English flagItalian flagKorean flagChinese (Simplified) flagPortuguese flagGerman flagFrench flagSpanish flagJapanese flagArabic flagRussian flagDutch flagCzech flagFinnish flagHindi flagPolish flagRomanian flagSwedish flagHebrew flagIndonesian flagSerbian flagUkrainian flagThai flagTurkish flagHungarian flag                 
New Online Casino Websites Top Ten Best Online Casinos Casino With Sign On Bonus Casino Sites For Usa Players Online Casino Payouts Sign Up Casino Bonus Online Casinos Best Bonuses Casino Deposit And Mastercard Casino That Allow Us Players For Real Money Rtg Online Casino Bonus Online Casino Games For Mac No Download Roulette Registration Bonus On Line Casino Sign Up Bonus Internet Slots United States Download New Casino Games 2010 New Casinos With Deposit Bonus American Online Casino Guide Biggest Usa Online Deposit Bonuses Online Blackjack For Money Legal Instant Playing No Download Slots Games Online Casino Ewalletxpress Best Online Usa Casino Bonuses Internet Casino Slot Games Video Slots With Bonus Play Online Casinos Us Player List No Download Required Online Casinos Online Slots Real Money Bonus Gamble Blackjack Online Real Money Casinos Online Us Based Slots Bonus Us Players List Of Rtg Casino Bonus Codes Best New Online Casinos Rtg Casino Redeem Codes Top Casino Promotions Flash Casino Us Amex Blackjack Online Gambling Real Money Internet Casino Sites New Rtg Casino List Best Slots No Download Best Online Casino For U.s. Residents Usa Casino Reviews New Slot Machine Downloads Rtg Casino Bonus Slots Top 10 Casino Downloads Casinos In America To Download Latest Casino Codes For Rtg Casinos Las Vegas Casinos Online Real Money Vegas Slot Bonus Codes Best Casino Flash Online Casino Flash Online Blackjack Sign Up Bonus Casino Rtg Coupon Codes Moneybookers Deposit Casino Video Slots Amex Top 10 Casino Names United States Casino Slots Gambling Website Where Us Players Can Play Play Online Slots Now Flash Casino Real Money No Download Slot Play Best Online Internet Casinos Usa Welcome Bonus Slots Best Bingo Sign Up Bonuses America Mac Casinos Multiplayer Blackjack Online Rtg Casino Echeck Usa Casinos With No Downloading Vegas Casinos Slot Payout United States Casinos Online Online Casino Best Top10 Usa Web Complete List Of Online Casinos Casinos That Play For Money Echeck Casinos In The Us Best Blackjack Online Casinos Mastercard Casinos Usa List Of Casinos In The Usa The Best Slots Ever New Online Casinos Accepting Us Players With Bonus Us Casinos Online Take Us Credit Cards Gamble Online Debit Video Slots Casino Mac Best Odds Online Craps Mac Casino Real Money Play Slots With Welcome Bonus Best Promotion Casino Play Real Money Casinos In Usa Real Money Casino In Usa Casino Instant Online Slots With American Express Deposit Rtg Casino Signup Bonus Best Casino Promotions 2010 Casinos Online With Real Money Us Players Slot Casino Usa Casino Online Slot Tournaments Casino Video Slot Game Rtg Online Casino Usa Casino Download For Mac Usa Casinos That Accept Mastercard Tournaments For Rtg Casinos Play Craps Online For Real Money New Instant Play Casino Casino Allowing Us Players Internet Casino Gambling Blackjack Casinos Online Allow Usa Player Deposit American Express Online Game New Deposit Casino Bonus Black Jack Ewalletxpress Sign On Bonus Slots Usa Flash Casino Welcome Bonus Best Match Bonus Casinos New Casino Sites Online Online Slots In Usa Real Money Online Casinos For Americans New Casinos With New Bonus Offers Online Casino For Real Money Play Casino Card Game Best Online Casinos Accept Us Best Online Casino Bonus Us Friendly Flash Casino Blackjack Online Bonus Slot Games Online Casino Slots To Play Us Online Real Slots Deposit Casinos No Download 1000 Slot Bonus Casinos Excepting Us Players Flash Casino For Us Players Best Online Slots With Bonus Rounds New Usa Slots Top Online Slots Casinos Top Internet Casinos Online Bonus Slot Games Best Video Slots Casino Play Casino Slots Online In United States Casino That Takes American Express Gamble Online Using Echeck Us Casino Player Deposit Bonuses Internet Casino Craps Odds Casino Mac No Limits Online Roulette Play Casino Table Games Online Best Usa Casino Sites Casino Online For Us Players Approved Us Online Gambling Online Slot Machine Games No Download Bonus Game Slot Machines Online Casinos And U.s. Credit Cards Complete Listing Rtg Online Casinos Casino Online Games In California 10 Best Online Casinos Us Online Slots Best Online Slot Bonuses United States Online Blackjack Casino New Casino Online Usa Casinos Deposit Sign Up Bonus Casinos Online Casinos Accepting Us Players Us Players Accepted Casino Bonus New Casino On Net Legal Usa Casinos Us Players Online Casino Best Signup Bonus Online Slots Machines Real Money United States No Downloading Casinos No Download Slots And Games Gamble Online With Echeck New Online Casinos For Usa Players Best Casinos For Us Players Casino Slots For Us Players Online Us Slots Tournaments On Line Casinos Accepting Mastercard For Deposits Las Vegas Slot Machine Tournaments Slot Bonus Machine 15 Lines On Line Slots Using Us Money 20 Reel Bonus Slots Ewallet Rtg Casino Bonus Slots Review Blackjack Game Online Slot Machines 2010 Casinos On Line Con American Express Legal Usa Online Casino Poker Casino Bonus For Us Players New Slots Online Casino Roulette Mac High Roller Casino Online Gambling And Ewallet Xpress Bonus Online Roulette Play Bonus Slot Games Istant Flash Casinos For Mac Online Casinos Allowing American Players Online Casinos Mac For Real Money Usa Casinos Best Bonuses European Roulette Casinos That Allow Us Players America Online Casinos Internet For Slot Machines Rtg Online Casinos Usa Players No Download Casino Video Slots Casinos To Play For Real Money Online Us Casino Payouts Rtg Casinos Accept 900 Pay New Casinos With New Slots Usa No Download Casino Slot Machines Flash Casinos With Bonus Roulette No Download Best Match Casinos Top Sign Up Bonus In Usa Casinos Mac Slots Casino Best Slot Machines Casino Online Casinos Payouts Online Gambling With Us Credit Cards Bonus Slot Casino Coupons Internet Casinos Bonus Online Gambling Promotion Codes Flash No Download Casinos Online Blackjack Us Virtual Online Blackjack Casino Online Casino Sites 2010 American Casino Guide Casinos With Instant Play Best Slot Machines To Play Gamble Online Slot Machines Download Casino Games 2010 Map Of Us Casinos Slots Casino For Mac List New Casinos Craps Gambling Best Paying Usa Online Casino Best Promotions For Casinos Bonus Slot Download Online Video Poker Bonus Codes Best Online Slots And Bonus Gamble Online Using Bank Account Online Casino Accepting Us Players With Bonus Top Casinos For Us Players New Online Casino Promotions No Download Online Casino Roulette Best Payout Online Casino For Us 99 Slots Bonus Codes Top Casino Bonuses New Usa Online Flash Casinos Online Casinos With Instant Bonus No Download Slot Machines Rtg Games Slots Mac Casino Sign Up Bonus Forums Internet Casino Directories Legal Usa Gambling Online Online Usa Credit Card Casinos List All United States Signup Bonuses Play Casino Slots Online Slots American Express Online Casinos For Us Players For 2010 Real Money Slot Machines Online Online Slot Tournament Usa Online Casinos Usa Credit Cards 3 Reel Slots Online Gamble Poker Machine Download 2010 Casino Bonus Gamble Online Review Black Jack For Mac Black Jack Casino Gamble Online United States Slot Games By Credit Card Complete Rtg Casino List Casino Sign On Bonus 3 Reel Slots Real Money Slot Machines Usa Casino Real Money Online Craps Gambling Roulette Casinos Accepting Us Players European Roulette Download Casino Usa Best Bonus Online On Line Gambling For Us Players Best 5 Reel Slot Machines Us Slot Promotion Craps Online For Macs Online Casino Best Match Bonus Casino Us Player Gambling Sites That Accept Us Credit Cards Best Us Online Casinos Online Video Slots Casinos Rtg Casinos With No Downloads Play Real Money Casinos Casino For Mac User Gamble Online Usa Best Us Friendly Casinos Online Blackjack Accepting Mastercards Bonus Roulette Slot Machine Legal Online Usa Casino Gambling Slots For Macs Best Start Up Bonus At Online Casinos Us Bonus Codes Slots Best Online Slots Play Usa Casinos Accepting Mastercard Casino Promotion Guide Mac Casino With Real Money Bonus Play Casino Slot Machines Online Casino Usa Players Gamble Online In Vegas I Want To Play Casinos Games On Line Complete List Of Us Online Casinos European Roulette No Downloads Best Us Slot Machines Casinos Casino Best Signup Bonus Casino In The Usa Best Bonus Slot Downloads Online Casinos Accepting Usa Players No Download Rtg Casino Slots With Sign Up Bonus Best Real Money Blackjack Gambling Online Online Casino Promotions For Usa Players All Online Video Slot Machines Casino Sign Up Bonus No Download Internet Casino Site Instant Bonus Casino Games High Roller Blackjack Table Play Blackjack For Money Online Slot Tournaments For Cash Real Casino Bonus Slots American Casino Slots On Line Video Casino Slots Online Online Casinos Accepting American Players 2010 Us Casinos Bonuses Accept Us Player Casino Casino Games With No Downloads Casino Except Usa Slot Machine 2010 Download Online Instant Casinos Games Top Online Casinos Mac Casino Online Real Money New Online Casino For Us Players Casino Sites Uk Casino Online Sign Up Bonus Moneybookers Accepted Casino Slot Tournaments Vegas Us Casino Downloads New Rtg Casino Games New Online Casino Accepting Us Players Play Casinos Games For Mac Best Slots Download Instant Casino Poker Us Casinos That Accept Debit Cards Casino Online Slots Us Online Casino Top 5 Casinos That Accept All Us Players Ewalletxpress Casino Slots Online Slots For Real Money American Express At Casinos No Download Casino For Mac 2010 Casino List Online Slots Bonus Us Top Ten Online Casino Best Deposit Bonus Casinos For Us Players Gambling For Real Money Mac Gamble Online Mastercard Online Casino Usa Amex Online Usa Casinos Slot Tournaments Best Online Casinos Open To Us Players Casino No Download Slots Gambling Online With Macintosh Blackjack With Real Money No Download Casino Games Online Gambling 4 Us Bonus Codes For Slots Multiplayer Blackjack Games Casino Mac Os Real Online Blackjack Us Roulette Bonus Casinos Accepting Us New Bonus Slots No Download Best Us Deposit Bonus Casinos Best Internet Casino Guide American Original Online Slots Best Online Casino For Usa Players On Line Slots For Real Money In The Usa casino deposit casino

USA Online Casinos blackjack casino usa players

Is your WordPress blog hacked? Why not upgrade to the latest version?

Wordpress logo

If you are running WordPress blog software (and it’s not upgraded to the latest version) you might have been a target for hackers who are looking to take over blogs for search-engine optimization (SEO) of other sites they control, traffic-redirection and other bad purposes.

Most of the attacks consist in using SQL injection and XSS cross-site scripting and that is because the user input isn’t filtered properly by the software. Some of the attacks use bots which can create hundreds of spam pages on your blog automatically, place a backdoor (so the hacker can come back at later time) or steal users passwords.

Hackers are taking advantage of the open-source nature of the software to look and analyze the source code of a specific software they want to attack and test it for potential vulnerabilities. Then the developers and users have to detect, track down, and shut down the vulnerabilities in the code that those attackers are using.
The pattern seems to be the same: when a new hole is found, it’s broadly exploited, then developers rush out a patch and/or a new release. Most of the damage inflicted by the automated exploits can be reversed with an upgrade but in some cases you can be left with thousands of spam pages and images to clean up (and they are usually well hidden). If the attacked software is very popular (and that attracts hackers too) – like WordPress – then thousands of installs can be compromised.

Chances are that a blog owner realizes late that his blog was hacked that why it is important to keep up with the latest upgrades and security patches from WordPress.com and keep an eye on your blog: monitor the statistics, the blog usage, have frequent backups and track other security blogs for news about any security holes one of them is BlogSecurity.net.

Always upgrade your WordPress installation to the latest version (also any latest security patches released should be installed). Be aware that if you installed WordPress from within Fantastico package then most probably you won’t have the latest version in the package (it seem Fantastico guys takes their time in updating their package with the latest versions of the software they put in that package – WordPress included). Faster than them in updating their software the guys from SimpleScripts (Fantastico and SimpleScripts are usually offerend by many hosting companies to their subscribers).

How you secure your WordPress installation?

 

  • Your “plugins” directory is NOT secured by default!
  • And that means there’s no “index.html” or “index.php” file in that directory so anyone can SEE what plugins are you using by just going to “www.yoursite.com/wp-content/plugins”. It is easy to stop this by creating a blank HTML file named “index.html” and put it in that directory. Job done!

     

  • Choose a strong password!
  • Don’t use an easy to be guessed admin password (your several characters small name, your wife’s name, pet names, etc)…choose a longer password and try to combine it with numbers and upper/lower case letters (even other characters like #,$,%,^…). And change your admin password regurarly!

     

  • Use security-related plugins!
  • Some of these security related plugins may help you:

    - BS-WP-NoVersion
    A lot of attackers and automated tools will try and determine software versions before launching exploit code. Removing your WordPress blog version may discourage some attackers and certainly will mitigate virus and worm programs that rely on software versions.
    You can get this plugin from here (download it as PHP file – not TXT – and put it in your “plugins” directory, then activate it)
    Or you can use Replace WP version plugin.

    - Login LockDown
    Login LockDown records the IP address and timestamp of every failed WordPress login attempt. If more than a certain number of attempts are detected within a short period of time from the same IP range, then the login function is disabled for all requests from that range. This helps to prevent brute force password discovery. Currently the plugin defaults to a 1 hour lock out of an IP block after 3 failed login attempts within 5 minutes. This can be modified via the Options panel. Admisitrators can release locked out IP ranges manually from the panel.
    Download it from here.

    - AskApache
    AskApache Password Protect adds some serious password protection to your WordPress Blog. Not only does it protect your wp-admin directory, but also your wp-includes, wp-content, plugins, etc. plugins as well. Imagine a HUGE brick wall protecting your frail .php scripts from the endless attacks of automated web robots and password-guessing exploit-serving virii. Forget spam, these millions of zombie bots are too outrageous to ignore, they are attempting known (but strangely outdated) exploits looking for known vulnerabilities against blogs and other Internet software. Sooner or later some poor blogger is going to miss an upgrade and become a victim to this type of video-game-like-attack.
    Get it from here.

    - WP Security Scan
    Scans your WordPress installation for security vulnerabilities and suggests corrective actions: passwords, file permissions, database security, version hiding, WordPress admin protection/security, removes WP Generator META tag from core code
    Download it from here.

    - Use WordPress firewall!
    A weblog platform is vulnerable to hacking attempts which is where their unique firewall protection for WordPress will give you peace of mind (so they say).
    The firewall script supports PHP and MYSQL making it an ideal partner for WordPress. No matter what version of WordPress you are using the Firewall Script will make your blog secure (protecting your blog from SQL Injections, Coding Errors, Cross Site Scripting (XSS), Cross-site request Forgery (CSRF), Password theft (IP Lock), Comment Spam, DDoS Attacks, Customized wordpress ruleset (blocks all exploits)).
    Download Firewall software now to make your WordPress installation secure against web based attacks (this software is not free!).

     

  • Rename the administrative account!
  • You can do this in the MySQL command-line client with a command like “update tableprefix_users set user_login=’newuser’ where user_login=’admin’;”, or by using a MySQL frontend like phpMyAdmin.

     

  • Backup your database!
  • You should backup your data regurarly (that includes the database). Encrypting the backup, keeping an independent record of MD5 hashes for each backup file, and/or placing backups on read-only media (such as CD-R) increases your confidence that your data has not been tampered with.
    One good utility is WP-DBManager and can be downloaded from here or WP-DB-Backup which can be downloaded from here.
    Or you can use the MySQL database manager of choice: phpMyAdmin (how to use this as a backup tool read here)

     

  • Log all your $POST variables!
  • Standard Apache logs do not offer much help with dealing with security forensics.
    So, to log all $POST variables sent to WordPress you can use this plugin called Postlogger (download it from here).
    If you happen to be using this plugin, and actively logging all $POST variables, and your WordPress install is exploited, you will be able to go back and actually see where and how the exploit occurred. Armed with that information, you can take the data to the WordPress developers.

     

  • Plugins that need write access!
  • If a plugin wants write access to your WordPress files and directories, then first read the code to make sure it is legit or check with someone you trust and is more savvy than you. Other possible places to check are the WordPress Support Forums and IRC Channel.

     

  • Encrypt all communication within “wp-admin” directory! (if possible)
  • You can secure and encrypt all of your communication and important WordPress cookies using the Admin-SSL plugin. Works with Private and Shared SSL. This plugin can be downloaded from here.

     

  • Tighten up the file permissions!
  • Some of WordPress’ cool features come from allowing some files to be writable by web server. However, letting an application have write access to your files is a dangerous thing, particularly in a public environment.
    From a security perspective, it is best to lock down your file permissions as much as possible and to loosen those restrictions on the occasions that you need to allow write access, or to create special folders with more lax restrictions for the purpose of doing things like uploading images.

     

  • Of course, update your WordPress!
  • Like I said above, keeping your WordPress installation up to date is one of the most important measure against hackers. And it’s not complicated to be done either (backup everything before upgrade!).

Learn more about Hardening a WordPress installation here, on WordPress website.

To test your WordPress blog for weaknesses Blogsecurity website developed an online WordPress scanner.
You can try it out here.
*NOTE: Before using this scanner you need to install a plugin (named “wp-scanner”) they offer and can be downloaded from here! Activate the plugin, scan your blog, then deactivate the plugin to prevent others scanning your blog again.

 

BlogSecurity also offers a WordPress Security Whitepaper which has detailed informations about securing your WordPress installation. Read more here.

 

Now that you have SECURED your blog (hopefully you did implement those above measures, did you? at least most of them…) please read more how others were attacked and what did they do to fix this. Or just read how can YOU be attacked by different means.

 

————————————
Mircea Goia was born in Romania and immigrated to US in 2005.
He lives in Phoenix, AZ and works as web developer. Aside, he works also on several entrepreneurial Web projects.
He shows a keen interest in commercial Web development such as social networks, viral marketing and online video.
His artistic hobby is filmmaking with special interest in directing.

————————————

Sphere: Related Content



Want more web software reviews, news and tips/tricks?
Then make sure you subscribe to our RSS feed!


Related posts

1 Star2 Stars3 Stars4 Stars5 Stars (6 votes, average: 5.00 out of 5)
Loading ... Loading ...

10 Responses to “Is your WordPress blog hacked? Why not upgrade to the latest version?”

  1. Your Blog Got Cracked! 8 Steps To Show You Concern | Make Money Online Blog UNITED STATES Says:

    [...] Is your WordPress blog hacked? Why not upgrade to the latest version? [...]


  2. dian INDONESIA Says:

    Thx for the info, u really help me with the issue of securing my wp site.
    btw i knew that GNUCitizen.org has released plugin for wordpress last october, WP Blogsecurify 1.0 . have u review the plugin? u can see it in http://www.gnucitizen.org/blog/wp-blogsecurify-10/


  3. Mircea Goia UNITED STATES Says:

    No, I haven’t seen that plugin but I’ll take a look. Thank you for the info.


  4. Sameer Dhoot UNITED STATES Says:

    This is a good article.. good work..keep em coming…


  5. Wordpress Secure Login INDONESIA Says:

    You can use wordpress stealth login like this tutorial http://xtremenitro.org/2008/12/29/stealth-login-secure-your-wordpress-login.html


  6. Mircea Goia UNITED STATES Says:

    If that page would be in English it would be better.
    The link to the stealth plugin is here: http://wordpress.org/extend/plugins/stealth-login/


  7. Titus Barik UNITED STATES Says:

    Great tips! It’s surprising that the plugins directory doesn’t have an index.php or index.html file included by default.


  8. emin TURKEY Says:

    hello ?m speak turk?sh. not speak english:-(


  9. Fotos de cali COLOMBIA Says:

    esta muy bueno el post, sobretodo los plugins para hacer backup de al base de datos :D


  10. Freshly Pressed » Blog Archive » WordPress security UNITED STATES Says:

    [...] Is your WordPress blog hacked? [...]


Additional comments powered by BackType