2009
Posts: 61
Thanks: 3
Thanked 6 Times in 6 Posts
|
One thing to keep in mind with site security is it is not a one-time process or event. What is secure today could be hacked by a new discovery tomorrow. In the last week alone, there were over 200 thousand sites hacked to spread malware, and I am sure many of those sites were "secure" at one point. If you have a casual site that you are not relying on for income, you should check your security with an updated security scan at least every month. If you are using your site as a source of income, you really need to check your site weekly or daily to make sure you know about and fix the latest vulnerabilities before the bad guys discover them on your site. In the last week alone, there were over 200 thousand sites hacked to spread malware. |
| Free online GED classes information
| |
| | |
| | #31 |
| Warrior Member War Room Member Join Date: Nov 2009
Posts: 24
Thanks: 1
Thanked 2 Times in 2 Posts
|
umm, look: if trying to protect your blog you will be have use best security level and I used to be an Auditor & Security Analysts so here is a list that I use frequently to find what I need for securing my WP Blogs hackers are too genius but they are said to idiot because they did there work for bad reply of there futre. thanks ![]() keshav ![]() i have my own idea about entertainment wann know noth up me soon |
| | |
| | #32 | |
| Fatman War Room Member Join Date: Sep 2009 Location: Kuala Lumpur, Malaysia
Posts: 11
Thanks: 14
Thanked 1 Time in 1 Post
| Quote:
When you add an IP address to your ban list, are you not afraid of alienating all the good visitors coming from that particular IP as most ISP's use DHCP (dynamic IP assigning) and that would mean everytime someone logs onto the Internet, they get assigned a different IP address. I normally ban the user's email address, so I was wondering if you knew of a way to overcome the above problem? Thanks. Regards, Kenneth, | |
| | ||
| | |
| | #33 |
| Fatman War Room Member Join Date: Sep 2009 Location: Kuala Lumpur, Malaysia
Posts: 11
Thanks: 14
Thanked 1 Time in 1 Post
|
But James, all versions have bugs in them. When we not update, dont we leave ourselves exposed to hackers who can manipulate these holes? Isnt that why Wordpress issues updates? Regards, Kenneth. |
| | |
| | |
| | #34 |
| Everyday I'm Hustlin War Room Member Join Date: Oct 2009
Posts: 85
Thanks: 6
Thanked 8 Times in 8 Posts
|
1. Don't auto update anything ever, do update and patch when obviously stable, but automating this process is setting yourself up for unstable software that is more readily hacked. 2. Don't use Wordpress if you don't have to. You'll get a bunch of script kiddies that will figure out a way in... these aren't even hackers, most hackers wouldn't really care to break into your site, these are lazy wannabe techies that borrow someone elses script and modify it to bust your site. 3. You can never fully secure your site, but do take the obvious precautions mentioned above and use a hardware firewall, take backups, and think long term when crafting your security. |
| | |
| | |
| | #35 | |
| Guest
Posts: n/a
| Quote:
If you want to stop hackers, then you must secure your blog youself and change the coding. 2 Customers of mine above has already answered this problem with a real solution. Stop trying to use those so-called security plugins and those wannabe security tips that many non-security experts post about. Would you hire an electrician to wire your house for electricity or hire a plumber ??? Many of those created blogs and security tips are from people that have never coded a site in their lives and they know nothing about security. Sorry to say it but hard core facts are hard core facts, stop trying to be cheap and find free solutions to secure your business.. Do you seriously leave your business to so-called experts based on some free information that some non-coder post on a site ?? Fact is business cost money and if you are making money then investing in your site is also a must. James | |
|
| | #36 |
| Obsessive Tester War Room Member Join Date: Oct 2009 Location: Switzerland
Posts: 723
Thanks: 411
Thanked 293 Times in 140 Posts
|
Don't know if this has been listed yet. For Wordpress, definitely watch this video guide: 10 Tips To Make WordPress Hack-Proof. The Ultimate Guide. - GUVNR |
| | |
| | |
| | #37 |
| YadaText.com War Room Member Join Date: Jun 2005
Posts: 879
Thanks: 27
Thanked 102 Times in 79 Posts
|
[QUOTE=TheRichJerksNet]That is why you secure your own blog... I'm willing to confess to the following so others will take this serious. I know most people buy stuff and really use it.............NOT! Well I'm guilty of this many times over but lately I've been hearing more and more horror stories on blogs getting hacked. I'm dedicating this week end to actually securing my blogs. I purchased your program James and never bothered to follow through and actually do it. I've been fortunate or lucky to have not gotten hit. Don't fall victim to this. If you've bought James program, use it today. I'm going to. James I bought WP secured about 6 months ago. Are there any updates? |
|
Are you frustrated trying to figure which Text Program to use? Download this FREE Report "Removing The Blinders" No Optin Required www.LegalGap.com/mobile.pdf | |
| | |
| | #38 | |
| Guest
Posts: n/a
|
[quote=proapc;1411747] Quote:
I can not give an exact date right now as I am working on several projects and updates to my sites. James | |
|
| | #39 | |
| Fatman War Room Member Join Date: Sep 2009 Location: Kuala Lumpur, Malaysia
Posts: 11
Thanks: 14
Thanked 1 Time in 1 Post
|
James, I got your point on security. How do I know the loopholes in my Wordpress blog (Think & Create) that is susceptible to be compromised Regards, Kenneth. Quote:
| |
| | ||
| | |
| | #40 | |
| Guest
Posts: n/a
| Quote:
I do not just sell this product or that product, I use everything I sell myself also... James | |
|
| | #41 |
| Senior Warrior Member War Room Member Join Date: Sep 2006 Location: Stockholm , Sweden.
Posts: 1,469
Thanks: 33
Thanked 151 Times in 92 Posts
|
I highly recommend James' Wordpress Secured, it's probably the best wp security product you can find. It does make you work a little bit, and you cannot update your secured blogs right away, but your blogs are protected! I secured my blogs on wp version 2.6.3 with Wordpress Secured, did not update them since then, and I had no hacked blog for a looong time. |
|
||Total Traffic Mastery videos || Resell Rights - Know-How ||Successful Online Business - Know-How || Make Money Online || A.C.
| |
| | |
| | #42 | |
| HyperActive Warrior Join Date: Dec 2008
Posts: 139
Thanks: 25
Thanked 7 Times in 7 Posts
| Quote:
So how does one do that , what code do you modify ? BayAreaSteve | |
| | |
![]() |
|
| Tags |
| blog, hackers, protect |
| Thread Tools | |
| |
![]() |