SlideShare una empresa de Scribd logo
1 de 26
Presenter:
Tom Townsend
Tom is a Cloud Technical Manager for a
Fortune Global Company and also owns and
operates SMBsocial.com a local WordPress
Agency.
Has been using WordPress since 2007
 Co-Organizer of Tampa Bay WordPress Meetup
 Co-Organizer – New Port Richey WordPress Meetup
 Co-Organizer WordCamp Tampa 2014,2015,2016
Contact:
Email: tom@smbsocial.com
SMBsocial
https://www.linkedin.com/in/thomastownsend/
• Welcome to the first 2017 Newport Richey WordPress meetup.
• Were 1 of 6 Regional Meetups that make up the Eco System of the
Tampa Bay WordPress Network /Community
SecuriCyber security is the Hot Topic in 2017
ng your WordPress website• Cyber Attack
• Phishing
• Malicious Websites
• Ransomware: WannaCry, Petya
• Malware: GhostHook, PowerPoint
Social Engineering Attack,
downloader - hyperlink - subtitles
in Free Movies (video players like
Popcorn Time & VLC)
Where does YOUR website fit in?
ng your WordPress website• WordPress – Good and bad
• What do you need to watch out for and how can you ensure your site is secure.
• From Hosting to WordPress Core, Plugins and Themes.
A few statistics
• According to a survey of hacked WordPress site owners, brute-force
attacks were the second most popular known method of hacking, with
password theft not too far down the list. These attacks should be a very
real concern for WordPress users.
• July 03, 2017 - SQL injection vulnerability found in popular WordPress
plug in
https://www.scmagazineuk.com/sql-injection-vulnerability-found-in-
popular-wordppress-plug-in-again/article/672839/
• April 2017 Home Routers Used to Hack WordPress Sites -
There's a group of hackers who are hijacking unsecured home routers and
using these devices to launch coordinated brute-force attacks on the
administration panel of WordPress sites. The purpose of these attacks is
for the hackers to guess the password for the admin account and take over
the attacked site.
https://www.bleepingcomputer.com/news/security/home-routers-used-
to-hack-wordpress-sites/
It's NOT just WordPress sites getting hacked:
• June 2017
• Year-old vulnerability allowed pro-ISIS hackers to hack US Government websites
• Affected websites reportedly included (amongst others) the Department of Health for the state of
Washington, the Rhode Island Department of Education, the official websites of Ohio Governor
John Kasich and his wife, as well as the Ohio Department of Rehabilitation and Corrections.
• all of the compromised websites were running the same content management system –
DotNetNuke (better known as DNN).
• There’s nothing inherently wrong with running DNN to power your website, but what is a very
bad idea is not keeping your content management system up-to-date. Because the version of
DNN that was being run on the defaced websites was version 7.0, released way back in 2015. The
latest edition of DNN is version 9.01.
https://hotforsecurity.bitdefender.com/blog/year-old-vulnerability-allowed-pro-isis-hackers-to-
hack-us-government-websites-18289.html
It's NOT just WordPress sites getting hacked:
April 2017
• Phishing scammers exploit Wix web
hosting
Criminals flock to free web services to
establish their attack infrastructure.
The latest example: A group using free
website host Wix for its phishing
pages
http://www.infoworld.com/article/31
87346/security/phishing-scammers-
exploit-wix-web-hosting.html
The BIG 8 Mistakes that “WILL” Co$t YOU
• Mistake #1: Shoddy Hosting **
• Mistake #2: Failing to Keep Up to Date ***
• Mistake #3: Using Insecure Login Information
• Mistake #4: Installing Themes and Plugins from Untrustworthy
Sources
• Mistake #5: Hoarding Unused Plugins, Themes, and User Accounts
• Mistake #6: Failing to Back Up Regularly
• Mistake #7: Not Using WordPress-internal Security Measures
• Mistake #8: Not Using a Security Plugin *
Mistake #1: Shoddy Hosting
Unmasked: What 10 million passwords reveal about the people who
choose them
DISCLAIMER: WPEngine Affiliate Link:
Mistake #2: Failing to Keep Up to Date
Security updates and supports installing major releases, plugins, themes, or even
regular SVN checkouts!
• Automatic background updates were introduced in WordPress 3.7 in an effort to
promote better security, and to streamline the update experience overall. By
default, only minor releases – such as for maintenance and security purposes –
and translation file updates are enabled on most sites. In special cases, plugins
and themes may be updated.
• In WordPress, there are four types of automatic background updates:
• Core updates
• Plugin updates
• Theme updates
• Translation file updates
Mistake #3: Using Insecure Login Information
https://www.entrepreneur.com/article/296269
Mistake #4: Installing Themes and Plugins from
Untrustworthy Sources
• Only Install Themes, Plugins and Scripts From Their
Official Source
• Using any software from a “FREE” Pirate site is NEVER
a good idea!
• Many of these “Free Download” pirated themes have
maliciously tweaked scripts that install a back door
which allows your site to be remotely controlled by
hackers.
Mistake #5: Hoarding Unused Plugins, Themes, and User
Accounts
Inactive Plugins: Use em or loose em
http://www.wpbeginner.com/beginners-guide/will-inactive-plugins-slow-down-wordpress-
should-you-delete-inactive-plugins/
Mistake #6: Failing to Back Up Regularly
Mistake #7: Not Using WordPress-internal Security
Measures
Mistake #8: Not Using a Security Plugin *
References
Steps to help secure your WordPress website
 Strengthen your password
 Use email in place of a username (Don't use yahoo, aol gmail ets if you can avoid)
 Introduce two-factor authentication
 Backup your WordPress site regularly
 Secure wp-config.php file
Firewall Plugins (Security)
http://www.wpbeginner.com/plugins/best-wordpress-firewall-plugins-compared/
References
Use 2 Factor Authentication for WP Sites
https://torquemag.io/2016/04/5-two-factor-authentication-plugins-wordpress/
NOTE: Clef is no longer available - Launch-key is replacement
https://updraftplus.com/launch-keyy-simple-secure-logins-wave-phone/
https://getkeyy.com/faqs/
https://wordpress.org/plugins/miniorange-2-factor-authentication/#description
https://wordpress.org/plugins/google-authenticator/
Also Consider:
• Google Authenticator or Authy
• Jetpack.com two factor through WordPress.com
Mobile Apps: iPhone /Android:
Google Authenticator App.
Authy 2-Factor Authentication App.
References
Manage your plugins and themes yourself or use a service provider to do this for you.
Look out for Bad Plugins:
Fake SEO plugin backdoors WordPress installation
Utilize a Managed Service Provider to Secure your websites
http://www.wp-servicemanager.com
References
Check out my personal curated WordPress resources.
Flipboard https://flipboard.com
Check out WordPress Toolkit by Tom Townsend
http://flip.it/EzcxyN
Check out CYBER SECURITY FOR ALL by Tom Townsend
http://flip.it/vByNn6
References
New Port Richey and Tampa Bay WordPress Meetup links.
https://www.meetup.com/New-Port-Richey-WordPress/
https://www.meetup.com/Tampa-Bay-WordPress/
https://tampabaywp.org/
https://www.facebook.com/groups/wptpa/
Slack – (Chat for Tampa Bay WordPress and associated Meetups)
tampabaywp.slack.com (This is by invite only so you need to request through the meetup either on Tampa
Bay WordPress or New Port Richey WordPress Meetup. All we need is an email to send you an invite.)
Thank You

Más contenido relacionado

La actualidad más candente

How To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your WordpressHow To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your Wordpress
Chelsea O'Brien
 

La actualidad más candente (20)

WORDPRESS SECURITY: HOW TO AVOID BEING HACKED
WORDPRESS SECURITY: HOW TO AVOID BEING HACKEDWORDPRESS SECURITY: HOW TO AVOID BEING HACKED
WORDPRESS SECURITY: HOW TO AVOID BEING HACKED
 
Really Awesome WordPress Plugins You Should Know About
Really Awesome WordPress Plugins You Should Know AboutReally Awesome WordPress Plugins You Should Know About
Really Awesome WordPress Plugins You Should Know About
 
WordPress Security Presentation
WordPress Security PresentationWordPress Security Presentation
WordPress Security Presentation
 
Sucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! websiteSucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! website
 
Wordpress security best practices - WordCamp Waukesha 2017
Wordpress security best practices - WordCamp Waukesha 2017Wordpress security best practices - WordCamp Waukesha 2017
Wordpress security best practices - WordCamp Waukesha 2017
 
Beefy WordPress Security Wordcamp 2012 by Tammy Lee
Beefy WordPress Security Wordcamp 2012 by Tammy LeeBeefy WordPress Security Wordcamp 2012 by Tammy Lee
Beefy WordPress Security Wordcamp 2012 by Tammy Lee
 
WordPress Security WordCamp OC 2013
WordPress Security WordCamp OC 2013WordPress Security WordCamp OC 2013
WordPress Security WordCamp OC 2013
 
Introduction to WordPress Security
Introduction to WordPress SecurityIntroduction to WordPress Security
Introduction to WordPress Security
 
The Ultimate Guide to Wordpress Security
The Ultimate Guide to Wordpress SecurityThe Ultimate Guide to Wordpress Security
The Ultimate Guide to Wordpress Security
 
How To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your WordpressHow To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your Wordpress
 
Building Secure WordPress Sites
Building Secure WordPress Sites Building Secure WordPress Sites
Building Secure WordPress Sites
 
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYANBEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
 
WordPress Security Presentation from South Florida WordPress Meetup
WordPress Security Presentation from South Florida WordPress MeetupWordPress Security Presentation from South Florida WordPress Meetup
WordPress Security Presentation from South Florida WordPress Meetup
 
Securing Your WordPress Website by Vlad Lasky
Securing Your WordPress Website by Vlad LaskySecuring Your WordPress Website by Vlad Lasky
Securing Your WordPress Website by Vlad Lasky
 
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
 
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITERUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
 
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
 
10 Ways to Secure WordPress
10 Ways to Secure WordPress10 Ways to Secure WordPress
10 Ways to Secure WordPress
 
Security-Web Vulnerabilities-Browser Attacks
Security-Web Vulnerabilities-Browser AttacksSecurity-Web Vulnerabilities-Browser Attacks
Security-Web Vulnerabilities-Browser Attacks
 
WordPress Security
WordPress SecurityWordPress Security
WordPress Security
 

Similar a Securing your WordPress website - New Port Richey WP Meetup

Joomla Security Simplified —  Seven Easy Steps For a More Secure Website
Joomla Security Simplified — Seven Easy Steps For a More Secure WebsiteJoomla Security Simplified — Seven Easy Steps For a More Secure Website
Joomla Security Simplified —  Seven Easy Steps For a More Secure Website
Imperva Incapsula
 

Similar a Securing your WordPress website - New Port Richey WP Meetup (20)

WordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
WordPress Site Management - Keeping Your Creation Happy, Healthy and SecureWordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
WordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
 
WordPress Security Essentials
WordPress Security EssentialsWordPress Security Essentials
WordPress Security Essentials
 
Protect Your WordPress From The Inside Out
Protect Your WordPress From The Inside OutProtect Your WordPress From The Inside Out
Protect Your WordPress From The Inside Out
 
WordPress security
WordPress securityWordPress security
WordPress security
 
Responsible [digital] Home Ownership
Responsible [digital] Home OwnershipResponsible [digital] Home Ownership
Responsible [digital] Home Ownership
 
WordPress Resources Nov 2014
WordPress Resources Nov 2014WordPress Resources Nov 2014
WordPress Resources Nov 2014
 
Joomla Security Simplified —  Seven Easy Steps For a More Secure Website
Joomla Security Simplified — Seven Easy Steps For a More Secure WebsiteJoomla Security Simplified — Seven Easy Steps For a More Secure Website
Joomla Security Simplified —  Seven Easy Steps For a More Secure Website
 
Simple Ways to Secure and Maintain Your WordPress Website
Simple Ways to Secure and Maintain Your WordPress WebsiteSimple Ways to Secure and Maintain Your WordPress Website
Simple Ways to Secure and Maintain Your WordPress Website
 
WordPress Security Best Practices
WordPress Security Best PracticesWordPress Security Best Practices
WordPress Security Best Practices
 
Emergency WordPress Troubleshooting
Emergency WordPress TroubleshootingEmergency WordPress Troubleshooting
Emergency WordPress Troubleshooting
 
The WordPress Hosting Decision: It All Starts Here
The WordPress Hosting Decision: It All Starts HereThe WordPress Hosting Decision: It All Starts Here
The WordPress Hosting Decision: It All Starts Here
 
Steps to Keep Your Site Clean
Steps to Keep Your Site CleanSteps to Keep Your Site Clean
Steps to Keep Your Site Clean
 
A Guide To Secure WordPress Website – A Complete Guide.pdf
A Guide To Secure WordPress Website – A Complete Guide.pdfA Guide To Secure WordPress Website – A Complete Guide.pdf
A Guide To Secure WordPress Website – A Complete Guide.pdf
 
Security, more important than ever!
Security, more important than ever!Security, more important than ever!
Security, more important than ever!
 
Owning word press all you need to know as a wordpress developer by lutaaya ...
Owning word press   all you need to know as a wordpress developer by lutaaya ...Owning word press   all you need to know as a wordpress developer by lutaaya ...
Owning word press all you need to know as a wordpress developer by lutaaya ...
 
WordPress Security Best Practices
WordPress Security Best PracticesWordPress Security Best Practices
WordPress Security Best Practices
 
10 Ways to Speed Up and Secure your WP Site
10 Ways to Speed Up and Secure your WP Site10 Ways to Speed Up and Secure your WP Site
10 Ways to Speed Up and Secure your WP Site
 
Up and Running with WordPress - Site Shack Nashville Web Design
Up and Running with WordPress - Site Shack Nashville Web DesignUp and Running with WordPress - Site Shack Nashville Web Design
Up and Running with WordPress - Site Shack Nashville Web Design
 
WordCamp RI 2015 - Beginner WordPress Workshop
WordCamp RI 2015 - Beginner WordPress Workshop   WordCamp RI 2015 - Beginner WordPress Workshop
WordCamp RI 2015 - Beginner WordPress Workshop
 
WordPress End-User Security
WordPress End-User SecurityWordPress End-User Security
WordPress End-User Security
 

Último

在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
ydyuyu
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
nirzagarg
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
JOHNBEBONYAP1
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
nilamkumrai
 

Último (20)

在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
 
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
APNIC Policy Roundup, presented by Sunny Chendi at the 5th ICANN APAC-TWNIC E...
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
💚😋 Bilaspur Escort Service Call Girls, 9352852248 ₹5000 To 25K With AC💚😋
 
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
 
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdfpdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
pdfcoffee.com_business-ethics-q3m7-pdf-free.pdf
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrStory Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
Story Board.pptxrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrrr
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 

Securing your WordPress website - New Port Richey WP Meetup

  • 1.
  • 2. Presenter: Tom Townsend Tom is a Cloud Technical Manager for a Fortune Global Company and also owns and operates SMBsocial.com a local WordPress Agency. Has been using WordPress since 2007  Co-Organizer of Tampa Bay WordPress Meetup  Co-Organizer – New Port Richey WordPress Meetup  Co-Organizer WordCamp Tampa 2014,2015,2016 Contact: Email: tom@smbsocial.com SMBsocial https://www.linkedin.com/in/thomastownsend/
  • 3. • Welcome to the first 2017 Newport Richey WordPress meetup. • Were 1 of 6 Regional Meetups that make up the Eco System of the Tampa Bay WordPress Network /Community
  • 4.
  • 5. SecuriCyber security is the Hot Topic in 2017 ng your WordPress website• Cyber Attack • Phishing • Malicious Websites • Ransomware: WannaCry, Petya • Malware: GhostHook, PowerPoint Social Engineering Attack, downloader - hyperlink - subtitles in Free Movies (video players like Popcorn Time & VLC)
  • 6. Where does YOUR website fit in? ng your WordPress website• WordPress – Good and bad • What do you need to watch out for and how can you ensure your site is secure. • From Hosting to WordPress Core, Plugins and Themes.
  • 7. A few statistics • According to a survey of hacked WordPress site owners, brute-force attacks were the second most popular known method of hacking, with password theft not too far down the list. These attacks should be a very real concern for WordPress users. • July 03, 2017 - SQL injection vulnerability found in popular WordPress plug in https://www.scmagazineuk.com/sql-injection-vulnerability-found-in- popular-wordppress-plug-in-again/article/672839/ • April 2017 Home Routers Used to Hack WordPress Sites - There's a group of hackers who are hijacking unsecured home routers and using these devices to launch coordinated brute-force attacks on the administration panel of WordPress sites. The purpose of these attacks is for the hackers to guess the password for the admin account and take over the attacked site. https://www.bleepingcomputer.com/news/security/home-routers-used- to-hack-wordpress-sites/
  • 8. It's NOT just WordPress sites getting hacked: • June 2017 • Year-old vulnerability allowed pro-ISIS hackers to hack US Government websites • Affected websites reportedly included (amongst others) the Department of Health for the state of Washington, the Rhode Island Department of Education, the official websites of Ohio Governor John Kasich and his wife, as well as the Ohio Department of Rehabilitation and Corrections. • all of the compromised websites were running the same content management system – DotNetNuke (better known as DNN). • There’s nothing inherently wrong with running DNN to power your website, but what is a very bad idea is not keeping your content management system up-to-date. Because the version of DNN that was being run on the defaced websites was version 7.0, released way back in 2015. The latest edition of DNN is version 9.01. https://hotforsecurity.bitdefender.com/blog/year-old-vulnerability-allowed-pro-isis-hackers-to- hack-us-government-websites-18289.html
  • 9. It's NOT just WordPress sites getting hacked: April 2017 • Phishing scammers exploit Wix web hosting Criminals flock to free web services to establish their attack infrastructure. The latest example: A group using free website host Wix for its phishing pages http://www.infoworld.com/article/31 87346/security/phishing-scammers- exploit-wix-web-hosting.html
  • 10.
  • 11. The BIG 8 Mistakes that “WILL” Co$t YOU • Mistake #1: Shoddy Hosting ** • Mistake #2: Failing to Keep Up to Date *** • Mistake #3: Using Insecure Login Information • Mistake #4: Installing Themes and Plugins from Untrustworthy Sources • Mistake #5: Hoarding Unused Plugins, Themes, and User Accounts • Mistake #6: Failing to Back Up Regularly • Mistake #7: Not Using WordPress-internal Security Measures • Mistake #8: Not Using a Security Plugin *
  • 12. Mistake #1: Shoddy Hosting Unmasked: What 10 million passwords reveal about the people who choose them DISCLAIMER: WPEngine Affiliate Link:
  • 13. Mistake #2: Failing to Keep Up to Date Security updates and supports installing major releases, plugins, themes, or even regular SVN checkouts! • Automatic background updates were introduced in WordPress 3.7 in an effort to promote better security, and to streamline the update experience overall. By default, only minor releases – such as for maintenance and security purposes – and translation file updates are enabled on most sites. In special cases, plugins and themes may be updated. • In WordPress, there are four types of automatic background updates: • Core updates • Plugin updates • Theme updates • Translation file updates
  • 14. Mistake #3: Using Insecure Login Information https://www.entrepreneur.com/article/296269
  • 15. Mistake #4: Installing Themes and Plugins from Untrustworthy Sources • Only Install Themes, Plugins and Scripts From Their Official Source • Using any software from a “FREE” Pirate site is NEVER a good idea! • Many of these “Free Download” pirated themes have maliciously tweaked scripts that install a back door which allows your site to be remotely controlled by hackers.
  • 16. Mistake #5: Hoarding Unused Plugins, Themes, and User Accounts Inactive Plugins: Use em or loose em http://www.wpbeginner.com/beginners-guide/will-inactive-plugins-slow-down-wordpress- should-you-delete-inactive-plugins/
  • 17. Mistake #6: Failing to Back Up Regularly
  • 18. Mistake #7: Not Using WordPress-internal Security Measures
  • 19. Mistake #8: Not Using a Security Plugin *
  • 20. References Steps to help secure your WordPress website  Strengthen your password  Use email in place of a username (Don't use yahoo, aol gmail ets if you can avoid)  Introduce two-factor authentication  Backup your WordPress site regularly  Secure wp-config.php file Firewall Plugins (Security) http://www.wpbeginner.com/plugins/best-wordpress-firewall-plugins-compared/
  • 21. References Use 2 Factor Authentication for WP Sites https://torquemag.io/2016/04/5-two-factor-authentication-plugins-wordpress/ NOTE: Clef is no longer available - Launch-key is replacement https://updraftplus.com/launch-keyy-simple-secure-logins-wave-phone/ https://getkeyy.com/faqs/ https://wordpress.org/plugins/miniorange-2-factor-authentication/#description https://wordpress.org/plugins/google-authenticator/ Also Consider: • Google Authenticator or Authy • Jetpack.com two factor through WordPress.com Mobile Apps: iPhone /Android: Google Authenticator App. Authy 2-Factor Authentication App.
  • 22. References Manage your plugins and themes yourself or use a service provider to do this for you. Look out for Bad Plugins: Fake SEO plugin backdoors WordPress installation Utilize a Managed Service Provider to Secure your websites http://www.wp-servicemanager.com
  • 23. References Check out my personal curated WordPress resources. Flipboard https://flipboard.com Check out WordPress Toolkit by Tom Townsend http://flip.it/EzcxyN Check out CYBER SECURITY FOR ALL by Tom Townsend http://flip.it/vByNn6
  • 24. References New Port Richey and Tampa Bay WordPress Meetup links. https://www.meetup.com/New-Port-Richey-WordPress/ https://www.meetup.com/Tampa-Bay-WordPress/ https://tampabaywp.org/ https://www.facebook.com/groups/wptpa/ Slack – (Chat for Tampa Bay WordPress and associated Meetups) tampabaywp.slack.com (This is by invite only so you need to request through the meetup either on Tampa Bay WordPress or New Port Richey WordPress Meetup. All we need is an email to send you an invite.)
  • 25.