Posts Tagged ‘People’

How to Secure WordPress

Friday, September 11th, 2009

iStock_000002714744Small

If you are an internet marketer, you probably have quite a bit on your plate already.   You have spent a great deal of time putting together a good website or blog and are really concentrating on how to deliver your product or information.   Unfortunately, there are a certain breed of people out there in cyberspace whose self appointed mission is to break into your vault and create havoc.

If you are using WordPress as a platform to blog from, here are a few tips on how to secure WordPress

Keep WordPress Updated and Backed Up

Older versions of WordPress still have many vulnerabilities that are widely known in the hacker community.  To their credit, the WordPress people are always doing their best to plug security holes and are updating constantly.   So your first line of defense is to keep your blogging platform updated.

Medical Tip:  To avoid increasing your blood pressure, always be sure to make a backup of your blog before installing any updates.   Its a good idea to regularly to keep your WordPress backed up regularly anyhow, since any number of things can go wrong.

Another tip is to delete the meta tags that tells the world of the version of Wp you are using.  This info is usually in the header file.

Keep Your Plugins Hidden

One of the great things about using WordPress is the plugins. While they greatly increase your blogs capabilities, they too contain certain bugs and vulnerabilities that are exploited by hackers.   So be sure to keep them updated also.

It is easy for anyone to see what type of plugins you are using by visiting the wp-content/plugins folder.   To keep potential intruders from finding out the plugins that you use, create an empty  ‘index.html’  file and place it in your plugins folder

Its also a good idea to check your plugin folder and make sure the plugins there are the ones you want.  Some hacker, once they get into your files upload their own plugin.   So if you see something that you are not familiar with, delete it.

Here is a  Free WP plugin that keeps track of the attempts to login to your site.   Many hackers use brute force to try and get your password.   So, if there are too many of them coming from the same IP address within a short period of time, the plugin will disable the login function for that IP range.   Login Lockdown:  bad-neighborhood.com.  Click on login lockdown and you will be taken to the download page.   Be sure to check out their other plugins to.

Change Your Passwords

This is an easy hack that is often exploited.  You can have a more  secure blog by making up a crazy, difficult password.   Even change it monthly if need be.

But not only your WordPress login.  Don’t forget your hosting account and your ftp passwords as well.

Headache tip: Be sure to write your passwords down immediately and keep all your them all in a safe place.

Secure the /wp-admin/ directory

Your  most sensitive Wordpress information is stored in the /wp-admin/ folder.  By default, WordPress leaves that folder open, so people can access these files to make changes  if they know what they are doing.

To secure this folder:

Place an .htaccess file inside the /wp-admin/ folder to block the access to all IP addresses, except yours.

Here is the code you need to put in the .htaccess file:

AuthUserFile /dev/null

AuthGroupFile /dev/null

AuthName “Example Access Control”

AuthType Basic

order deny,allow

deny from all

allow from xx.xx.xx.xx

allow from xx.xx.xxx.xx

Now, ff you ever find your site being redirected to another website you will need to:

Check For Hidden Code

This requires a bit more knowledge of the inner workings of WP on your part, so don’t mess with it unless you know what you are doing.

Browse your theme files

Log into your WordPress control panel, go to the theme editor, and look inside your theme files.   See if there are any lines of code that are not supposed to be there, or that contain a PHP code that you don’t recognize.

Check your database tables

Some hackers upload fake images to your “Uploads” folder and activate them with a plugin call.   To detect this you need to open PHPMyAdmin, browse the “wp-options” table, and edit the “active_plugins” record.

On that record you will see a list of all the plugins that active on your blog.   Delete any that seem unusual or that you aren’t using

Browse your site files through FTP

Log into your FTP account and browse through the folders on your site.   You are looking for any files that have a strange name or that look suspicious.    If you have another WordPress blog installed on another site, compare the structure of the files to make sure they match up.

Tip to avoid a heart attack:  Remember: Backup, backup, backup, before you star messing with anything!

Be Fearless

Billy Ojai

Do you want to make more money in Internet Marketing? One way is to learn good copywriting techniques. Pick up your Free copy of ‘Copywriting for the Web’ at http://billyojai.com

change domain homepage to wordpess homepage?

Monday, June 29th, 2009
Wordpress Plugin
Timothy M asked:


I have a wordpress blog in a subfolder of my domain. I would like to know if it is possible to make my hompage for the domain be my homepage from wordpress. Make example.com’s homepage not be home.html or whatever you can use as the file name for your domain. and just make it so when people go to example.com they go straight to my wordpress blog homepage thats in a subdirectory. Is this Possible? Using a plugin, changing script.
and if so can you explain how or point me to a link
thanks

Free Tech Support

If you have a website and you use a wordpress theme, does that make it a blog?

Saturday, March 28th, 2009
Wordpress Theme
Sir Walter asked:


I know this sounds like a stupid question but I want to know if people will consider it a blog if I use a wordpress theme.

Surrey City BC

How can I upload a theme in my wordpress blog & make people know about my blog?

Wednesday, July 16th, 2008
wordpress
siddhartha m asked:


I just made a blog in wordpress .i wanna know how to upload a theme in my blog.is there any software for it?How can I make people knoe about my blog?

Tech Support

Play Hide and Go Seek With Google Adsense On Your Blog

Monday, February 4th, 2008
LivingOnAdsense asked:


video discussed how different traffic sources react differently to Google Adsense Ads. I have found a great plugin for Wordpress that allows you to only show your adsense ads to viewers that came from specific locations. In my case I only want to show my the ads on my Adsense Blog to people that have come from search engines. Check out blog post to get the plugin and for more details. livingonadsense.com … google adsense blog wordpress plugin ppc blogging blogoshpere search engine traffic …

Free Technical Support

Question for people savvy with the NextGen Gallery plugin for Wordpress?

Sunday, July 15th, 2007
Wordpress Plugin
Mandy M asked:


Is there any way that when someone clicks on a picture in my gallery it automatically opens with PicLens instead of just that one picture? And with that, can I remove the “View with PicLens” link? I just wanna clean it up a bit. Thank you for any help!

Surrey City BC

Issues with WordPress SEO Secrets

Friday, October 27th, 2006
remarkablogger asked:


michaelmartine.com Addressing a couple issues that people have raised about WordPress SEO Secrets. I hit them head on and talk about them openly.

Free IT Support

How can I setup wordpress to allow memberships?

Tuesday, October 10th, 2006
wordpress
Good day asked:


I would like to setup wordpress blog that would allow people to sign up to receive news letters and updates? Do I need to download wordpress to my computer? Is there any pre-made templates for this type?

IT Support

How do you get a customised wordpress background?

Thursday, February 9th, 2006
wordpress
Green Eyed Masterpiece asked:


On some wordpress blogs some people have customised backgrounds. How do you get these, can someone help me pleaseeeeeeeeee?

Technical Support

Legalities using WordPress to develop sites for clients?

Sunday, January 15th, 2006
Wordpress Plugins
Rob7 asked:


Does anyone know the legalities to using wordpress to setup sites for clients?

Also using the plugins? The themes are custom so that is not an issue.

Another thing, what about the plugins that remove the visual elements to brand wordpress. I have seen a few plugins that scale down the admin panels features, and also remove all mentions of wordpress.

So, to me that is developed for people trying to do what I am as well? But is this accepted and allowed?

Thanks Everyone!

Surrey BC