Wednesday, August 29, 2012

7 Easy WordPress Security Tips | Business 2 Community

WordPress is the most popular Content Management System (CMS) on the World Wide Web.?Like many popular applications, WordPress even has many thousands of plug-ins and widgets created by WordPress? vast developer community. Because WordPress is open source and licensed under GPL, each release gets better and better, and thousands of developers are making useful programs for it. Although WordPress was really designed for blogs, with the multitude of plug-ins that can be installed, and the flexibility to customize many elements, the CMS can be adapted for many other formats of websites.

WordPress is used by an astonishing 8.5% of all websites. Web delivered malware and website cracking are becoming increasingly common. With such a large percentage of web content using WordPress as a CMS, any security vulnerabilities in WordPress? coding or framework could affect millions of websites.

In this article, I?ll explain how you can best protect your WordPress developed website from malware and cracking.

Step 1: Audit Overall Work Station Security

First of all, make sure that any and all PCs and web servers you use are kept properly secure. Make sure you?re running the most recent release of your favourite web browser, and make sure that it?s set to automatically patch. Do the same with your antivirus software and operating systems. Make sure that all authentication vectors you use have secure passwords which are changed every so often. Scan your PCs and servers for malware, frequently. Make sure you use proper firewalls- at the OS level, at the router level and at the ISP level, if at all possible. Any security holes outside of WordPress, in software and hardware you use with it, can affect the CMS itself. It?d be sad to create a really secure password for your WordPress admin account, only to find out a keylogger defeated all of your effort.

Step 2: Keep WordPress Updated

Then, the next step is to make sure you always have the most recent version of WordPress installed. Updating WordPress is relatively quick and easy, and can be done through the WordPress panel in your web browser. If the most recent version of WordPress is incompatible with the versions of PHP and mySQL installed in your web server or web host, I strongly recommend you go to the effort to upgrade those to ensure your version of WordPress is up to date. Obsolete versions of WordPress will no longer get security patches, much the same way that older OSes see support expiration.

Step 3: Report Bugs and Vulnerabilities

If you ever discover security vulnerabilities on your own, do the community a favour by sending a detailed e-mail to security@wordpress.org. If the vulnerability is in a plug-in instead, e-mail plugins@wordpress.org. You would want other web developers to report loopholes that may affect your website, so treat others as you would like to be treated! Just avoid writing about those newly discovered vulnerabilities on the web or on social networking sites, so that information doesn?t fall into the wrong hands.

Step 4: Check For Exploits

Every so often, run the ?Exploit Scanner? plug-in to check for indications of malicious activity. Exploit Scanner doesn?t directly repair any issues, but it will leave you a detailed log to troubleshoot with. If you ever suspect cracking, that?s the time to run that plug-in, as well.

Step 5: Disable Custom HTML When Possible

WordPress can use custom HTML for various functions. If that isn?t absolutely necessary for the form and function of your website, you may want to disable unfiltered HTML by adding ?define( ?DISALLOW_UNFILTERED_HTML?, true ); ? to your wp-config.php file.

Step 6: Back It Up!

?WP-DB Manager? is excellent for backing up your entire WordPress site, but it?ll also alert you to mySQL vulnerabilities and let you know when parts of your database are publicly accessible.

Always be sure to properly back up the content of your site. In a worst-case scenario, at least keeping back ups will allow you to easily restore your site. With WP-DB Manager, you could also use ?Online Backup for WordPress?. The back up the plug-in creates can be stored in your e-mail inbox, on your PC, or you can use the 100MB of free storage space on developer Backup Technology?s own secure servers.

Step 7: Install Other Useful Security Plug-Ins

I previously mentioned the Exploit Scanner plug-in, which you should run on your site every so often to check for vulnerabilities and cracking attempts. There are a number of other WordPress plug-ins that I recommend you install and use. When used properly, they can harden your WordPress site very effectively.

With Exploit Scanner, you can also use ?WP Security Scan?. Not only will the plugin look for vulnerabilities, but it?ll also give you specific advice for blocking them.

To prevent man-in-the-middle cracks to find your login credentials, be sure to encrypt your login packets with ?Login Encryption?. That plugin uses both DEA and RSA algorithms for enchanced security.

?

Installing plug-ins from the admin panel

Configure the ?Limit Login Attempts? plugin to prevent brute-force attacks. With the plugin, you can set a maximum number of login attempts, and also set the duration of lockouts in between.?The ?User Locker? plugin works in a similar way. With it, you can set a maximum number of invalid authentication attempts before the account is locked.?There?s also an excellent plug-in for securing your entire admin panel. Try ?Admin SSL Secure? plugin to encrypt your panel with SSL.

Another excellent plug-in for securing your site?s login is ?Chap Secure Login?. By using that plugin, all of your login credentials, except for usernames, will be encrypted with the Chap protocol and SHA-256 algorithm.?As mentioned before, it?s an excellent idea to change as many WordPress defaults as possible. With ?Stealth Login?, you can create custom URLs for logging in and out of your site.

WordPress sites are frequently targeted by spambots. I have to spend a lot of time going through comments on my site, and the majority of my pending comments have to be marked as spam. Imagine what those spambots can do to your site, beyond giving you a lot of tedious extra work! For that reason, I recommend installing ?Bad Behavior? on your site. By logging your site?s HTTP requests, you can better troubleshoot spambot issues. Furthermore, the plugin will limit access to your site when a bot hits it.

With Bad Behavior, you can also use ?User Spam Remover?. It will remove unused user accounts on your site. You can set an age threshold to those settings and you can also configure a whitelist. ?Block Bad Queries??will try to block malicious queries made to your site. It looks for ?eval(? or ?base64? in request URIs, and also looks for request strings that are suspiciously long.?An anti-malware shield can be applied to your entire site with the ?AntiVirus? plugin. It looks for viruses, worms, rootkits, and other forms of malware. Be sure to keep it updated!

When you choose and install plug-ins on your site, also be sure to only install plugins offered through your admin panel or under the plug-in directory at wordpress.org. Outside plug-ins may be secure, but it?s best to mitigate the risk. Officially released plug-ins are audited for security and scanned for malware.

Keeping your WordPress site hardened for security is an ongoing responsibility, just like all other areas of IT and development security. You can?t just configure a number of settings or programs and then forget about it. Your WordPress site should be on a schedule for malware and vulnerability scanning, and logs should be kept and analyzed.

By keeping your WordPress site secure, you?re doing your part to prevent malicious activity that could not only harm websites, but also web servers and user?s PCs, tablets and smartphone devices. As WordPress is such a common CMS on the web, knowledge about the design and configuration of the console is readily available, and certain hacks could work on perhaps millions of websites. Fortunately, knowledge about WordPress security is abundant, for much the same reasons. In the ongoing maintenance of your website and web server, always be security minded. You can then have proper control over your web content, and do your part to make the Internet a better place.

Kim Crawley is a researcher for InfoSec Institute.

Source: http://www.business2community.com/blogging/7-easy-wordpress-security-tips-0265029

space ball drops on namibia matt barkley melanie amaro x factor boise state jordans prometheus movie posterior

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.