How to secure your wordpress blog

July 15th, 2008

  1. Use latest stable version of Wordpress. Don’t use beta version!
  2. Your database table prefix must be other than default prefix (wp_) - Securing against sql injection.
  3. Wordpress version must be hidden - Many hackers take this advantage to attack wordpress in version that vulnerable. So, let them know nothing.
  4. Must be no user “admin” - this should be guested during sql injection. If u used it.. change it now.
  5. Put .htaccess in yout /wp-admin/ directory. - avoid directory listing.
Share This Post

 

Posted by Mr Am on July 15th, 2008 | Filed in Hacker, Network Security, Wordpress, hacking |


2 Responses to “How to secure your wordpress blog”

  1. September 7th, 2008 at 5:08 pm

    lubuntu Identicon Icon lubuntu said:

    ada lagi..
    1.default login page http://domain.com/wp-login.php tidak di sorok ;)
    2.tidak menggunakan captcha pada wp-login.php - allow bruteforce
    3.commnet juga tidakk menggunakan captcha - allow DDoS

    [Reply]

    Mr Am Identicon Icon Mr Am Reply:

    Tq..

    [Reply]



Please leave a Comment





:) :( :d :"> :(( :d/ :x 8-| /:) :o :-? :whistling: :-w ;) [-( :)>- more »