File

Posts Tagged 'Security'

Improve the security of your WordPress

In order to eliminate attacks, or at least minimize them, here's a list of the main security plugins for WordPress that will help you combat any type of intrusion.

WP Security Scan

Indispensable! This plugin will track all of your WordPress installation and will suggest measures regarding security vulnerability on your system, such as passwords, security permissions for folders and files, naming tables and other information. It will also hide the version of your WordPress removing the META tags, and no attacker will know where the vulnerabilities according to the version you use.

Secure WordPress

Help protect the WordPress installation, removing several items that can help attackers. It will remove error information from the login page and will also change or remove the version information, but leaves unchanged the administration.

Secure WordPress Suggests remove any unwanted information to anyone who is not an administrator, for security reasons, such as information about plugins, themes and update critical data. This plugin will also add a blank index.html in the folder plugins, so if someone tries to access this page you will see an empty page.

WordPress Database Backup

This plugin should be installed immediately after the complete installation of wordpress. It will help you make constant backups of your database and other content of your choice. You can choose to receive email backup, FTP in or download it to your computer. In case of accident or guilt or trespass, you can restore your blog easily. It is recommended to version 2.03 or higher.

Force SSL

Having a secure connection to communicate with your users is really beneficial. To enable this, I know the SSL site must first be activated. To implement it, you need to buy an SSL certificate. By installing this plugin, the user is forced to access your blog through an SSL connection. This eliminates any third-party attack since all data is encrypted.

Chap Secure Login

If you do not have a secure connection with SSL to protect your password, then you can use this plugin for encrypting passwords. He will use the protocol Chap to hide the passwords and send them encrypted. The only information that is not your server is encrypted. Protect your password and full security will not allow an attacker complete control over your blog.

Anonymous WordPress Plugin

From version 2.3 all versions of WordPress has a feature for automatic updates of plugins. During this process some information is sent as: URL of your blog, plugin list, version of WordPress and plugins enabled.

This type of information can be used by bad guys, so to avoid this situation created the WordPress plugin Anonymous. This plugin is compatible with WordPress 2.3 or higher.

Encrypt Login

This plugin will help encrypt login information using a combination of DES and RSA. It uses JavaScript coding and attaching the user password and generates a DES key. And using this key, the user can have a secure login every time you log in to access the dashboard of your blog.

Admin SSL

This plugin force a secure connection on each page where the password may or must be entered. It is very useful to protect the administration and all pages of your WordPress. This plugin works for version 2.2 to version 2.7 of WordPress.

AskApache Password Protect

It will block the bots and create a protection for any vulnerability that may exist on your WordPress. This plugin protects your password, wp-includes directories like wp-content and others. It's like using a firewall on your blog.

How to prevent your site seje Hacked

Comments off 26, November, 2009 Comments off

In this article we will teach you how to prevent your site seje hacked.

Today one of the most common attacks and frequent is the theft of passwords for FTP by "hacker" where with the password in your possession, you have access to your FTP site where you can download all the HTML and PHP, to insert an HTML with a hidden iframe to a site with a virus, causing those who access your website download (mostly unknowingly) a virus on your computer.

To avoid this type of attack, you should keep your anti-virus enabled and with always updated virus definitions, so that Quaker virus / keylogger indentificado be removed and your computer, thus preventing the theft of passwords.

Once infected, your password will be sent to the "hacker" in this case the step to follow is to contact our support for the immediate change of your password and then take your computer to a repair facility to remove the virus. If your files have already been modified, you can ask our support to restore the last backup available (dirário generated at 1 am).

And do not forget, change your password regularly, it helps to maintain the security of your site. Always use strong passwords with special characters and different passwords you use other services like gmail, hotmail, and others.

Tags: , Categories: Security Tags: ,