SlideShare ist ein Scribd-Unternehmen logo
1 von 47
Downloaden Sie, um offline zu lesen
INTROTO
SECURITY
(BEGINNERS EDITION)
Michele Butcher
CantSpeakGeek.com WPSecurityLock.com
@Michele_Butcher
Slides can be found at http://mlb.pw/wcstl2015
MICHELE BUTCHER
• WordPress Specialist, Site
Cleaner, andTrainer for 

WP Security Lock
• WordPress Specialist for
Megabytes Inc
• One Woman Wonder at 

Can’t Speak Geek
@michele_butcher
WHY IS SECURITY
IMPORTANT?
@michele_butcher
EVERY DAY HACKERSTRYTO
FIND WAYSTO GETYOUR
INFORMATION.
@michele_butcher
WHY DO HACKERS HACK?
• Make bank
• Build a zombie site army
• Share their nasty malware with the world
• Get your information
• They are bored
• They want to see if they can do it
@michele_butcher
WHY ARETHESE PEOPLE
ATTACKING ME?
Anymore, it is not people but bots attacking your site. Hackers have programs that do the work for them.
Rarely is it people doing the hacking unless it is targeted. Strong opinion sites are a good example.
@michele_butcher
HOW DOTHEY GET IN?
• Guess your login. If you know it so can someone else. (Brute
force attack or man in the middle)
• Denial of Service attack (DDoS) flood your site with more
traffic than it can handle
• Through a theme, file or plugin
• Through your FTP or CPanel. (Files set to read, write,execute.
Brute force, anonymous login, shared hosting infection)
@michele_butcher
AND NOW FORTHE ONLY
THING SCARYTHAT I AM
GOINGTO SAY.
@michele_butcher
YOU ARE NEVER
100% SECURE
@michele_butcher
EVEN ATEST SITE OR A
KNITTING SITE WITH ONLY 2
VISITORS CAN BE HACKED. IT
CAN HAPPENTOYOUR SITE.
@michele_butcher
It has happened to me, it can happen to you.
DON’T LET
SECURITY MAKE
YOU LIKETHIS GUY.
@michele_butcher
NEVER FEAR…
THERE ARE WAYSTO KEEPTHE
HACKER ATTACKERS OUT!
@michele_butcher
I promise it is not all that painful!
WORDPRESS SECURITY
BASICS
@michele_butcher
NEVER EVER EVER USE ADMIN AS
USER NAME OR PASSWORD AS
PASSWORD.
NEVER!
@michele_butcher
Got it?
ALWAYS CHANGEYOUR PREFIX NAME
FROM WP_ LET IT BE ANYTHING
OTHERTHAN WP_
FDHSFJKHS_ IS ALWAYS GOOD
I typically do not even look at what I am typing anymore
when I make the WP prefix.The random the better.
@michele_butcher
WHAT TO DO WHEN
YOU HAVETEMPORARY
PEOPLE INYOUR
DASHBOARD
@michele_butcher
ALWAYS USE SFTP
Regular FTP is not secure. Do not use it unless the
server is only set up for FTP.
Only give them access to what they NEED not what
they want.
Just because they want to be an admin does not
automatically make them one.
Guest bloggers should not be anymore than a contributor.
If it is only a temporary login, delete their login when
they have completed their job.
If they have posts on your site, you can knock them down to
subscribers so they can not change anything on your site.
If they are only doing work, delete them when their job is done.
Set up a file change detection
notification to know what they are
changing in your site.
iThemes Security and other security plugins
give you the option to see what all users are
doing when logged into the dashboard.
WHAT ABOUT SECURITY
PLUGINS?
@michele_butcher
ITHEMES SECURITY PRO
Great all encompassing best practices WordPress security
plugin.
Two versions a free and a premium.
http://ithemes.com/security
@michele_butcher
BRUTE PROTECT
If you are mainly worried about DDoS attacks, Brute Protect has you covered.
http://bruteprotect.com
@michele_butcher
WHO CAN SCAN MY SITE
FOR MALWARE?
Google Webmaster Tools http://google.com/webmaster
VirusTotal https://virustotal.com
iThemes Security Pro htttp://ithemes.com/security
@michele_butcher
NEED AN EXTRA EYE ON
YOUR SITE?
CloudFlare has a free and premium version.
http://cloudflare.com
@michele_butcher
THINGSYOU CAN DOTO 

PROTECTYOUR WEBSITE
UPDATE!
UPDATE!
UPDATE!
Update core, update plugins, update themes, update
content, update everything and update often!
The biggest source of nearly all hacks as once
something is patched, it is trivial to get into the old
stuff.
@michele_butcher
IFYOU USETHEMES OR PLUGINS AT ANY OFTHE
ENVATO (THEMEFOREST, CODE CANYON)
ALWAYS CHECKTHE BOXTO BE NOTIFIED OF
UPDATES.THEY WILL NOTTELLYOU OTHERWISE
This is why the RevSlider SoakSoak infection was so widespread.
Many didn't know the plugin was built within the theme.
HAVE A MINIMALIST APPROACH
TO PLUGINS ANDTHEMES.
• Only have the plugins you are using at that time
on your site.You can always upload them again
later.
• Only have your theme you are using on your site.
• If something is not active, delete it.
@michele_butcher
BACK UPYOUR SITE!
SOMEWHERE,ANYWHERE, JUST HAVE A
BACKUP COPY.
BackupBuddy from iThemes is a great choice.
iThemes Security will do a database backup for you.
http://ithemes.com/backupbuddy
@michele_butcher
ALWAYS BACK UPTO SOMEPLACE OTHERTHANYOUR
SERVER. IFTHE SERVER GETS HACKED, SO DOESYOUR
BACKUP.
EVEN BACKING A COPYTO DROPBOX ORYOUR
COMPUTER IS A BETTER OPTION.
@michele_butcher
DON’T LETYOUR SITE GET
LONELY.
Lonely sites can turn into zombie sites and nobody
wants a zombie
@michele_butcher
IFYOUR WEBSITE GET HACKED IT IS
NOTTHE END OFTHE WORLD.
IT CAN AND WILL BE FIXED.
@michele_butcher
WHO CLEANS HACKED
WEBSITES?
Well I do over at WP Security Lock ~Smile~
http://wpsecuritylock.com
I apologize… had to do one shameful plug.
@michele_butcher
WHAT ARE OTHER WAYS I
CAN BE MORE SECURE?
@michele_butcher
ALWAYS USE COMPLEX
PASSWORDS.ALWAYS!
FOR EVERYTHING!
“PASSWORD” IS NEVER A
GOOD PASSWORD!
@michele_butcher
NEVER EMAIL PASSWORDSTO
ANYONE. INCLUDING
YOURSELF.
@michele_butcher
USE A DIFFERENT PASSWORD
FOR EACH AND EVERYTHING
YOU LOG INTO.
USE SOMETHING LIKE
LASTPASS OR ONE
PASSWORDTO SAVEYOUR
PASSWORDS ANDTO
SHARE PASSWORDS WITH
OTHERS.
IFTHE LOGIN HAS A
TWO-FACTOR
AUTHENTICATION,
USE IT!
@michele_butcher
ANTI-VIRUS
PROTECTYOUR UNIT!
Yes I even have an anti-virus on my Mac!
AVG and Avast have free versions as well as paid.
Kaspersky is great with Windows and Macs.
@michele_butcher
BE CONSCIOUS
WHEN USING
PUBLIC WIFI.
@michele_butcher
USE AVPN WHEN CONNECTING
OUT INTHE WILD.
torguard.com
@michele_butcher
UPDATE!
UPDATE!
UPDATE!
Let me say this again
BACK UP EVERYTHING AND
BACK IT UP OFTEN.
IFYOU FEARYOU MIGHT LOSE
INFORMATION, SAVE IT IN MORETHAN
ONE SPOT. BITCASA, CARBONITE,AND
EXTERNAL HARD DRIVES ARE GREAT
OPTIONS OF BACKING UP DATA.
@michele_butcher
QUESTIONS?
@michele_butcher
THANKYOU FOR ATTENDING!
Slides can be found at http://mlb.pw/wcstl2015
Michele Butcher
@michele_butcher
http://wpsecuritylock.com
http://cantspeakgeek.com

Weitere ähnliche Inhalte

Was ist angesagt?

Sucuri Webinar: Oh No! My Website Has Been Hacked.
Sucuri Webinar: Oh No! My Website Has Been Hacked.Sucuri Webinar: Oh No! My Website Has Been Hacked.
Sucuri Webinar: Oh No! My Website Has Been Hacked.Sucuri
 
Tips And Zips Part 1
Tips And Zips Part 1Tips And Zips Part 1
Tips And Zips Part 1ql.things
 
WordPress media library - Going Outside the Instructionsmedia library
WordPress media library - Going Outside the Instructionsmedia libraryWordPress media library - Going Outside the Instructionsmedia library
WordPress media library - Going Outside the Instructionsmedia libraryEasily Amused, Inc. & The WP Valet
 
The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...
The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...
The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...Swiss Data Forum Swiss Data Forum
 
Sucuri Webinar: How to Optimize Your Website for Best Performance
Sucuri Webinar: How to Optimize Your Website for Best PerformanceSucuri Webinar: How to Optimize Your Website for Best Performance
Sucuri Webinar: How to Optimize Your Website for Best PerformanceSucuri
 
Your Site vs. The World (WordCamp LA 2014)
Your Site vs. The World (WordCamp LA 2014)Your Site vs. The World (WordCamp LA 2014)
Your Site vs. The World (WordCamp LA 2014)Jason Cosper
 
Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...
Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...
Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...justcess
 
Pubcon Las Vegas 2016 - Penguin 4.0
Pubcon Las Vegas 2016 - Penguin 4.0Pubcon Las Vegas 2016 - Penguin 4.0
Pubcon Las Vegas 2016 - Penguin 4.0paul_macnamara
 
That's crazy! how to build single page web apps
That's crazy! how to build single page web appsThat's crazy! how to build single page web apps
That's crazy! how to build single page web appsChris Love
 
Develop and Deploy your Mobile API with Rails, Nginx, Unicorn and Capistrano
Develop and Deploy your Mobile API with Rails, Nginx, Unicorn and CapistranoDevelop and Deploy your Mobile API with Rails, Nginx, Unicorn and Capistrano
Develop and Deploy your Mobile API with Rails, Nginx, Unicorn and CapistranoErrazudin Ishak
 
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website SpeedSucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website SpeedSucuri
 
10 things Not To Do With WordPress
10 things Not To Do With WordPress10 things Not To Do With WordPress
10 things Not To Do With WordPressRicky Blacker
 
Sucuri Webinar: Hacked Website Trend Report Q1/2016
Sucuri Webinar: Hacked Website Trend Report Q1/2016Sucuri Webinar: Hacked Website Trend Report Q1/2016
Sucuri Webinar: Hacked Website Trend Report Q1/2016Sucuri
 
5 Quick JavaScript Performance Improvement Tips
5 Quick JavaScript Performance Improvement Tips5 Quick JavaScript Performance Improvement Tips
5 Quick JavaScript Performance Improvement TipsTroy Miles
 
Flutter For Web: An Intro
Flutter For Web: An IntroFlutter For Web: An Intro
Flutter For Web: An IntroFahad Murtaza
 
The ES6 Conundrum - All Things Open 2015
The ES6 Conundrum - All Things Open 2015The ES6 Conundrum - All Things Open 2015
The ES6 Conundrum - All Things Open 2015Christian Heilmann
 
Progressive Web Apps - Techdays Finland
Progressive Web Apps - Techdays FinlandProgressive Web Apps - Techdays Finland
Progressive Web Apps - Techdays FinlandChristian Heilmann
 

Was ist angesagt? (20)

Sucuri Webinar: Oh No! My Website Has Been Hacked.
Sucuri Webinar: Oh No! My Website Has Been Hacked.Sucuri Webinar: Oh No! My Website Has Been Hacked.
Sucuri Webinar: Oh No! My Website Has Been Hacked.
 
Tips And Zips Part 1
Tips And Zips Part 1Tips And Zips Part 1
Tips And Zips Part 1
 
WordPress media library - Going Outside the Instructionsmedia library
WordPress media library - Going Outside the Instructionsmedia libraryWordPress media library - Going Outside the Instructionsmedia library
WordPress media library - Going Outside the Instructionsmedia library
 
The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...
The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...
The Power of Mobile & Cloud: Building a Homesecurity-System with Microsoft Az...
 
Sucuri Webinar: How to Optimize Your Website for Best Performance
Sucuri Webinar: How to Optimize Your Website for Best PerformanceSucuri Webinar: How to Optimize Your Website for Best Performance
Sucuri Webinar: How to Optimize Your Website for Best Performance
 
Your Site vs. The World (WordCamp LA 2014)
Your Site vs. The World (WordCamp LA 2014)Your Site vs. The World (WordCamp LA 2014)
Your Site vs. The World (WordCamp LA 2014)
 
Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...
Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...
Alicia Lyttle & Lorette Lyttle of Monetized Marketing - WordPress Wednesdays ...
 
Pubcon Las Vegas 2016 - Penguin 4.0
Pubcon Las Vegas 2016 - Penguin 4.0Pubcon Las Vegas 2016 - Penguin 4.0
Pubcon Las Vegas 2016 - Penguin 4.0
 
For The Love of Jetpack
For The Love of JetpackFor The Love of Jetpack
For The Love of Jetpack
 
That's crazy! how to build single page web apps
That's crazy! how to build single page web appsThat's crazy! how to build single page web apps
That's crazy! how to build single page web apps
 
Develop and Deploy your Mobile API with Rails, Nginx, Unicorn and Capistrano
Develop and Deploy your Mobile API with Rails, Nginx, Unicorn and CapistranoDevelop and Deploy your Mobile API with Rails, Nginx, Unicorn and Capistrano
Develop and Deploy your Mobile API with Rails, Nginx, Unicorn and Capistrano
 
Twitter Talk
Twitter TalkTwitter Talk
Twitter Talk
 
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website SpeedSucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
 
10 things Not To Do With WordPress
10 things Not To Do With WordPress10 things Not To Do With WordPress
10 things Not To Do With WordPress
 
Sucuri Webinar: Hacked Website Trend Report Q1/2016
Sucuri Webinar: Hacked Website Trend Report Q1/2016Sucuri Webinar: Hacked Website Trend Report Q1/2016
Sucuri Webinar: Hacked Website Trend Report Q1/2016
 
5 Quick JavaScript Performance Improvement Tips
5 Quick JavaScript Performance Improvement Tips5 Quick JavaScript Performance Improvement Tips
5 Quick JavaScript Performance Improvement Tips
 
Flutter For Web: An Intro
Flutter For Web: An IntroFlutter For Web: An Intro
Flutter For Web: An Intro
 
The ES6 Conundrum - All Things Open 2015
The ES6 Conundrum - All Things Open 2015The ES6 Conundrum - All Things Open 2015
The ES6 Conundrum - All Things Open 2015
 
Progressive Web Apps - Techdays Finland
Progressive Web Apps - Techdays FinlandProgressive Web Apps - Techdays Finland
Progressive Web Apps - Techdays Finland
 
My Site Was Hacked!
My Site Was Hacked!My Site Was Hacked!
My Site Was Hacked!
 

Andere mochten auch

WordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das Máquinas
WordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das MáquinasWordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das Máquinas
WordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das MáquinasThiago Dieb
 
Word benchfukuoka
Word benchfukuokaWord benchfukuoka
Word benchfukuokaJunji Manno
 
Cash blog system- Make Money Online With Simple Blogs
Cash blog system- Make Money Online With Simple BlogsCash blog system- Make Money Online With Simple Blogs
Cash blog system- Make Money Online With Simple Blogsadfw ltd
 
Menggunakan Kali Linux Untuk Mengetahui Kelemahan Implementasi TI
Menggunakan Kali Linux Untuk  Mengetahui Kelemahan Implementasi TIMenggunakan Kali Linux Untuk  Mengetahui Kelemahan Implementasi TI
Menggunakan Kali Linux Untuk Mengetahui Kelemahan Implementasi TIIsmail Fahmi
 
WEB ve MOBİL SIZMA TESTLERİ
WEB ve MOBİL SIZMA TESTLERİ WEB ve MOBİL SIZMA TESTLERİ
WEB ve MOBİL SIZMA TESTLERİ BGA Cyber Security
 
23k guestbooks mix
23k guestbooks mix23k guestbooks mix
23k guestbooks mixWaleed Ahmad
 
Web 2016 (13/13) Securitatea aplicațiilor Web
Web 2016 (13/13) Securitatea aplicațiilor WebWeb 2016 (13/13) Securitatea aplicațiilor Web
Web 2016 (13/13) Securitatea aplicațiilor WebSabin Buraga
 

Andere mochten auch (9)

WordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das Máquinas
WordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das MáquinasWordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das Máquinas
WordCamp Belo Horizonte 2015 | Hackers vs WordPress – A Rebelião das Máquinas
 
САМБО для WordPress
САМБО для WordPressСАМБО для WordPress
САМБО для WordPress
 
Word benchfukuoka
Word benchfukuokaWord benchfukuoka
Word benchfukuoka
 
Výkon WordPress
Výkon WordPressVýkon WordPress
Výkon WordPress
 
Cash blog system- Make Money Online With Simple Blogs
Cash blog system- Make Money Online With Simple BlogsCash blog system- Make Money Online With Simple Blogs
Cash blog system- Make Money Online With Simple Blogs
 
Menggunakan Kali Linux Untuk Mengetahui Kelemahan Implementasi TI
Menggunakan Kali Linux Untuk  Mengetahui Kelemahan Implementasi TIMenggunakan Kali Linux Untuk  Mengetahui Kelemahan Implementasi TI
Menggunakan Kali Linux Untuk Mengetahui Kelemahan Implementasi TI
 
WEB ve MOBİL SIZMA TESTLERİ
WEB ve MOBİL SIZMA TESTLERİ WEB ve MOBİL SIZMA TESTLERİ
WEB ve MOBİL SIZMA TESTLERİ
 
23k guestbooks mix
23k guestbooks mix23k guestbooks mix
23k guestbooks mix
 
Web 2016 (13/13) Securitatea aplicațiilor Web
Web 2016 (13/13) Securitatea aplicațiilor WebWeb 2016 (13/13) Securitatea aplicațiilor Web
Web 2016 (13/13) Securitatea aplicațiilor Web
 

Ähnlich wie Intro to Security (Beginner's Edition) WordCamp St. Louis 2015

Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?Michele Butcher-Jones
 
WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012Angela Bowman
 
How to Secure your WordPress Website - WordCamp UK 2014
How to Secure your WordPress Website - WordCamp UK 2014How to Secure your WordPress Website - WordCamp UK 2014
How to Secure your WordPress Website - WordCamp UK 2014Primary Image Ltd
 
Sucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! websiteSucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! websiteSucuri
 
WordCamp Minnepolis 2015: From Zero To WordPress Publish
WordCamp Minnepolis 2015: From Zero To WordPress PublishWordCamp Minnepolis 2015: From Zero To WordPress Publish
WordCamp Minnepolis 2015: From Zero To WordPress PublishMichele Butcher-Jones
 
Word camp pune 2013 security
Word camp pune 2013   securityWord camp pune 2013   security
Word camp pune 2013 securityGaurav Singh
 
I Want These * Bugs Off My * Internet
I Want These * Bugs Off My * InternetI Want These * Bugs Off My * Internet
I Want These * Bugs Off My * InternetDan Kaminsky
 
Bridging the Gap: From WordPress beginner to WordPress Wizard
Bridging the Gap: From WordPress beginner to WordPress WizardBridging the Gap: From WordPress beginner to WordPress Wizard
Bridging the Gap: From WordPress beginner to WordPress WizardMatthew Vaccaro
 
Strategies for securing your banks & enterprises (from someone who robs bank...
 Strategies for securing your banks & enterprises (from someone who robs bank... Strategies for securing your banks & enterprises (from someone who robs bank...
Strategies for securing your banks & enterprises (from someone who robs bank...ITCamp
 
WordPress Security Essentials
WordPress Security EssentialsWordPress Security Essentials
WordPress Security EssentialsAngela Bowman
 
Faster Secure Software Development with Continuous Deployment - PH Days 2013
Faster Secure Software Development with Continuous Deployment - PH Days 2013Faster Secure Software Development with Continuous Deployment - PH Days 2013
Faster Secure Software Development with Continuous Deployment - PH Days 2013Nick Galbreath
 
Dont Break Live lightning talk
Dont Break Live lightning talkDont Break Live lightning talk
Dont Break Live lightning talkJamie Schmid
 
WordCamp Ottawa 2016: Updates
WordCamp Ottawa 2016: UpdatesWordCamp Ottawa 2016: Updates
WordCamp Ottawa 2016: Updatesthe___miked
 
Types of Security Threats WordPress Websites Face: Part-1
Types of Security Threats WordPress Websites Face: Part-1Types of Security Threats WordPress Websites Face: Part-1
Types of Security Threats WordPress Websites Face: Part-1WPWhiteBoard
 

Ähnlich wie Intro to Security (Beginner's Edition) WordCamp St. Louis 2015 (20)

So i have a website now what?
So i have a website now what?So i have a website now what?
So i have a website now what?
 
Keep Your SIte Secure
Keep Your SIte SecureKeep Your SIte Secure
Keep Your SIte Secure
 
Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?Your Site Has Been Hacked, Now What?
Your Site Has Been Hacked, Now What?
 
I Have My WordPress Site Now What?
I Have My WordPress Site Now What?I Have My WordPress Site Now What?
I Have My WordPress Site Now What?
 
From Zero To WordPress
From Zero To WordPressFrom Zero To WordPress
From Zero To WordPress
 
WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012WordPress Security Essentials WordCamp Denver 2012
WordPress Security Essentials WordCamp Denver 2012
 
Zero To WordPress Plubish
Zero To WordPress PlubishZero To WordPress Plubish
Zero To WordPress Plubish
 
How to Secure your WordPress Website - WordCamp UK 2014
How to Secure your WordPress Website - WordCamp UK 2014How to Secure your WordPress Website - WordCamp UK 2014
How to Secure your WordPress Website - WordCamp UK 2014
 
Sucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! websiteSucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! website
 
WordCamp Minnepolis 2015: From Zero To WordPress Publish
WordCamp Minnepolis 2015: From Zero To WordPress PublishWordCamp Minnepolis 2015: From Zero To WordPress Publish
WordCamp Minnepolis 2015: From Zero To WordPress Publish
 
Word camp pune 2013 security
Word camp pune 2013   securityWord camp pune 2013   security
Word camp pune 2013 security
 
I Want These * Bugs Off My * Internet
I Want These * Bugs Off My * InternetI Want These * Bugs Off My * Internet
I Want These * Bugs Off My * Internet
 
Bridging the Gap: From WordPress beginner to WordPress Wizard
Bridging the Gap: From WordPress beginner to WordPress WizardBridging the Gap: From WordPress beginner to WordPress Wizard
Bridging the Gap: From WordPress beginner to WordPress Wizard
 
Strategies for securing your banks & enterprises (from someone who robs bank...
 Strategies for securing your banks & enterprises (from someone who robs bank... Strategies for securing your banks & enterprises (from someone who robs bank...
Strategies for securing your banks & enterprises (from someone who robs bank...
 
WordPress Security Essentials
WordPress Security EssentialsWordPress Security Essentials
WordPress Security Essentials
 
Faster Secure Software Development with Continuous Deployment - PH Days 2013
Faster Secure Software Development with Continuous Deployment - PH Days 2013Faster Secure Software Development with Continuous Deployment - PH Days 2013
Faster Secure Software Development with Continuous Deployment - PH Days 2013
 
Anatomy of a_bum
Anatomy of a_bumAnatomy of a_bum
Anatomy of a_bum
 
Dont Break Live lightning talk
Dont Break Live lightning talkDont Break Live lightning talk
Dont Break Live lightning talk
 
WordCamp Ottawa 2016: Updates
WordCamp Ottawa 2016: UpdatesWordCamp Ottawa 2016: Updates
WordCamp Ottawa 2016: Updates
 
Types of Security Threats WordPress Websites Face: Part-1
Types of Security Threats WordPress Websites Face: Part-1Types of Security Threats WordPress Websites Face: Part-1
Types of Security Threats WordPress Websites Face: Part-1
 

Mehr von Michele Butcher-Jones

Onboarding Clients Does Not have to take a Miracle to get all the things! - W...
Onboarding Clients Does Not have to take a Miracle to get all the things! - W...Onboarding Clients Does Not have to take a Miracle to get all the things! - W...
Onboarding Clients Does Not have to take a Miracle to get all the things! - W...Michele Butcher-Jones
 
You Don't Have to be Crazy to Work Here! A Mental Health Check
You Don't Have to be Crazy to Work Here! A Mental Health CheckYou Don't Have to be Crazy to Work Here! A Mental Health Check
You Don't Have to be Crazy to Work Here! A Mental Health CheckMichele Butcher-Jones
 
WordPress London: Creating a 5 Star Customer Experience
WordPress London: Creating a 5 Star Customer ExperienceWordPress London: Creating a 5 Star Customer Experience
WordPress London: Creating a 5 Star Customer ExperienceMichele Butcher-Jones
 
Demons in the Closet - Handling your mental health while working remotely and...
Demons in the Closet - Handling your mental health while working remotely and...Demons in the Closet - Handling your mental health while working remotely and...
Demons in the Closet - Handling your mental health while working remotely and...Michele Butcher-Jones
 
Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...
Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...
Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...Michele Butcher-Jones
 
What To Do Post-Launch: How To Care For Your Brand New WordPress Site
What To Do Post-Launch: How To Care For Your Brand New WordPress SiteWhat To Do Post-Launch: How To Care For Your Brand New WordPress Site
What To Do Post-Launch: How To Care For Your Brand New WordPress SiteMichele Butcher-Jones
 
WordCamp St Louis 2018 Contributing Without Coding
WordCamp St Louis 2018 Contributing Without CodingWordCamp St Louis 2018 Contributing Without Coding
WordCamp St Louis 2018 Contributing Without CodingMichele Butcher-Jones
 
Contributing to WordPress without Coding
Contributing to WordPress without CodingContributing to WordPress without Coding
Contributing to WordPress without CodingMichele Butcher-Jones
 
The Five Star Customer Service Experience
The Five Star Customer Service ExperienceThe Five Star Customer Service Experience
The Five Star Customer Service ExperienceMichele Butcher-Jones
 
Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...
Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...
Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...Michele Butcher-Jones
 
Demons in the Closet WordCamp Montreal 2016
Demons in the Closet WordCamp Montreal 2016Demons in the Closet WordCamp Montreal 2016
Demons in the Closet WordCamp Montreal 2016Michele Butcher-Jones
 
WordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALCWordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALCMichele Butcher-Jones
 
Word press for beginners lesson 3 jalc fall 2015
Word press for beginners lesson 3 jalc fall 2015Word press for beginners lesson 3 jalc fall 2015
Word press for beginners lesson 3 jalc fall 2015Michele Butcher-Jones
 

Mehr von Michele Butcher-Jones (20)

Onboarding Clients Does Not have to take a Miracle to get all the things! - W...
Onboarding Clients Does Not have to take a Miracle to get all the things! - W...Onboarding Clients Does Not have to take a Miracle to get all the things! - W...
Onboarding Clients Does Not have to take a Miracle to get all the things! - W...
 
The Importance of Maintenance
The Importance of MaintenanceThe Importance of Maintenance
The Importance of Maintenance
 
Elevating Customer Experiences
Elevating Customer ExperiencesElevating Customer Experiences
Elevating Customer Experiences
 
You Don't Have to be Crazy to Work Here! A Mental Health Check
You Don't Have to be Crazy to Work Here! A Mental Health CheckYou Don't Have to be Crazy to Work Here! A Mental Health Check
You Don't Have to be Crazy to Work Here! A Mental Health Check
 
WordPress London: Creating a 5 Star Customer Experience
WordPress London: Creating a 5 Star Customer ExperienceWordPress London: Creating a 5 Star Customer Experience
WordPress London: Creating a 5 Star Customer Experience
 
Demons in the Closet - Handling your mental health while working remotely and...
Demons in the Closet - Handling your mental health while working remotely and...Demons in the Closet - Handling your mental health while working remotely and...
Demons in the Closet - Handling your mental health while working remotely and...
 
Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...
Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...
Successful Teams are Created when Everyone Leads - Shift-Enter Charlottesvill...
 
What To Do Post-Launch: How To Care For Your Brand New WordPress Site
What To Do Post-Launch: How To Care For Your Brand New WordPress SiteWhat To Do Post-Launch: How To Care For Your Brand New WordPress Site
What To Do Post-Launch: How To Care For Your Brand New WordPress Site
 
The Five Star Customer Experience
The Five Star Customer ExperienceThe Five Star Customer Experience
The Five Star Customer Experience
 
Taming the Demons in the Closet
Taming the Demons in the ClosetTaming the Demons in the Closet
Taming the Demons in the Closet
 
My website is live now what?
My website is live now what?My website is live now what?
My website is live now what?
 
WordCamp St Louis 2018 Contributing Without Coding
WordCamp St Louis 2018 Contributing Without CodingWordCamp St Louis 2018 Contributing Without Coding
WordCamp St Louis 2018 Contributing Without Coding
 
Contributing to WordPress without Coding
Contributing to WordPress without CodingContributing to WordPress without Coding
Contributing to WordPress without Coding
 
The Five Star Customer Service Experience
The Five Star Customer Service ExperienceThe Five Star Customer Service Experience
The Five Star Customer Service Experience
 
Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...
Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...
Demons In The Closet - A look at Mental Health with Remote Wokers WordCamp St...
 
Demons in the Closet WordCamp Montreal 2016
Demons in the Closet WordCamp Montreal 2016Demons in the Closet WordCamp Montreal 2016
Demons in the Closet WordCamp Montreal 2016
 
Jetpack All The Things
Jetpack All The ThingsJetpack All The Things
Jetpack All The Things
 
WordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALCWordPress for beginners lesson 4 fall2015 JALC
WordPress for beginners lesson 4 fall2015 JALC
 
Word press for beginners lesson 3 jalc fall 2015
Word press for beginners lesson 3 jalc fall 2015Word press for beginners lesson 3 jalc fall 2015
Word press for beginners lesson 3 jalc fall 2015
 
Beginners WordPress JALC Lesson 2
Beginners WordPress JALC Lesson 2Beginners WordPress JALC Lesson 2
Beginners WordPress JALC Lesson 2
 

Kürzlich hochgeladen

Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITMgdsc13
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012rehmti665
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书rnrncn29
 
Intellectual property rightsand its types.pptx
Intellectual property rightsand its types.pptxIntellectual property rightsand its types.pptx
Intellectual property rightsand its types.pptxBipin Adhikari
 
Elevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New OrleansElevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New Orleanscorenetworkseo
 
Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Sonam Pathan
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMartaLoveguard
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一Fs
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Sonam Pathan
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一z xss
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predieusebiomeyer
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Excelmac1
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书rnrncn29
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationLinaWolf1
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一Fs
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhimiss dipika
 
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一Fs
 

Kürzlich hochgeladen (20)

Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in  Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Jamuna Vihar Delhi reach out to us at 🔝9953056974🔝
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITM
 
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
 
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
Call Girls South Delhi Delhi reach out to us at ☎ 9711199012
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
 
Intellectual property rightsand its types.pptx
Intellectual property rightsand its types.pptxIntellectual property rightsand its types.pptx
Intellectual property rightsand its types.pptx
 
Elevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New OrleansElevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New Orleans
 
Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170
 
Magic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptxMagic exist by Marta Loveguard - presentation.pptx
Magic exist by Marta Loveguard - presentation.pptx
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
 
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
Call Girls In The Ocean Pearl Retreat Hotel New Delhi 9873777170
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predi
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
 
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Serviceyoung call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
 
PHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 DocumentationPHP-based rendering of TYPO3 Documentation
PHP-based rendering of TYPO3 Documentation
 
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhi
 
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
定制(UAL学位证)英国伦敦艺术大学毕业证成绩单原版一比一
 

Intro to Security (Beginner's Edition) WordCamp St. Louis 2015

  • 1. INTROTO SECURITY (BEGINNERS EDITION) Michele Butcher CantSpeakGeek.com WPSecurityLock.com @Michele_Butcher Slides can be found at http://mlb.pw/wcstl2015
  • 2. MICHELE BUTCHER • WordPress Specialist, Site Cleaner, andTrainer for 
 WP Security Lock • WordPress Specialist for Megabytes Inc • One Woman Wonder at 
 Can’t Speak Geek @michele_butcher
  • 4. EVERY DAY HACKERSTRYTO FIND WAYSTO GETYOUR INFORMATION. @michele_butcher
  • 5. WHY DO HACKERS HACK? • Make bank • Build a zombie site army • Share their nasty malware with the world • Get your information • They are bored • They want to see if they can do it @michele_butcher
  • 6. WHY ARETHESE PEOPLE ATTACKING ME? Anymore, it is not people but bots attacking your site. Hackers have programs that do the work for them. Rarely is it people doing the hacking unless it is targeted. Strong opinion sites are a good example. @michele_butcher
  • 7. HOW DOTHEY GET IN? • Guess your login. If you know it so can someone else. (Brute force attack or man in the middle) • Denial of Service attack (DDoS) flood your site with more traffic than it can handle • Through a theme, file or plugin • Through your FTP or CPanel. (Files set to read, write,execute. Brute force, anonymous login, shared hosting infection) @michele_butcher
  • 8. AND NOW FORTHE ONLY THING SCARYTHAT I AM GOINGTO SAY. @michele_butcher
  • 9. YOU ARE NEVER 100% SECURE @michele_butcher
  • 10. EVEN ATEST SITE OR A KNITTING SITE WITH ONLY 2 VISITORS CAN BE HACKED. IT CAN HAPPENTOYOUR SITE. @michele_butcher It has happened to me, it can happen to you.
  • 11. DON’T LET SECURITY MAKE YOU LIKETHIS GUY. @michele_butcher
  • 12. NEVER FEAR… THERE ARE WAYSTO KEEPTHE HACKER ATTACKERS OUT! @michele_butcher I promise it is not all that painful!
  • 14. NEVER EVER EVER USE ADMIN AS USER NAME OR PASSWORD AS PASSWORD. NEVER! @michele_butcher Got it?
  • 15. ALWAYS CHANGEYOUR PREFIX NAME FROM WP_ LET IT BE ANYTHING OTHERTHAN WP_ FDHSFJKHS_ IS ALWAYS GOOD I typically do not even look at what I am typing anymore when I make the WP prefix.The random the better. @michele_butcher
  • 16. WHAT TO DO WHEN YOU HAVETEMPORARY PEOPLE INYOUR DASHBOARD @michele_butcher
  • 17. ALWAYS USE SFTP Regular FTP is not secure. Do not use it unless the server is only set up for FTP.
  • 18. Only give them access to what they NEED not what they want. Just because they want to be an admin does not automatically make them one. Guest bloggers should not be anymore than a contributor.
  • 19. If it is only a temporary login, delete their login when they have completed their job. If they have posts on your site, you can knock them down to subscribers so they can not change anything on your site. If they are only doing work, delete them when their job is done.
  • 20. Set up a file change detection notification to know what they are changing in your site. iThemes Security and other security plugins give you the option to see what all users are doing when logged into the dashboard.
  • 22. ITHEMES SECURITY PRO Great all encompassing best practices WordPress security plugin. Two versions a free and a premium. http://ithemes.com/security @michele_butcher
  • 23. BRUTE PROTECT If you are mainly worried about DDoS attacks, Brute Protect has you covered. http://bruteprotect.com @michele_butcher
  • 24. WHO CAN SCAN MY SITE FOR MALWARE? Google Webmaster Tools http://google.com/webmaster VirusTotal https://virustotal.com iThemes Security Pro htttp://ithemes.com/security @michele_butcher
  • 25. NEED AN EXTRA EYE ON YOUR SITE? CloudFlare has a free and premium version. http://cloudflare.com @michele_butcher
  • 26. THINGSYOU CAN DOTO 
 PROTECTYOUR WEBSITE
  • 27. UPDATE! UPDATE! UPDATE! Update core, update plugins, update themes, update content, update everything and update often! The biggest source of nearly all hacks as once something is patched, it is trivial to get into the old stuff. @michele_butcher
  • 28. IFYOU USETHEMES OR PLUGINS AT ANY OFTHE ENVATO (THEMEFOREST, CODE CANYON) ALWAYS CHECKTHE BOXTO BE NOTIFIED OF UPDATES.THEY WILL NOTTELLYOU OTHERWISE This is why the RevSlider SoakSoak infection was so widespread. Many didn't know the plugin was built within the theme.
  • 29. HAVE A MINIMALIST APPROACH TO PLUGINS ANDTHEMES. • Only have the plugins you are using at that time on your site.You can always upload them again later. • Only have your theme you are using on your site. • If something is not active, delete it. @michele_butcher
  • 30. BACK UPYOUR SITE! SOMEWHERE,ANYWHERE, JUST HAVE A BACKUP COPY. BackupBuddy from iThemes is a great choice. iThemes Security will do a database backup for you. http://ithemes.com/backupbuddy @michele_butcher
  • 31. ALWAYS BACK UPTO SOMEPLACE OTHERTHANYOUR SERVER. IFTHE SERVER GETS HACKED, SO DOESYOUR BACKUP. EVEN BACKING A COPYTO DROPBOX ORYOUR COMPUTER IS A BETTER OPTION. @michele_butcher
  • 32. DON’T LETYOUR SITE GET LONELY. Lonely sites can turn into zombie sites and nobody wants a zombie @michele_butcher
  • 33. IFYOUR WEBSITE GET HACKED IT IS NOTTHE END OFTHE WORLD. IT CAN AND WILL BE FIXED. @michele_butcher
  • 34. WHO CLEANS HACKED WEBSITES? Well I do over at WP Security Lock ~Smile~ http://wpsecuritylock.com I apologize… had to do one shameful plug. @michele_butcher
  • 35. WHAT ARE OTHER WAYS I CAN BE MORE SECURE? @michele_butcher
  • 36. ALWAYS USE COMPLEX PASSWORDS.ALWAYS! FOR EVERYTHING! “PASSWORD” IS NEVER A GOOD PASSWORD! @michele_butcher
  • 37. NEVER EMAIL PASSWORDSTO ANYONE. INCLUDING YOURSELF. @michele_butcher
  • 38. USE A DIFFERENT PASSWORD FOR EACH AND EVERYTHING YOU LOG INTO.
  • 39. USE SOMETHING LIKE LASTPASS OR ONE PASSWORDTO SAVEYOUR PASSWORDS ANDTO SHARE PASSWORDS WITH OTHERS.
  • 40. IFTHE LOGIN HAS A TWO-FACTOR AUTHENTICATION, USE IT! @michele_butcher
  • 41. ANTI-VIRUS PROTECTYOUR UNIT! Yes I even have an anti-virus on my Mac! AVG and Avast have free versions as well as paid. Kaspersky is great with Windows and Macs. @michele_butcher
  • 42. BE CONSCIOUS WHEN USING PUBLIC WIFI. @michele_butcher
  • 43. USE AVPN WHEN CONNECTING OUT INTHE WILD. torguard.com @michele_butcher
  • 45. BACK UP EVERYTHING AND BACK IT UP OFTEN. IFYOU FEARYOU MIGHT LOSE INFORMATION, SAVE IT IN MORETHAN ONE SPOT. BITCASA, CARBONITE,AND EXTERNAL HARD DRIVES ARE GREAT OPTIONS OF BACKING UP DATA. @michele_butcher
  • 47. THANKYOU FOR ATTENDING! Slides can be found at http://mlb.pw/wcstl2015 Michele Butcher @michele_butcher http://wpsecuritylock.com http://cantspeakgeek.com