SlideShare a Scribd company logo
1 of 24
Download to read offline
https://www.sucuri.net https://blog.sucuri.net
Who are we?
● Globally distributed website security
team
● Website Antivirus + Firewall
● Clean hundreds of websites per day
● Protect against countless attacks
● Platform agnostic
Who am I?
● Ben Martin @rngdmstrben
● Remediation Lead and malware slaya' at Sucuri
● Hails from Victoria BC
● ~2 years at the company cleaning websites
● Security / online privacy geek
● Music Producer & cat enthusiest
Building a Better Security Posture
● Security matters: All websites get
attacked!
● Responsibility & safety
● Attackers go after low hanging fruit
● Peace of Mind
Security can be complicated but the principles are actually very simple :)
What is 'Security Posture'?
● Security is not just a service or
software that can be
purchased
● Security is an attitude
● Development of good habits
● Critical thinking + wee bit of
healthy paranoia
There are NO silver bullet security solutions!
Be Proactive Not Reactive
● “We are intuitive. We drink water before we become
dehydrated. We sleep before we become overtired.
Most of the time, we automatically defend ourselves
from germs and viruses, because we have
consciously (and unconsciously) focused on
preventative maintenance for our bodies and
minds...Spend more time preventing problems
and less time fixing issues that result from a
compromise”
David L. Prowse
Common Myth!
● “Bob must have gone to some website
that he shouldn't have!”
● All types of websites get
attacked/compromised regardless of
content
● You don't have to go to “sketchy”
websites to find malware
Popular CMS = Targeted CMS
● WP is more than 20% of the Internet!
● Common targets for attackers
● Vulnerable plugins + themes are a big
problem
Why would someone want to hack ME!?
● Automation – targeted attacks are
usually reserved for big companies
● Same thing that motivates most bad
behaviour: Money! $$$
● Phishing, malicious redirects, drive
by downloads, blackhat SEO
● Defacements / Hacktivism
Security is a Priority
● We all want our websites to have excellent content, look
nice and be easy to use. Add security to that list!
● You are responsible as a site owner
● Check up on your site security every time you log in –
familiarize yourself with your environment
● Learn to recognize when something
is out of place
What is POOR Security Posture?
● Avoiding plugin, theme & core
updates
● Using “freemium” (pirated) plugins,
themes or other software
● Lumping multiple
websites/subdomains into the
same hosting account
● Relying on the assumption that
you won't be hacked because it is
unlikely (?)
Responsibility
● Responsibility to protect your
site visitors & yourself
● Protect your reputation & hard
work! “Is this site safe?”
● Consider security a priority
from day one
● Your visitors trust you & your
website
Plugins
● Out of date / vulnerable software is leading
cause of website infection
● Less is more
● Decrease the attack surface
● Avoid old plugins and update update update!!!
● Also helps speed/memory of site
Passwords
● Other leading cause of infection
● Pass123 = no bueno
● Automated password attacks
● Reusing passwords = no buneo
● Use secure, encrypted protocols
like SFTP or FTPS
Backups
● Backup your website. Always. ALWAYS.
● Your best friend on a rainy day
● Store them offline in a safe place
● Learn how to restore via FTP & database –
this goes a long way
Practical Steps to Take
● UPDATE UPDATE UPDATE!!!
● Don't keep old software on your server
● Use a security plugin (Sucuri Scanner,
Wordfence, iThemes, etc)
● Consider a firewall – paid & free options
available
Practical Steps to Take pt. 2
● Default settings are inherantly
unsafe for all software/hardware!
● Exercise least privilege
● define( 'DISALLOW_FILE_EDIT',
true );
● Verify your file permissions and
ownership ( 644, 755 )
Lock Down /wp-admin
● Don't use admin name 'admin'
● Employ the use of a CAPTCHA
● Restrict access by IP address
● Don't forget to monitor who's
logging in
Sucuri Scanner WP Plugin (free)
● Security activity auditing
● File integrity monitoring
● Remote malware scanning
● Website hardening
What if I get HACKED!?!?1
● This is when you really
appreciate being proactive
● Website compromises are
stressful but don't panic!
● Every problem has a
solution
● Not a bad idea to disclose
to your visitors
Protect Yourself Online
● All this talk about malware, how do I stay safe!?
● Antivirus obviously (yes even if you have a Mac)
● Practice good / responsible browsing habits
● Security browser extensions – NoScript, AdBlock, HTTPS Everywhere
● Web browser security is can be annoying & inconvenient but is very
important
visitorTracker_isMob( ){
● Very aggressive campaign
targeting multiple vulnerabilities
● Ultimate goal is to redirect users to
Nuclear Exploit Kit (Ransomeware,
Cryptolocker, other exploits)
● Many thousands of websites
infected + blacklisted
Building a Better Security Posture

More Related Content

More from Sucuri

Sucuri Webinar: What is SEO Spam and How to Fight It
Sucuri Webinar: What is SEO Spam and How to Fight ItSucuri Webinar: What is SEO Spam and How to Fight It
Sucuri Webinar: What is SEO Spam and How to Fight ItSucuri
 
Sucuri Webinar: How To Know For Sure You Can Trust A Plugin
Sucuri Webinar: How To Know For Sure You Can Trust A PluginSucuri Webinar: How To Know For Sure You Can Trust A Plugin
Sucuri Webinar: How To Know For Sure You Can Trust A PluginSucuri
 
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends Sucuri
 
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit Guide
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit GuideSucuri Webinar: WAF (Firewall) and CDN Feature Benefit Guide
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit GuideSucuri
 
Sucuri Webinar: Leveraging Sucuri's API
Sucuri Webinar: Leveraging Sucuri's APISucuri Webinar: Leveraging Sucuri's API
Sucuri Webinar: Leveraging Sucuri's APISucuri
 
Sucuri Webinar: Website Security Primer for Digital Marketers
Sucuri Webinar: Website Security Primer for Digital MarketersSucuri Webinar: Website Security Primer for Digital Marketers
Sucuri Webinar: Website Security Primer for Digital MarketersSucuri
 
Sucuri Webinar: Sucuri Introduces the Sales Enablement Department
Sucuri Webinar: Sucuri Introduces the Sales Enablement DepartmentSucuri Webinar: Sucuri Introduces the Sales Enablement Department
Sucuri Webinar: Sucuri Introduces the Sales Enablement DepartmentSucuri
 
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website SpeedSucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website SpeedSucuri
 
Sucuri Webinar: Simple Steps To Secure Your Online Store
Sucuri Webinar: Simple Steps To Secure Your Online StoreSucuri Webinar: Simple Steps To Secure Your Online Store
Sucuri Webinar: Simple Steps To Secure Your Online StoreSucuri
 
Sucuri Webinar: Getting Started with Sucuri
Sucuri Webinar: Getting Started with SucuriSucuri Webinar: Getting Started with Sucuri
Sucuri Webinar: Getting Started with SucuriSucuri
 
Sucuri Webinar: Is SSL enough to secure your website?
Sucuri Webinar: Is SSL enough to secure your website?Sucuri Webinar: Is SSL enough to secure your website?
Sucuri Webinar: Is SSL enough to secure your website?Sucuri
 
Sucuri Webinar: Preventing Cross-Site Contamination for Beginners
Sucuri Webinar: Preventing Cross-Site Contamination for BeginnersSucuri Webinar: Preventing Cross-Site Contamination for Beginners
Sucuri Webinar: Preventing Cross-Site Contamination for BeginnersSucuri
 
Webinar: CWAF for Mid Market/Enterprise Organizations
Webinar: CWAF for Mid Market/Enterprise OrganizationsWebinar: CWAF for Mid Market/Enterprise Organizations
Webinar: CWAF for Mid Market/Enterprise OrganizationsSucuri
 
Webinar: eCommerce Compliance - PCI meets GDPR
Webinar: eCommerce Compliance - PCI meets GDPRWebinar: eCommerce Compliance - PCI meets GDPR
Webinar: eCommerce Compliance - PCI meets GDPRSucuri
 
Webinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio Web
Webinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio WebWebinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio Web
Webinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio WebSucuri
 
Ecommerce Website Security
Ecommerce Website SecurityEcommerce Website Security
Ecommerce Website SecuritySucuri
 
Kludges and PHP. Why Should You Use a WAF?
Kludges and PHP. Why Should You Use a WAF?Kludges and PHP. Why Should You Use a WAF?
Kludges and PHP. Why Should You Use a WAF?Sucuri
 
Otimização de Websites para Ganho de Performance & Resiliência
Otimização de Websites para Ganho de Performance & ResiliênciaOtimização de Websites para Ganho de Performance & Resiliência
Otimização de Websites para Ganho de Performance & ResiliênciaSucuri
 
Guia de Segurança para WordPress
Guia de Segurança para WordPressGuia de Segurança para WordPress
Guia de Segurança para WordPressSucuri
 
Gambiarra e PHP. Por que você deveria usar um WAF?
Gambiarra e PHP. Por que você deveria usar um WAF?Gambiarra e PHP. Por que você deveria usar um WAF?
Gambiarra e PHP. Por que você deveria usar um WAF?Sucuri
 

More from Sucuri (20)

Sucuri Webinar: What is SEO Spam and How to Fight It
Sucuri Webinar: What is SEO Spam and How to Fight ItSucuri Webinar: What is SEO Spam and How to Fight It
Sucuri Webinar: What is SEO Spam and How to Fight It
 
Sucuri Webinar: How To Know For Sure You Can Trust A Plugin
Sucuri Webinar: How To Know For Sure You Can Trust A PluginSucuri Webinar: How To Know For Sure You Can Trust A Plugin
Sucuri Webinar: How To Know For Sure You Can Trust A Plugin
 
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends
Sucuri Webinar: Tis the Season for Credit Card Scraping and Malware Trends
 
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit Guide
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit GuideSucuri Webinar: WAF (Firewall) and CDN Feature Benefit Guide
Sucuri Webinar: WAF (Firewall) and CDN Feature Benefit Guide
 
Sucuri Webinar: Leveraging Sucuri's API
Sucuri Webinar: Leveraging Sucuri's APISucuri Webinar: Leveraging Sucuri's API
Sucuri Webinar: Leveraging Sucuri's API
 
Sucuri Webinar: Website Security Primer for Digital Marketers
Sucuri Webinar: Website Security Primer for Digital MarketersSucuri Webinar: Website Security Primer for Digital Marketers
Sucuri Webinar: Website Security Primer for Digital Marketers
 
Sucuri Webinar: Sucuri Introduces the Sales Enablement Department
Sucuri Webinar: Sucuri Introduces the Sales Enablement DepartmentSucuri Webinar: Sucuri Introduces the Sales Enablement Department
Sucuri Webinar: Sucuri Introduces the Sales Enablement Department
 
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website SpeedSucuri Webinar: How Caching Options Can Impact Your Website Speed
Sucuri Webinar: How Caching Options Can Impact Your Website Speed
 
Sucuri Webinar: Simple Steps To Secure Your Online Store
Sucuri Webinar: Simple Steps To Secure Your Online StoreSucuri Webinar: Simple Steps To Secure Your Online Store
Sucuri Webinar: Simple Steps To Secure Your Online Store
 
Sucuri Webinar: Getting Started with Sucuri
Sucuri Webinar: Getting Started with SucuriSucuri Webinar: Getting Started with Sucuri
Sucuri Webinar: Getting Started with Sucuri
 
Sucuri Webinar: Is SSL enough to secure your website?
Sucuri Webinar: Is SSL enough to secure your website?Sucuri Webinar: Is SSL enough to secure your website?
Sucuri Webinar: Is SSL enough to secure your website?
 
Sucuri Webinar: Preventing Cross-Site Contamination for Beginners
Sucuri Webinar: Preventing Cross-Site Contamination for BeginnersSucuri Webinar: Preventing Cross-Site Contamination for Beginners
Sucuri Webinar: Preventing Cross-Site Contamination for Beginners
 
Webinar: CWAF for Mid Market/Enterprise Organizations
Webinar: CWAF for Mid Market/Enterprise OrganizationsWebinar: CWAF for Mid Market/Enterprise Organizations
Webinar: CWAF for Mid Market/Enterprise Organizations
 
Webinar: eCommerce Compliance - PCI meets GDPR
Webinar: eCommerce Compliance - PCI meets GDPRWebinar: eCommerce Compliance - PCI meets GDPR
Webinar: eCommerce Compliance - PCI meets GDPR
 
Webinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio Web
Webinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio WebWebinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio Web
Webinar: 10 Consejos para Mejorar la Postura de Seguridad de tu Sitio Web
 
Ecommerce Website Security
Ecommerce Website SecurityEcommerce Website Security
Ecommerce Website Security
 
Kludges and PHP. Why Should You Use a WAF?
Kludges and PHP. Why Should You Use a WAF?Kludges and PHP. Why Should You Use a WAF?
Kludges and PHP. Why Should You Use a WAF?
 
Otimização de Websites para Ganho de Performance & Resiliência
Otimização de Websites para Ganho de Performance & ResiliênciaOtimização de Websites para Ganho de Performance & Resiliência
Otimização de Websites para Ganho de Performance & Resiliência
 
Guia de Segurança para WordPress
Guia de Segurança para WordPressGuia de Segurança para WordPress
Guia de Segurança para WordPress
 
Gambiarra e PHP. Por que você deveria usar um WAF?
Gambiarra e PHP. Por que você deveria usar um WAF?Gambiarra e PHP. Por que você deveria usar um WAF?
Gambiarra e PHP. Por que você deveria usar um WAF?
 

Recently uploaded

办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书zdzoqco
 
TRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxTRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxAndrieCagasanAkio
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119APNIC
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predieusebiomeyer
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书rnrncn29
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书rnrncn29
 
Company Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxCompany Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxMario
 
ETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxNIMMANAGANTI RAMAKRISHNA
 
Unidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxUnidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxmibuzondetrabajo
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxDyna Gilbert
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa494f574xmv
 

Recently uploaded (11)

办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
办理多伦多大学毕业证成绩单|购买加拿大UTSG文凭证书
 
TRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptxTRENDS Enabling and inhibiting dimensions.pptx
TRENDS Enabling and inhibiting dimensions.pptx
 
IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119IP addressing and IPv6, presented by Paul Wilson at IETF 119
IP addressing and IPv6, presented by Paul Wilson at IETF 119
 
SCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is prediSCM Symposium PPT Format Customer loyalty is predi
SCM Symposium PPT Format Customer loyalty is predi
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
 
Company Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptxCompany Snapshot Theme for Business by Slidesgo.pptx
Company Snapshot Theme for Business by Slidesgo.pptx
 
ETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptxETHICAL HACKING dddddddddddddddfnandni.pptx
ETHICAL HACKING dddddddddddddddfnandni.pptx
 
Unidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptxUnidad 4 – Redes de ordenadores (en inglés).pptx
Unidad 4 – Redes de ordenadores (en inglés).pptx
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptx
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa
 

Building a Better Security Posture

  • 2. Who are we? ● Globally distributed website security team ● Website Antivirus + Firewall ● Clean hundreds of websites per day ● Protect against countless attacks ● Platform agnostic
  • 3. Who am I? ● Ben Martin @rngdmstrben ● Remediation Lead and malware slaya' at Sucuri ● Hails from Victoria BC ● ~2 years at the company cleaning websites ● Security / online privacy geek ● Music Producer & cat enthusiest
  • 4. Building a Better Security Posture ● Security matters: All websites get attacked! ● Responsibility & safety ● Attackers go after low hanging fruit ● Peace of Mind Security can be complicated but the principles are actually very simple :)
  • 5.
  • 6. What is 'Security Posture'? ● Security is not just a service or software that can be purchased ● Security is an attitude ● Development of good habits ● Critical thinking + wee bit of healthy paranoia There are NO silver bullet security solutions!
  • 7. Be Proactive Not Reactive ● “We are intuitive. We drink water before we become dehydrated. We sleep before we become overtired. Most of the time, we automatically defend ourselves from germs and viruses, because we have consciously (and unconsciously) focused on preventative maintenance for our bodies and minds...Spend more time preventing problems and less time fixing issues that result from a compromise” David L. Prowse
  • 8. Common Myth! ● “Bob must have gone to some website that he shouldn't have!” ● All types of websites get attacked/compromised regardless of content ● You don't have to go to “sketchy” websites to find malware
  • 9. Popular CMS = Targeted CMS ● WP is more than 20% of the Internet! ● Common targets for attackers ● Vulnerable plugins + themes are a big problem
  • 10. Why would someone want to hack ME!? ● Automation – targeted attacks are usually reserved for big companies ● Same thing that motivates most bad behaviour: Money! $$$ ● Phishing, malicious redirects, drive by downloads, blackhat SEO ● Defacements / Hacktivism
  • 11. Security is a Priority ● We all want our websites to have excellent content, look nice and be easy to use. Add security to that list! ● You are responsible as a site owner ● Check up on your site security every time you log in – familiarize yourself with your environment ● Learn to recognize when something is out of place
  • 12. What is POOR Security Posture? ● Avoiding plugin, theme & core updates ● Using “freemium” (pirated) plugins, themes or other software ● Lumping multiple websites/subdomains into the same hosting account ● Relying on the assumption that you won't be hacked because it is unlikely (?)
  • 13. Responsibility ● Responsibility to protect your site visitors & yourself ● Protect your reputation & hard work! “Is this site safe?” ● Consider security a priority from day one ● Your visitors trust you & your website
  • 14. Plugins ● Out of date / vulnerable software is leading cause of website infection ● Less is more ● Decrease the attack surface ● Avoid old plugins and update update update!!! ● Also helps speed/memory of site
  • 15. Passwords ● Other leading cause of infection ● Pass123 = no bueno ● Automated password attacks ● Reusing passwords = no buneo ● Use secure, encrypted protocols like SFTP or FTPS
  • 16. Backups ● Backup your website. Always. ALWAYS. ● Your best friend on a rainy day ● Store them offline in a safe place ● Learn how to restore via FTP & database – this goes a long way
  • 17. Practical Steps to Take ● UPDATE UPDATE UPDATE!!! ● Don't keep old software on your server ● Use a security plugin (Sucuri Scanner, Wordfence, iThemes, etc) ● Consider a firewall – paid & free options available
  • 18. Practical Steps to Take pt. 2 ● Default settings are inherantly unsafe for all software/hardware! ● Exercise least privilege ● define( 'DISALLOW_FILE_EDIT', true ); ● Verify your file permissions and ownership ( 644, 755 )
  • 19. Lock Down /wp-admin ● Don't use admin name 'admin' ● Employ the use of a CAPTCHA ● Restrict access by IP address ● Don't forget to monitor who's logging in
  • 20. Sucuri Scanner WP Plugin (free) ● Security activity auditing ● File integrity monitoring ● Remote malware scanning ● Website hardening
  • 21. What if I get HACKED!?!?1 ● This is when you really appreciate being proactive ● Website compromises are stressful but don't panic! ● Every problem has a solution ● Not a bad idea to disclose to your visitors
  • 22. Protect Yourself Online ● All this talk about malware, how do I stay safe!? ● Antivirus obviously (yes even if you have a Mac) ● Practice good / responsible browsing habits ● Security browser extensions – NoScript, AdBlock, HTTPS Everywhere ● Web browser security is can be annoying & inconvenient but is very important
  • 23. visitorTracker_isMob( ){ ● Very aggressive campaign targeting multiple vulnerabilities ● Ultimate goal is to redirect users to Nuclear Exploit Kit (Ransomeware, Cryptolocker, other exploits) ● Many thousands of websites infected + blacklisted