Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Blogging Forum


You are currently viewing our Blogging Forum as a guest. Please register to participate.
Login



Closed Thread
How secure is wordpress?
Old 04-16-2010, 02:29 AM How secure is wordpress?
lynxus's Avatar
Awesomeo-Maximo

Posts: 1,618
Location: UK
Trades: 1
Im going to start up a blog ( or at least actually update mine ) with php and general computer stuff I learn from day to day.

Anyway..

Im thinking of using wordpress, Mainly because ive got too much work on and cant be bothered to write my own platform..

How secure is wordpress on linux?
Should i jail it?

I see a lot of sites being hackedthat use wordpress and dont really fancy my server being screwed over..

Any thoughts?
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


lynxus is offline
View Public Profile Visit lynxus's homepage!
 
 
Register now for full access!
Old 04-16-2010, 06:48 PM Re: How secure is wordpress?
racer x's Avatar
Ultra Talker

Posts: 457
Name: Randy
Location: Northern Wisconsin
Trades: 0
There are tons of great articles on extra security for wordpress.
http://www.noupe.com/how-tos/wordpre...and-hacks.html
http://www.problogdesign.com/wordpre...ress-security/
http://wpshout.com/10-practical-word...security-tips/

One that comes up alot is to create a new user with ALL privileges, then delete the admin user. This way, a hacker has to also guess the user name AND the password rather than knowing half the entry is 'admin'.

Do be careful of plugin's as well. Poorly managed ones have left gaping holes.
http://wordpress.org/extend/plugins/wp-security-scan/

I have never had a problem with security, but then again, I haven't done too many sites that would be considered "targeted" for a hacker unless he was super bored.
racer x is offline
View Public Profile Visit racer x's homepage!
 
Old 04-18-2010, 10:21 AM Re: How secure is wordpress?
wkathome's Avatar
Average Talker

Posts: 26
Name: Dan Johnson
Location: Orlando, Fl, USA
Trades: 0
I've been using wordpress.org for a year now, and the program itself can be darn fickle. When hitting save, it may or may not save what you have just entered, the same with the widgets. I added some script to my right side, and had a heck of a time getting it to show up on the main blog page. Wordpress is easy to work with, but if you can put up with times that it want's to be contrary is a pain. Sometimes I just log off and come back later to try again.
__________________
Dan Johnson
Learn to Market Like the 7 Figure Earners Do!

Please login or register to view this content. Registration is FREE
wkathome is offline
View Public Profile Visit wkathome's homepage!
 
Old 04-18-2010, 07:07 PM Re: How secure is wordpress?
Defies a Status

Posts: 1,606
Trades: 0
lynxus, WP is as secure as any major script available for mass download. Racer-x gave some good suggestions for additional security.

I think this additional one works with it also: rename the log in file to a unique name that only you know. Then you have 3 levels of protection.
__________________
Colbyt

Please login or register to view this content. Registration is FREE
colbyt is offline
View Public Profile
 
Old 04-25-2010, 11:16 PM Re: How secure is wordpress?
JValero's Avatar
Average Talker

Posts: 25
Name: Jasper
Location: California
Trades: 0
Thanks for the tips guys. I am also using WP for my blog I am launching next month. I've used it for about 2 years now and haven't had any problems. But that has been for private (career planning journals) blogs, set for my eyes only. And only briefly for a popular gaming tip blog I had going for a about a year. Loss interest in the game. :/

Anyway gonna make sure to try these when I launch my new blog. Because I plan on trying to grow it out and eventually try and draw some sort of an income through it. Thanks again!
JValero is offline
View Public Profile
 
Old 04-26-2010, 12:04 AM Re: How secure is wordpress?
Marik's Avatar
Skilled Talker

Posts: 99
Trades: 0
Out of the box WordPress is very tight security wise, the problem with security is one that comes with the introduction of plugins. Plugins that are made by inexperienced developers are usually the point of entry for most WordPress hacks. As long as you are careful about which plugins you use, for example try to stick with the most popular ones as these are well tested and revised, you should be safe. Some other things to consider are:

1. changing your wordpress database table prefix (most script kiddies rely on pre-written code that depend on the default wp_ prefix to work)

2. Use this firewall plugin:

http://wordpress.org/extend/plugins/wordpress-firewall/

I have used it for a while on a rather popular wp site and it works very well. It will send you an email when it blocks an attack.

3. htpasswd your wp-admin directory and your wp-login.php file (dual log-ins will put an extra layer of security against brute force attacks)

etc...
Marik is offline
View Public Profile
 
Old 04-26-2010, 01:39 PM Re: How secure is wordpress?
Experienced Talker

Posts: 40
Name: Jack hilcock
Trades: 0
The attacks are really common these days over WP but it all depends upon your server security. Also you can get some other security measures...
__________________
"$25 + 4 ppl + 10 wks = $1K+ per day ::
Please login or register to view this content. Registration is FREE
"
makemoney123 is offline
View Public Profile
 
Old 04-28-2010, 08:53 PM Re: How secure is wordpress?
Average Talker

Latest Blog Post:
Guam
Posts: 23
Name: guam network
Trades: 0
Thanks for the info, I'm using Wordpress and confident with it.
__________________

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
guamnetwork is offline
View Public Profile Visit guamnetwork's homepage!
 
Old 04-29-2010, 12:02 PM Re: How secure is wordpress?
Average Talker

Posts: 17
Trades: 0
Apart from frequent spam comments, wordpress is pretty stable for me - but it depends on the theme and plugins installed.
__________________

Please login or register to view this content. Registration is FREE
TemplateQueen is offline
View Public Profile
 
Old 04-29-2010, 12:06 PM Re: How secure is wordpress?
lynxus's Avatar
Awesomeo-Maximo

Posts: 1,618
Location: UK
Trades: 1
Cool,
Well im running it in a chrooted environment anyway now with very tight file permissions.

I havent and wont be adding any extra plugins.
Just needed a nice looking blog system for one of my other sites.


_G
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


lynxus is offline
View Public Profile Visit lynxus's homepage!
 
Old 04-30-2010, 03:54 AM Re: How secure is wordpress?
Banned

Posts: 36
Name: Chirag Patel
Location: Deep somewhere in SEO world
Trades: 0
Wordpress is most secured blogging platform as compared to others, you may customize the security as you need if your blog is hosted on self hosted private domain.
seoexplain is offline
View Public Profile
 
Old 05-02-2010, 05:23 PM Re: How secure is wordpress?
Novice Talker

Posts: 12
Name: Alejandro
Trades: 0
Security is not certainly one of WordPress strengths, and pretty much as it happens with windows, its popularity makes it more prone to hacker attacks.

I have never been hacked but I have read about some nasty stories that you would not want to be part of.

There are a number of security measures you can take to make your blog more secure and at least make the hackers work for it.

Some of them involve changing the database prefix, relocating your config.php file and other necessary tweaks. If you do this then you blog should be secure.
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

alexwebseo is offline
View Public Profile
 
Old 05-13-2010, 07:25 PM Re: How secure is wordpress?
Skilled Talker

Posts: 68
Name: Melvin Dichoso
Trades: 0
Wordpress is really secure BUT since so many people are using it, hackers are becoming more and more innovative to find new ways to get things done. Piece of advice is do regular backups.
__________________
MelvinBlog.Com -
Please login or register to view this content. Registration is FREE

Must Read Articles -
Please login or register to view this content. Registration is FREE

Importance of
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
| My
Please login or register to view this content. Registration is FREE
countolaf is offline
View Public Profile Visit countolaf's homepage!
 
Old 05-14-2010, 03:12 AM Re: How secure is wordpress?
mikejoel's Avatar
Ultra Talker

Posts: 494
Name: mike joel ambler
Trades: 0
I started with wordpress, for years now. Then after years of using it my wordpress got hacked and really don't know what happened on my site.
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
mikejoel is offline
View Public Profile
 
Old 05-14-2010, 05:43 PM Re: How secure is wordpress?
vangogh's Avatar
Post Impressionist

Latest Blog Post:
Why Responsive Design?
Posts: 10,815
Name: Steven Bradley
Location: Boulder, Colorado
Trades: 0
One thing to know about WordPress security is the majority of sites getting hacked are usually running an older version. 1st rule of WordPress security is to keep WP updated.

WordPress developers are usually very good at fixing security issues quickly, but you do have to upgrade to the latest version to reap those benefits.
__________________
l Search Engine Friendly Web Design |
Please login or register to view this content. Registration is FREE

l Tips On Marketing, SEO, Design, and Development |
Please login or register to view this content. Registration is FREE

l
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
vangogh is offline
View Public Profile Visit vangogh's homepage!
 
Old 05-14-2010, 07:11 PM Re: How secure is wordpress?
racer x's Avatar
Ultra Talker

Posts: 457
Name: Randy
Location: Northern Wisconsin
Trades: 0
As of late, I must say that I have been seeing a lot of WP sites hacked. Bluehost, now Godaddy, etc.

Many are due to the config.php file having the wrong file permissions.(I think that may be when fantastico installs WP actually...?)

This is straight from the Codex:
Quote:
Note that if you are on a shared-server the permissions of your wp-config.php should be 750
http://codex.wordpress.org/Hardening_WordPress

Always check this!! I have now went back and seen many cases where I forgot to and it was wrong!
racer x is offline
View Public Profile Visit racer x's homepage!
 
Old 05-16-2010, 10:39 PM Re: How secure is wordpress?
vangogh's Avatar
Post Impressionist

Latest Blog Post:
Why Responsive Design?
Posts: 10,815
Name: Steven Bradley
Location: Boulder, Colorado
Trades: 0
The issue with many of the hacks apparently is more to do with the hosts than with WordPress. Setting the proper permissions on wp-config is definitely a good idea as is setting permissions on all the files and folders. I think host don't automatically do that with their auto installs.
__________________
l Search Engine Friendly Web Design |
Please login or register to view this content. Registration is FREE

l Tips On Marketing, SEO, Design, and Development |
Please login or register to view this content. Registration is FREE

l
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
vangogh is offline
View Public Profile Visit vangogh's homepage!
 
Closed Thread     « Reply to How secure is wordpress?
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.49221 seconds with 12 queries