• Share
  • Email
  • Embed
  • Like
  • Save
  • Private Content
WordPress Security
 

WordPress Security

on

  • 3,874 views

Basics of WordPress Security as presented on February 8, 2012 at the Houston WordPress Meetup.

Basics of WordPress Security as presented on February 8, 2012 at the Houston WordPress Meetup.

Statistics

Views

Total Views
3,874
Views on SlideShare
3,874
Embed Views
0

Actions

Likes
1
Downloads
1
Comments
0

0 Embeds 0

No embeds

Accessibility

Categories

Upload Details

Uploaded via as Adobe PDF

Usage Rights

© All Rights Reserved

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Processing…
Post Comment
Edit your comment

    WordPress Security WordPress Security Presentation Transcript

    • WordPress [si-kyoor-i-tee] Barry Abrahamson AutomatticThursday, February 9, 12
    • • Automattic since 2006 • Scaling / Servers / Security / Stuff • http://barry.wordpress.com/Thursday, February 9, 12
    • Four Ws One H • Who • Why • When • Where • HowThursday, February 9, 12
    • WhoThursday, February 9, 12
    • Why • Fun • Revenge • Profit • PoliticalThursday, February 9, 12
    • When • (In)?Convenient • Least Expected • Coordinated Attacks • 0-day exploitsThursday, February 9, 12
    • (Every) Where • Shared Hosting • Virtual Private Server • Dedicated Server • Large Enterprises • Even your laptop!Thursday, February 9, 12
    • HowThursday, February 9, 12
    • DefacementThursday, February 9, 12
    • Spam Links • base64_decode(aHR0cDovLzEyNy4wLjAu MS9oZWxsby1zcGFtbWVyLnBocA==); • http://127.0.0.1/hello-spammer.phpThursday, February 9, 12
    • PHP Shell • http://phpshell.sourceforge.net/ • <?php / *00000000000000000000000000000000*/ eval(gzinflate(base64_decode(FZfFzsQ6uk Ufp89RBmHSHYWZsTJphZk5T3// npZKVbY/e++1yisd/qm/dqqG9Cj/yThursday, February 9, 12
    • DemoThursday, February 9, 12
    • How to Keep Your Site SafeThursday, February 9, 12
    • Security Plugins • http://wordpress.org/extend/plugins/ exploit-scanner/ • VaultPressThursday, February 9, 12
    • File Permissions • drwxrwxrwx 5 user group 4096 Feb 7 01:35 wp-content/ • drwxr-xr-x 5 user group 4096 Feb 7 01:35 wp-content/ • -rw-r--r-- 1 user group 3371 Feb 7 01:51 wp-config.php • chmod -R 777Thursday, February 9, 12
    • Virus Scanner • FTP passwords stolen by viruses on your computer can put your website at riskThursday, February 9, 12
    • Conclusion • Securing your website is a lot like securing your house or car. If someone really wants to break in, they probably will, but it is important to lock the doors and windows and have good insurance in case something bad happens.Thursday, February 9, 12
    • Questions?Thursday, February 9, 12