SlideShare ist ein Scribd-Unternehmen logo
1 von 26
Presenter:
Tom Townsend
Tom is a Cloud Technical Manager for a
Fortune Global Company and also owns and
operates SMBsocial.com a local WordPress
Agency.
Has been using WordPress since 2007
 Co-Organizer of Tampa Bay WordPress Meetup
 Co-Organizer – New Port Richey WordPress Meetup
 Co-Organizer WordCamp Tampa 2014,2015,2016
Contact:
Email: tom@smbsocial.com
SMBsocial
https://www.linkedin.com/in/thomastownsend/
• Welcome to the first 2017 Newport Richey WordPress meetup.
• Were 1 of 6 Regional Meetups that make up the Eco System of the
Tampa Bay WordPress Network /Community
SecuriCyber security is the Hot Topic in 2017
ng your WordPress website• Cyber Attack
• Phishing
• Malicious Websites
• Ransomware: WannaCry, Petya
• Malware: GhostHook, PowerPoint
Social Engineering Attack,
downloader - hyperlink - subtitles
in Free Movies (video players like
Popcorn Time & VLC)
Where does YOUR website fit in?
ng your WordPress website• WordPress – Good and bad
• What do you need to watch out for and how can you ensure your site is secure.
• From Hosting to WordPress Core, Plugins and Themes.
A few statistics
• According to a survey of hacked WordPress site owners, brute-force
attacks were the second most popular known method of hacking, with
password theft not too far down the list. These attacks should be a very
real concern for WordPress users.
• July 03, 2017 - SQL injection vulnerability found in popular WordPress
plug in
https://www.scmagazineuk.com/sql-injection-vulnerability-found-in-
popular-wordppress-plug-in-again/article/672839/
• April 2017 Home Routers Used to Hack WordPress Sites -
There's a group of hackers who are hijacking unsecured home routers and
using these devices to launch coordinated brute-force attacks on the
administration panel of WordPress sites. The purpose of these attacks is
for the hackers to guess the password for the admin account and take over
the attacked site.
https://www.bleepingcomputer.com/news/security/home-routers-used-
to-hack-wordpress-sites/
It's NOT just WordPress sites getting hacked:
• June 2017
• Year-old vulnerability allowed pro-ISIS hackers to hack US Government websites
• Affected websites reportedly included (amongst others) the Department of Health for the state of
Washington, the Rhode Island Department of Education, the official websites of Ohio Governor
John Kasich and his wife, as well as the Ohio Department of Rehabilitation and Corrections.
• all of the compromised websites were running the same content management system –
DotNetNuke (better known as DNN).
• There’s nothing inherently wrong with running DNN to power your website, but what is a very
bad idea is not keeping your content management system up-to-date. Because the version of
DNN that was being run on the defaced websites was version 7.0, released way back in 2015. The
latest edition of DNN is version 9.01.
https://hotforsecurity.bitdefender.com/blog/year-old-vulnerability-allowed-pro-isis-hackers-to-
hack-us-government-websites-18289.html
It's NOT just WordPress sites getting hacked:
April 2017
• Phishing scammers exploit Wix web
hosting
Criminals flock to free web services to
establish their attack infrastructure.
The latest example: A group using free
website host Wix for its phishing
pages
http://www.infoworld.com/article/31
87346/security/phishing-scammers-
exploit-wix-web-hosting.html
The BIG 8 Mistakes that “WILL” Co$t YOU
• Mistake #1: Shoddy Hosting **
• Mistake #2: Failing to Keep Up to Date ***
• Mistake #3: Using Insecure Login Information
• Mistake #4: Installing Themes and Plugins from Untrustworthy
Sources
• Mistake #5: Hoarding Unused Plugins, Themes, and User Accounts
• Mistake #6: Failing to Back Up Regularly
• Mistake #7: Not Using WordPress-internal Security Measures
• Mistake #8: Not Using a Security Plugin *
Mistake #1: Shoddy Hosting
Unmasked: What 10 million passwords reveal about the people who
choose them
DISCLAIMER: WPEngine Affiliate Link:
Mistake #2: Failing to Keep Up to Date
Security updates and supports installing major releases, plugins, themes, or even
regular SVN checkouts!
• Automatic background updates were introduced in WordPress 3.7 in an effort to
promote better security, and to streamline the update experience overall. By
default, only minor releases – such as for maintenance and security purposes –
and translation file updates are enabled on most sites. In special cases, plugins
and themes may be updated.
• In WordPress, there are four types of automatic background updates:
• Core updates
• Plugin updates
• Theme updates
• Translation file updates
Mistake #3: Using Insecure Login Information
https://www.entrepreneur.com/article/296269
Mistake #4: Installing Themes and Plugins from
Untrustworthy Sources
• Only Install Themes, Plugins and Scripts From Their
Official Source
• Using any software from a “FREE” Pirate site is NEVER
a good idea!
• Many of these “Free Download” pirated themes have
maliciously tweaked scripts that install a back door
which allows your site to be remotely controlled by
hackers.
Mistake #5: Hoarding Unused Plugins, Themes, and User
Accounts
Inactive Plugins: Use em or loose em
http://www.wpbeginner.com/beginners-guide/will-inactive-plugins-slow-down-wordpress-
should-you-delete-inactive-plugins/
Mistake #6: Failing to Back Up Regularly
Mistake #7: Not Using WordPress-internal Security
Measures
Mistake #8: Not Using a Security Plugin *
References
Steps to help secure your WordPress website
 Strengthen your password
 Use email in place of a username (Don't use yahoo, aol gmail ets if you can avoid)
 Introduce two-factor authentication
 Backup your WordPress site regularly
 Secure wp-config.php file
Firewall Plugins (Security)
http://www.wpbeginner.com/plugins/best-wordpress-firewall-plugins-compared/
References
Use 2 Factor Authentication for WP Sites
https://torquemag.io/2016/04/5-two-factor-authentication-plugins-wordpress/
NOTE: Clef is no longer available - Launch-key is replacement
https://updraftplus.com/launch-keyy-simple-secure-logins-wave-phone/
https://getkeyy.com/faqs/
https://wordpress.org/plugins/miniorange-2-factor-authentication/#description
https://wordpress.org/plugins/google-authenticator/
Also Consider:
• Google Authenticator or Authy
• Jetpack.com two factor through WordPress.com
Mobile Apps: iPhone /Android:
Google Authenticator App.
Authy 2-Factor Authentication App.
References
Manage your plugins and themes yourself or use a service provider to do this for you.
Look out for Bad Plugins:
Fake SEO plugin backdoors WordPress installation
Utilize a Managed Service Provider to Secure your websites
http://www.wp-servicemanager.com
References
Check out my personal curated WordPress resources.
Flipboard https://flipboard.com
Check out WordPress Toolkit by Tom Townsend
http://flip.it/EzcxyN
Check out CYBER SECURITY FOR ALL by Tom Townsend
http://flip.it/vByNn6
References
New Port Richey and Tampa Bay WordPress Meetup links.
https://www.meetup.com/New-Port-Richey-WordPress/
https://www.meetup.com/Tampa-Bay-WordPress/
https://tampabaywp.org/
https://www.facebook.com/groups/wptpa/
Slack – (Chat for Tampa Bay WordPress and associated Meetups)
tampabaywp.slack.com (This is by invite only so you need to request through the meetup either on Tampa
Bay WordPress or New Port Richey WordPress Meetup. All we need is an email to send you an invite.)
Thank You

Weitere ähnliche Inhalte

Was ist angesagt?

WORDPRESS SECURITY: HOW TO AVOID BEING HACKED
WORDPRESS SECURITY: HOW TO AVOID BEING HACKEDWORDPRESS SECURITY: HOW TO AVOID BEING HACKED
WORDPRESS SECURITY: HOW TO AVOID BEING HACKEDStuartJDavidson.com
 
Really Awesome WordPress Plugins You Should Know About
Really Awesome WordPress Plugins You Should Know AboutReally Awesome WordPress Plugins You Should Know About
Really Awesome WordPress Plugins You Should Know AboutAngela Bowman
 
WordPress Security Presentation
WordPress Security PresentationWordPress Security Presentation
WordPress Security PresentationAndrew Paton
 
Sucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! websiteSucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! websiteSucuri
 
Wordpress security best practices - WordCamp Waukesha 2017
Wordpress security best practices - WordCamp Waukesha 2017Wordpress security best practices - WordCamp Waukesha 2017
Wordpress security best practices - WordCamp Waukesha 2017vdrover
 
Beefy WordPress Security Wordcamp 2012 by Tammy Lee
Beefy WordPress Security Wordcamp 2012 by Tammy LeeBeefy WordPress Security Wordcamp 2012 by Tammy Lee
Beefy WordPress Security Wordcamp 2012 by Tammy LeeTop Draw Inc.
 
WordPress Security WordCamp OC 2013
WordPress Security WordCamp OC 2013WordPress Security WordCamp OC 2013
WordPress Security WordCamp OC 2013Brad Williams
 
Introduction to WordPress Security
Introduction to WordPress SecurityIntroduction to WordPress Security
Introduction to WordPress SecurityShawn Hooper
 
The Ultimate Guide to Wordpress Security
The Ultimate Guide to Wordpress SecurityThe Ultimate Guide to Wordpress Security
The Ultimate Guide to Wordpress SecurityAidanChard
 
How To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your WordpressHow To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your WordpressChelsea O'Brien
 
Building Secure WordPress Sites
Building Secure WordPress Sites Building Secure WordPress Sites
Building Secure WordPress Sites Catch Themes
 
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYANBEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYANSamvel Gevorgyan
 
WordPress Security Presentation from South Florida WordPress Meetup
WordPress Security Presentation from South Florida WordPress MeetupWordPress Security Presentation from South Florida WordPress Meetup
WordPress Security Presentation from South Florida WordPress MeetupJohn Carcutt
 
Securing Your WordPress Website by Vlad Lasky
Securing Your WordPress Website by Vlad LaskySecuring Your WordPress Website by Vlad Lasky
Securing Your WordPress Website by Vlad Laskywordcampgc
 
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011Samvel Gevorgyan
 
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITERUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITEAcodez IT Solutions
 
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013Vlad Lasky
 
10 Ways to Secure WordPress
10 Ways to Secure WordPress10 Ways to Secure WordPress
10 Ways to Secure WordPressJeremy Green
 
Security-Web Vulnerabilities-Browser Attacks
Security-Web Vulnerabilities-Browser AttacksSecurity-Web Vulnerabilities-Browser Attacks
Security-Web Vulnerabilities-Browser AttacksRaghu Addanki
 

Was ist angesagt? (20)

WORDPRESS SECURITY: HOW TO AVOID BEING HACKED
WORDPRESS SECURITY: HOW TO AVOID BEING HACKEDWORDPRESS SECURITY: HOW TO AVOID BEING HACKED
WORDPRESS SECURITY: HOW TO AVOID BEING HACKED
 
Really Awesome WordPress Plugins You Should Know About
Really Awesome WordPress Plugins You Should Know AboutReally Awesome WordPress Plugins You Should Know About
Really Awesome WordPress Plugins You Should Know About
 
WordPress Security Presentation
WordPress Security PresentationWordPress Security Presentation
WordPress Security Presentation
 
Sucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! websiteSucuri Webinar: How to identify and clean a hacked Joomla! website
Sucuri Webinar: How to identify and clean a hacked Joomla! website
 
Wordpress security best practices - WordCamp Waukesha 2017
Wordpress security best practices - WordCamp Waukesha 2017Wordpress security best practices - WordCamp Waukesha 2017
Wordpress security best practices - WordCamp Waukesha 2017
 
Beefy WordPress Security Wordcamp 2012 by Tammy Lee
Beefy WordPress Security Wordcamp 2012 by Tammy LeeBeefy WordPress Security Wordcamp 2012 by Tammy Lee
Beefy WordPress Security Wordcamp 2012 by Tammy Lee
 
WordPress Security WordCamp OC 2013
WordPress Security WordCamp OC 2013WordPress Security WordCamp OC 2013
WordPress Security WordCamp OC 2013
 
Introduction to WordPress Security
Introduction to WordPress SecurityIntroduction to WordPress Security
Introduction to WordPress Security
 
The Ultimate Guide to Wordpress Security
The Ultimate Guide to Wordpress SecurityThe Ultimate Guide to Wordpress Security
The Ultimate Guide to Wordpress Security
 
How To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your WordpressHow To Lock Down And Secure Your Wordpress
How To Lock Down And Secure Your Wordpress
 
Building Secure WordPress Sites
Building Secure WordPress Sites Building Secure WordPress Sites
Building Secure WordPress Sites
 
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYANBEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
BEST PRACTICES OF WEB APPLICATION SECURITY By SAMVEL GEVORGYAN
 
WordPress Security Presentation from South Florida WordPress Meetup
WordPress Security Presentation from South Florida WordPress MeetupWordPress Security Presentation from South Florida WordPress Meetup
WordPress Security Presentation from South Florida WordPress Meetup
 
Securing Your WordPress Website by Vlad Lasky
Securing Your WordPress Website by Vlad LaskySecuring Your WordPress Website by Vlad Lasky
Securing Your WordPress Website by Vlad Lasky
 
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
CROSS-SITE REQUEST FORGERY - IN-DEPTH ANALYSIS 2011
 
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITERUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
RUNNING A SECURITY CHECK FOR YOUR WORDPRESS SITE
 
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
Beating Spam On Your WordPress Website - WordCamp Melbourne 2013
 
10 Ways to Secure WordPress
10 Ways to Secure WordPress10 Ways to Secure WordPress
10 Ways to Secure WordPress
 
Security-Web Vulnerabilities-Browser Attacks
Security-Web Vulnerabilities-Browser AttacksSecurity-Web Vulnerabilities-Browser Attacks
Security-Web Vulnerabilities-Browser Attacks
 
WordPress Security
WordPress SecurityWordPress Security
WordPress Security
 

Ähnlich wie Securing your WordPress website - New Port Richey WP Meetup

WordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
WordPress Site Management - Keeping Your Creation Happy, Healthy and SecureWordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
WordPress Site Management - Keeping Your Creation Happy, Healthy and SecureMeagan Hanes
 
WordPress Security Essentials
WordPress Security EssentialsWordPress Security Essentials
WordPress Security EssentialsAngela Bowman
 
Protect Your WordPress From The Inside Out
Protect Your WordPress From The Inside OutProtect Your WordPress From The Inside Out
Protect Your WordPress From The Inside OutSiteGround.com
 
Responsible [digital] Home Ownership
Responsible [digital] Home OwnershipResponsible [digital] Home Ownership
Responsible [digital] Home OwnershipDenise (Dee) Teal
 
WordPress Resources Nov 2014
WordPress Resources Nov 2014WordPress Resources Nov 2014
WordPress Resources Nov 2014Judy Wilson
 
Joomla Security Simplified —  Seven Easy Steps For a More Secure Website
Joomla Security Simplified — Seven Easy Steps For a More Secure WebsiteJoomla Security Simplified — Seven Easy Steps For a More Secure Website
Joomla Security Simplified —  Seven Easy Steps For a More Secure WebsiteImperva Incapsula
 
Simple Ways to Secure and Maintain Your WordPress Website
Simple Ways to Secure and Maintain Your WordPress WebsiteSimple Ways to Secure and Maintain Your WordPress Website
Simple Ways to Secure and Maintain Your WordPress WebsiteRich Plakas
 
Emergency WordPress Troubleshooting
Emergency WordPress TroubleshootingEmergency WordPress Troubleshooting
Emergency WordPress TroubleshootingTiffany Bridge
 
The WordPress Hosting Decision: It All Starts Here
The WordPress Hosting Decision: It All Starts HereThe WordPress Hosting Decision: It All Starts Here
The WordPress Hosting Decision: It All Starts HereBusiness Vitality LLC
 
Steps to Keep Your Site Clean
Steps to Keep Your Site CleanSteps to Keep Your Site Clean
Steps to Keep Your Site CleanSucuri
 
A Guide To Secure WordPress Website – A Complete Guide.pdf
A Guide To Secure WordPress Website – A Complete Guide.pdfA Guide To Secure WordPress Website – A Complete Guide.pdf
A Guide To Secure WordPress Website – A Complete Guide.pdfHost It Smart
 
Security, more important than ever!
Security, more important than ever!Security, more important than ever!
Security, more important than ever!Marko Heijnen
 
Owning word press all you need to know as a wordpress developer by lutaaya ...
Owning word press   all you need to know as a wordpress developer by lutaaya ...Owning word press   all you need to know as a wordpress developer by lutaaya ...
Owning word press all you need to know as a wordpress developer by lutaaya ...Lutaaya Shafiq
 
10 Ways to Speed Up and Secure your WP Site
10 Ways to Speed Up and Secure your WP Site10 Ways to Speed Up and Secure your WP Site
10 Ways to Speed Up and Secure your WP SiteFLBlogCon
 
Up and Running with WordPress - Site Shack Nashville Web Design
Up and Running with WordPress - Site Shack Nashville Web DesignUp and Running with WordPress - Site Shack Nashville Web Design
Up and Running with WordPress - Site Shack Nashville Web DesignJudy Wilson
 
WordCamp RI 2015 - Beginner WordPress Workshop
WordCamp RI 2015 - Beginner WordPress Workshop   WordCamp RI 2015 - Beginner WordPress Workshop
WordCamp RI 2015 - Beginner WordPress Workshop Ella J Designs
 
WordPress End-User Security
WordPress End-User SecurityWordPress End-User Security
WordPress End-User SecurityDre Armeda
 

Ähnlich wie Securing your WordPress website - New Port Richey WP Meetup (20)

WordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
WordPress Site Management - Keeping Your Creation Happy, Healthy and SecureWordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
WordPress Site Management - Keeping Your Creation Happy, Healthy and Secure
 
WordPress Security Essentials
WordPress Security EssentialsWordPress Security Essentials
WordPress Security Essentials
 
Protect Your WordPress From The Inside Out
Protect Your WordPress From The Inside OutProtect Your WordPress From The Inside Out
Protect Your WordPress From The Inside Out
 
WordPress security
WordPress securityWordPress security
WordPress security
 
Responsible [digital] Home Ownership
Responsible [digital] Home OwnershipResponsible [digital] Home Ownership
Responsible [digital] Home Ownership
 
WordPress Resources Nov 2014
WordPress Resources Nov 2014WordPress Resources Nov 2014
WordPress Resources Nov 2014
 
Joomla Security Simplified —  Seven Easy Steps For a More Secure Website
Joomla Security Simplified — Seven Easy Steps For a More Secure WebsiteJoomla Security Simplified — Seven Easy Steps For a More Secure Website
Joomla Security Simplified —  Seven Easy Steps For a More Secure Website
 
Simple Ways to Secure and Maintain Your WordPress Website
Simple Ways to Secure and Maintain Your WordPress WebsiteSimple Ways to Secure and Maintain Your WordPress Website
Simple Ways to Secure and Maintain Your WordPress Website
 
WordPress Security Best Practices
WordPress Security Best PracticesWordPress Security Best Practices
WordPress Security Best Practices
 
Emergency WordPress Troubleshooting
Emergency WordPress TroubleshootingEmergency WordPress Troubleshooting
Emergency WordPress Troubleshooting
 
The WordPress Hosting Decision: It All Starts Here
The WordPress Hosting Decision: It All Starts HereThe WordPress Hosting Decision: It All Starts Here
The WordPress Hosting Decision: It All Starts Here
 
Steps to Keep Your Site Clean
Steps to Keep Your Site CleanSteps to Keep Your Site Clean
Steps to Keep Your Site Clean
 
A Guide To Secure WordPress Website – A Complete Guide.pdf
A Guide To Secure WordPress Website – A Complete Guide.pdfA Guide To Secure WordPress Website – A Complete Guide.pdf
A Guide To Secure WordPress Website – A Complete Guide.pdf
 
Security, more important than ever!
Security, more important than ever!Security, more important than ever!
Security, more important than ever!
 
Owning word press all you need to know as a wordpress developer by lutaaya ...
Owning word press   all you need to know as a wordpress developer by lutaaya ...Owning word press   all you need to know as a wordpress developer by lutaaya ...
Owning word press all you need to know as a wordpress developer by lutaaya ...
 
WordPress Security Best Practices
WordPress Security Best PracticesWordPress Security Best Practices
WordPress Security Best Practices
 
10 Ways to Speed Up and Secure your WP Site
10 Ways to Speed Up and Secure your WP Site10 Ways to Speed Up and Secure your WP Site
10 Ways to Speed Up and Secure your WP Site
 
Up and Running with WordPress - Site Shack Nashville Web Design
Up and Running with WordPress - Site Shack Nashville Web DesignUp and Running with WordPress - Site Shack Nashville Web Design
Up and Running with WordPress - Site Shack Nashville Web Design
 
WordCamp RI 2015 - Beginner WordPress Workshop
WordCamp RI 2015 - Beginner WordPress Workshop   WordCamp RI 2015 - Beginner WordPress Workshop
WordCamp RI 2015 - Beginner WordPress Workshop
 
WordPress End-User Security
WordPress End-User SecurityWordPress End-User Security
WordPress End-User Security
 

Kürzlich hochgeladen

『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书rnrncn29
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书zdzoqco
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predieusebiomeyer
 
Unidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxUnidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxmibuzondetrabajo
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa494f574xmv
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书rnrncn29
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxDyna Gilbert
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
TRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxTRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxAndrieCagasanAkio
 
Company Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxCompany Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxMario
 
ETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxNIMMANAGANTI RAMAKRISHNA
 

Kürzlich hochgeladen (11)

『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
 
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predi
 
Unidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxUnidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptx
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptx
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
TRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxTRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptx
 
Company Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxCompany Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptx
 
ETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptx
 

Securing your WordPress website - New Port Richey WP Meetup

  • 1.
  • 2. Presenter: Tom Townsend Tom is a Cloud Technical Manager for a Fortune Global Company and also owns and operates SMBsocial.com a local WordPress Agency. Has been using WordPress since 2007  Co-Organizer of Tampa Bay WordPress Meetup  Co-Organizer – New Port Richey WordPress Meetup  Co-Organizer WordCamp Tampa 2014,2015,2016 Contact: Email: tom@smbsocial.com SMBsocial https://www.linkedin.com/in/thomastownsend/
  • 3. • Welcome to the first 2017 Newport Richey WordPress meetup. • Were 1 of 6 Regional Meetups that make up the Eco System of the Tampa Bay WordPress Network /Community
  • 4.
  • 5. SecuriCyber security is the Hot Topic in 2017 ng your WordPress website• Cyber Attack • Phishing • Malicious Websites • Ransomware: WannaCry, Petya • Malware: GhostHook, PowerPoint Social Engineering Attack, downloader - hyperlink - subtitles in Free Movies (video players like Popcorn Time & VLC)
  • 6. Where does YOUR website fit in? ng your WordPress website• WordPress – Good and bad • What do you need to watch out for and how can you ensure your site is secure. • From Hosting to WordPress Core, Plugins and Themes.
  • 7. A few statistics • According to a survey of hacked WordPress site owners, brute-force attacks were the second most popular known method of hacking, with password theft not too far down the list. These attacks should be a very real concern for WordPress users. • July 03, 2017 - SQL injection vulnerability found in popular WordPress plug in https://www.scmagazineuk.com/sql-injection-vulnerability-found-in- popular-wordppress-plug-in-again/article/672839/ • April 2017 Home Routers Used to Hack WordPress Sites - There's a group of hackers who are hijacking unsecured home routers and using these devices to launch coordinated brute-force attacks on the administration panel of WordPress sites. The purpose of these attacks is for the hackers to guess the password for the admin account and take over the attacked site. https://www.bleepingcomputer.com/news/security/home-routers-used- to-hack-wordpress-sites/
  • 8. It's NOT just WordPress sites getting hacked: • June 2017 • Year-old vulnerability allowed pro-ISIS hackers to hack US Government websites • Affected websites reportedly included (amongst others) the Department of Health for the state of Washington, the Rhode Island Department of Education, the official websites of Ohio Governor John Kasich and his wife, as well as the Ohio Department of Rehabilitation and Corrections. • all of the compromised websites were running the same content management system – DotNetNuke (better known as DNN). • There’s nothing inherently wrong with running DNN to power your website, but what is a very bad idea is not keeping your content management system up-to-date. Because the version of DNN that was being run on the defaced websites was version 7.0, released way back in 2015. The latest edition of DNN is version 9.01. https://hotforsecurity.bitdefender.com/blog/year-old-vulnerability-allowed-pro-isis-hackers-to- hack-us-government-websites-18289.html
  • 9. It's NOT just WordPress sites getting hacked: April 2017 • Phishing scammers exploit Wix web hosting Criminals flock to free web services to establish their attack infrastructure. The latest example: A group using free website host Wix for its phishing pages http://www.infoworld.com/article/31 87346/security/phishing-scammers- exploit-wix-web-hosting.html
  • 10.
  • 11. The BIG 8 Mistakes that “WILL” Co$t YOU • Mistake #1: Shoddy Hosting ** • Mistake #2: Failing to Keep Up to Date *** • Mistake #3: Using Insecure Login Information • Mistake #4: Installing Themes and Plugins from Untrustworthy Sources • Mistake #5: Hoarding Unused Plugins, Themes, and User Accounts • Mistake #6: Failing to Back Up Regularly • Mistake #7: Not Using WordPress-internal Security Measures • Mistake #8: Not Using a Security Plugin *
  • 12. Mistake #1: Shoddy Hosting Unmasked: What 10 million passwords reveal about the people who choose them DISCLAIMER: WPEngine Affiliate Link:
  • 13. Mistake #2: Failing to Keep Up to Date Security updates and supports installing major releases, plugins, themes, or even regular SVN checkouts! • Automatic background updates were introduced in WordPress 3.7 in an effort to promote better security, and to streamline the update experience overall. By default, only minor releases – such as for maintenance and security purposes – and translation file updates are enabled on most sites. In special cases, plugins and themes may be updated. • In WordPress, there are four types of automatic background updates: • Core updates • Plugin updates • Theme updates • Translation file updates
  • 14. Mistake #3: Using Insecure Login Information https://www.entrepreneur.com/article/296269
  • 15. Mistake #4: Installing Themes and Plugins from Untrustworthy Sources • Only Install Themes, Plugins and Scripts From Their Official Source • Using any software from a “FREE” Pirate site is NEVER a good idea! • Many of these “Free Download” pirated themes have maliciously tweaked scripts that install a back door which allows your site to be remotely controlled by hackers.
  • 16. Mistake #5: Hoarding Unused Plugins, Themes, and User Accounts Inactive Plugins: Use em or loose em http://www.wpbeginner.com/beginners-guide/will-inactive-plugins-slow-down-wordpress- should-you-delete-inactive-plugins/
  • 17. Mistake #6: Failing to Back Up Regularly
  • 18. Mistake #7: Not Using WordPress-internal Security Measures
  • 19. Mistake #8: Not Using a Security Plugin *
  • 20. References Steps to help secure your WordPress website  Strengthen your password  Use email in place of a username (Don't use yahoo, aol gmail ets if you can avoid)  Introduce two-factor authentication  Backup your WordPress site regularly  Secure wp-config.php file Firewall Plugins (Security) http://www.wpbeginner.com/plugins/best-wordpress-firewall-plugins-compared/
  • 21. References Use 2 Factor Authentication for WP Sites https://torquemag.io/2016/04/5-two-factor-authentication-plugins-wordpress/ NOTE: Clef is no longer available - Launch-key is replacement https://updraftplus.com/launch-keyy-simple-secure-logins-wave-phone/ https://getkeyy.com/faqs/ https://wordpress.org/plugins/miniorange-2-factor-authentication/#description https://wordpress.org/plugins/google-authenticator/ Also Consider: • Google Authenticator or Authy • Jetpack.com two factor through WordPress.com Mobile Apps: iPhone /Android: Google Authenticator App. Authy 2-Factor Authentication App.
  • 22. References Manage your plugins and themes yourself or use a service provider to do this for you. Look out for Bad Plugins: Fake SEO plugin backdoors WordPress installation Utilize a Managed Service Provider to Secure your websites http://www.wp-servicemanager.com
  • 23. References Check out my personal curated WordPress resources. Flipboard https://flipboard.com Check out WordPress Toolkit by Tom Townsend http://flip.it/EzcxyN Check out CYBER SECURITY FOR ALL by Tom Townsend http://flip.it/vByNn6
  • 24. References New Port Richey and Tampa Bay WordPress Meetup links. https://www.meetup.com/New-Port-Richey-WordPress/ https://www.meetup.com/Tampa-Bay-WordPress/ https://tampabaywp.org/ https://www.facebook.com/groups/wptpa/ Slack – (Chat for Tampa Bay WordPress and associated Meetups) tampabaywp.slack.com (This is by invite only so you need to request through the meetup either on Tampa Bay WordPress or New Port Richey WordPress Meetup. All we need is an email to send you an invite.)
  • 25.