Recently been hacked and need secure wordpress how?

12 replies
I've had the worst possible outcome, and found one of my site's hacked by a russian group, which completly wiped out my site, but lucky for me i back up my sites every week, to be on the safe side.

I need to know any plugins or ways to properly secure wordpress sites!

i don't want this happening again, luckliy the site that was hacked was not worth anything just yet.

Any help?
#hacked #recently #secure #wordpress
  • Profile picture of the author greenovni
    There is a "login plugin" that you can configure to stop someone that tried to log in with the wrong password x # of times.

    Let me see if I find it.
    {{ DiscussionBoard.errors[1436588].message }}
  • {{ DiscussionBoard.errors[1436589].message }}
    • Originally Posted by greenovni View Post


      Cheers buddy, that will come in handy! but i don't think they came in through my login, due to all my passwords for my sites are all between 10-20 number and letters, and my virus and firewalls are running fine.

      Could it be through one of the plugins that was installed?
      {{ DiscussionBoard.errors[1436599].message }}
  • Profile picture of the author shaddai
    could have been through the server's login, mysql injection, SSH scraping, you name it..

    Start here: Hardening WordPress WordPress Codex
    WordPress › Blog How to Keep WordPress Secure
    WordPress Security Whitepaper

    ..along with any wordpress security search results from google.
    {{ DiscussionBoard.errors[1436610].message }}
  • Profile picture of the author greenovni
    Blocking their ip ranges might come in handy also
    {{ DiscussionBoard.errors[1436638].message }}
  • Profile picture of the author Abledragon
    Sorry to hear that, but great that you had regular backups so you could be back in business quickly.

    This article covers some things you could focus on:

    http://www.wealthydragon.com/blog/20...-security-ftp/

    Cheers,

    Martin.
    Signature
    WealthyDragon - Earning My Living Online
    {{ DiscussionBoard.errors[1436817].message }}
  • Profile picture of the author gbd
    Willie Crawford gives a testimonial for the free 'hacker-proof' version of Wordpress at http://www.expertwordpress.com
    {{ DiscussionBoard.errors[1436906].message }}
    • Profile picture of the author warriorkevin
      Take a hard look at everything you have installed - it may be WP, it may not be. Do you ahve form processing? And plugins that have SQL.
      PHP and WP are a bit of wildwest. Just about anybody can code things and release them - it doesn't mean they are safe.

      It is very easy to think about all the places you have passwords and completely miss the insecurity. Hackers do not need your password to hack your site.

      1) where did you get your WP template. A lot of free template sites offer templates that are already compromised. Hackers release them and look for the signature in search engines.

      2) many scripts and plugins are vulnerable to special query strings that offer up access or accept commands .

      3) apache is vulnerable to attacks that essentially tell it to give up the access with queries that allow commands to get through.

      It could very easily be a PW attack or Not. Does your site have weak pws for access to ftp, ssh. If you don't have security on your server, and you arent' checking the logs, you are probably missing how many people are scanning your box. I get emails every day for each scan of my server.
      They are all blocked. But before I did that, I would see logs of people trying various login attemps 100s-1000s of times a day through FTP, mail and ssh.

      Did you check your server logs to see what you might find?

      Hope you figure it all out.
      {{ DiscussionBoard.errors[1437029].message }}
      • Originally Posted by warriorkevin View Post

        Take a hard look at everything you have installed - it may be WP, it may not be. Do you ahve form processing? And plugins that have SQL.
        PHP and WP are a bit of wildwest. Just about anybody can code things and release them - it doesn't mean they are safe.

        It is very easy to think about all the places you have passwords and completely miss the insecurity. Hackers do not need your password to hack your site.

        1) where did you get your WP template. A lot of free template sites offer templates that are already compromised. Hackers release them and look for the signature in search engines.

        2) many scripts and plugins are vulnerable to special query strings that offer up access or accept commands .

        3) apache is vulnerable to attacks that essentially tell it to give up the access with queries that allow commands to get through.

        It could very easily be a PW attack or Not. Does your site have weak pws for access to ftp, ssh. If you don't have security on your server, and you arent' checking the logs, you are probably missing how many people are scanning your box. I get emails every day for each scan of my server.
        They are all blocked. But before I did that, I would see logs of people trying various login attemps 100s-1000s of times a day through FTP, mail and ssh.

        Did you check your server logs to see what you might find?

        Hope you figure it all out.

        Nope i haven't checked that, and i sure will now. I really apreciate all the help, i never knew wordpress wasn't that secure before now.
        {{ DiscussionBoard.errors[1438135].message }}
  • Profile picture of the author Steven Fullman
    I think Craig Desorcy (above) is being unnecessarily humble!

    Check out his Blog LockDown report...it's AWESOME.

    Blog Lock Down: Secure Your Wordpress Blog Today

    Steve
    Signature

    Not promoting right now

    {{ DiscussionBoard.errors[1438216].message }}

Trending Topics