Deprecated: Function create_function() is deprecated in /home2/blogwebhostingbu/public_html/wp-content/plugins/facebook-like-box-responsive/facebook-like-box.php on line 29
{"id":2303,"date":"2013-04-16T06:14:23","date_gmt":"2013-04-16T06:14:23","guid":{"rendered":"http:\/\/www.webhostingbuzz.com\/blog\/?p=2303"},"modified":"2013-04-16T21:08:05","modified_gmt":"2013-04-16T21:08:05","slug":"how-to-secure-your-wordpress-site-against-hacker-attacks","status":"publish","type":"post","link":"https:\/\/blog.webhostingbuzz.com\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/","title":{"rendered":"How to secure your WordPress site against hacker attacks"},"content":{"rendered":"

\"WordPressOne of the easiest content management systems to set up and use is WordPress<\/a>, the largest self-hosted blogging platform in the world, powering more than 60 million websites<\/a> worldwide.<\/p>\n

That fact may be a key reason why WordPress is in the news<\/a> right now as the subject of a large-scale attack from a huge number of computers from across the internet\u00a0 – known as an automated botnet attack<\/a> – attempting to take over servers that run WordPress.<\/p>\n

Some are saying<\/a> that this current attack is the precursor of a botnet of infected computers vastly stronger and more destructive than those of today. That’s because the servers have bandwidth connections that are typically tens, hundreds, or even thousands of times faster than botnets made of infected machines in homes and small businesses.<\/p>\n

WordPress’ popularity comes at a price in a situation like this, as a perceived vulnerability in the platform’s ease of use is weak security by users.<\/p>\n

That weak security typically means continuing to use the word ‘admin’ as a user name – this is the default administration account that’s created when you first install WordPress – along with a password that brute-force attempts<\/a> to guess are likely to succeed, which is what’s happening with this attack.<\/p>\n

If you’ve disabled the default ‘admin’ account in your WordPress installation – or, even better, you’ve deleted it – and have something else in its place as the main administrator of your WordPress dashboard, that will likely take you out of the immediate target area of the attackers.<\/p>\n

And if you’ve set a strong password – at least eight characters and in a combination of upper- and lower-case letters along with numbers and extended characters – you’re in a good position to be passed by if or when a botnet comes calling at your WordPress front door.<\/p>\n

Don’t be complacent, though – this attack serves as a great reminder that securing your WordPress blog or website so that no one can get into it unless they’re invited is something you do need to be sure about.<\/p>\n

So what can you do to make your site secure enough right now to deter such attacks in the future?<\/p>\n

First, make sure you have the latest WordPress version<\/a> installed. As of today, that version is 3.5.1.<\/p>\n

If you still have an administrative user called ‘admin,’ there are two steps to take:<\/p>\n

    \n
  1. Create a new admin account with a different name and give it a strong password.<\/li>\n
  2. Delete the ‘admin’ user account; during that procedure, you’ll be asked by WordPress which other account should you assign posts, pages, etc, created by ‘admin’ to. Choose the new admin account name you just created.<\/li>\n<\/ol>\n

    Next, enable two-step verification<\/a> for each user in your WordPress account. The simplest such service for a WordPress user to install and implement is the open source Google Authenticator<\/a>. If you have that enabled for your Google account, or other services such as Dropbox<\/a> or Amazon S3<\/a>, then you’ll be familiar with how it works.<\/p>\n

    \"WordPressAnd you’re in luck for your self-hosted WordPress site as there’s an excellent plugin that sets it up for you – Google Authenticator plugin for WordPress<\/a>.<\/p>\n

    Grab it now, either by downloading it from the WordPress plugin repository or installing it via the ‘add new plugin’ function in your WordPress dashboard.<\/p>\n

    You’ll need the free Google Authenticator app for your smartphone in order to use this security feature. There are versions for Android, Blackberry and iOS<\/a>.<\/p>\n

    And if you then follow the excellent “How To Enable 2-Step Authentication On Your Self-Hosted WordPress.org Site<\/a>” guide published last week by Techfleece, you’ll be up and running in no time with a WordPress site that will give you more peace of mind than you had before.<\/p>\n

    In my view, this is the bare minimum you should have set up in your self-hosted WordPress site that gives you a good level of security for your peace of mind. It would make it more difficult to hack into your site.<\/p>\n

    There’s a lot more you can do as well including steps to take to better secure the server on which your WordPress platform is installed. There’s a great tutorial on the WordPress Codex<\/a> that can tell you more.<\/p>\n

    Don’t let spammers, hackers or botnets mess up your presence on the web. You can be secure.<\/p>\n","protected":false},"excerpt":{"rendered":"

    One of the easiest content management systems to set up and use is WordPress, the largest self-hosted blogging platform in the world, powering more than 60 million websites worldwide. That fact may be a key reason why WordPress is in the news right now as the subject of a large-scale attack from a huge number […]<\/p>\n","protected":false},"author":420,"featured_media":2604,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[343,134],"tags":[275],"yoast_head":"\nHow to secure your WordPress blog against hacker attacks<\/title>\n<meta name=\"description\" content=\"Our guide to securing your WordPress blog against hacker attacks covers everything you need to know to step up security quickly and easily. We give you multiple tips and techniques to keep hackers locked out -- for good.\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to secure your WordPress blog against hacker attacks\" \/>\n<meta property=\"og:description\" content=\"Our guide to securing your WordPress blog against hacker attacks covers everything you need to know to step up security quickly and easily. We give you multiple tips and techniques to keep hackers locked out -- for good.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"WebHostingBuzz US Blog\" \/>\n<meta property=\"article:published_time\" content=\"2013-04-16T06:14:23+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2013-04-16T21:08:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.webhostingbuzz.com\/wp-content\/uploads\/2014\/06\/wordpressattack.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"198\" \/>\n\t<meta property=\"og:image:height\" content=\"195\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data1\" content=\"4 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#website\",\"url\":\"https:\/\/www.webhostingbuzz.com\/blog\/\",\"name\":\"WebHostingBuzz US Blog\",\"description\":\"Hosting, hosting, more hosting and a little of everything else\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.webhostingbuzz.com\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/blog.webhostingbuzz.com\/wp-content\/uploads\/2014\/06\/wordpressattack.jpg\",\"contentUrl\":\"https:\/\/blog.webhostingbuzz.com\/wp-content\/uploads\/2014\/06\/wordpressattack.jpg\",\"width\":198,\"height\":195},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/#webpage\",\"url\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/\",\"name\":\"How to secure your WordPress blog against hacker attacks\",\"isPartOf\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/#primaryimage\"},\"datePublished\":\"2013-04-16T06:14:23+00:00\",\"dateModified\":\"2013-04-16T21:08:05+00:00\",\"author\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#\/schema\/person\/6b62de29768678c29861b9ce053d2f1a\"},\"description\":\"Our guide to securing your WordPress blog against hacker attacks covers everything you need to know to step up security quickly and easily. We give you multiple tips and techniques to keep hackers locked out -- for good.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/\",\"url\":\"https:\/\/www.webhostingbuzz.com\/blog\/2013\/04\/16\/how-to-secure-your-wordpress-site-against-hacker-attacks\/\",\"name\":\"How to secure your WordPress site against hacker attacks\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#\/schema\/person\/6b62de29768678c29861b9ce053d2f1a\",\"name\":\"Neville Hobson\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.webhostingbuzz.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/46f89a506136d66774c7e29ce40d275f?s=96&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/46f89a506136d66774c7e29ce40d275f?s=96&r=g\",\"caption\":\"Neville Hobson\"},\"description\":\"Entrepreneurial communications professional with a curiosity for tech and how people use it. Early adopter (and leaver) and experimenter with social media. Co-host of the weekly business podcast For Immediate Release: The Hobson and Holtz Report. Also an occasional test pilot of shiny new objects. Follow me on Twitter and Google+.\",\"sameAs\":[\"http:\/\/www.nevillehobson.com\",\"https:\/\/twitter.com\/http:\/\/jangles\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/posts\/2303"}],"collection":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/users\/420"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/comments?post=2303"}],"version-history":[{"count":0,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/posts\/2303\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/media\/2604"}],"wp:attachment":[{"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/media?parent=2303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/categories?post=2303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.webhostingbuzz.com\/wp-json\/wp\/v2\/tags?post=2303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}