Alec Tang

Professional Web Developer/ Web Designer

I build websites based on the latest web standards providing the best possible solution to your company

  • Home
  • About
  • Portfolio
  • Contact
  • Blog
Subscribe Feed

Wordpress, Safe Enough from Hackers?

Posted by Alec on Wed, 02 Sep 2009, in Web Design   Wordpress   

I still remember the first time I started using Wordpress, that was not so long ago when the word 'blogging' started to appear on every media. Blogs have grown dramatically popular. Some blog for making pennies out of it, some blog for fun and variety reasons. Back in that time, there weren't many blogging platforms available, apart from those written as open source, such as Wordpress. It quickly became a hit year after year partly because of its simplicity of usage and free of charge.

Today, Wordpress community had grown bigger than it was and thousands and thousands of developers work on modules, pluggins and themes for it. However, security has always been a big issue for Wordpress powered sites and it seems to be one of the most common concerns for open sourced software. While wordpress powered blogs can be found almost everywhere on the Internet, it has quickly become a good spot for hackers and spam marketers to tack on.

The earliest trick of spamming on WP blogs was the annoying "spammy comments". Every blog post has the ability of enabling readers to leave comments. Many black hats saw this opportunity and used automated robot to post spammy comment on blogs crawled. These comments usually contained of links to their website or affiliated products and are usually irrelevant to the blog post's content, hence hurting the blog's status for organic search rankings.Developers had quickly realised this attack and later came out with a solution called, CAPTCHA, which is a technique enforcing comment authors to verify if they are real human by entering human readable only characters into a validated text field.

While this solved spammy comments for awhile, the new form of attacks on Wordpress blog has emerged. Recent years, many WP blogs have been attacked by hackers who hacked into their file systems and left malicious script on their template, which generated hidden links. What's even more scary is most of the time, the owner of these blogs are not aware of it because the links are hidden. The result of this is a dramatic decrease of website traffic, losing many high rankings from Google and possibly even blocked by Google.

As the Wordpress team are constantly developing and fixing security holes, Wordpress bloggers should always make sure their site is as safe as possible through the following checklist:

  • Always upgrade Wordpress platform to the latest
  • Install CAPTCHA or disable comments
  • Download security plugins which scan through files for malicious codings
  • Lock your templates in ftp, never have files with 777 rights
  • Constantly changing password every few months
  • Rename table prefix to something other than wp_
  • Constantly monitoring website traffic, if any dramatical change
  • Deleting malicious plugins

 

Comments Be the first to write a comment. Comment gets approved before publishing.

Post Your Comment

 
 
   

Search

 

Latest Posts

  • List Attachments Open as Read Only
  • Website finally back up from Google's block
  • Sys.WebForms.PageRequestManagerParserErrorException
  • How Google treats Content Duplication
  • How to create HTML column in Sharepoint List View
  • How Sharepoint stores User Data
  • How to send email via Sharepoint
  • Malaysia Airlines launched iPhone Application: MHMobile
  • Intranet, the next big market
  • How to retrieve and update from a multi choice Checkboxlist ...

Categories

  • Browsers (1)
  • Projects (1)
  • Web Design (7)
  • Sharepoint (21)
  • Telerik (5)
  • Wordpress (1)
  • Internet (2)
  • SQL (5)
  • LINQ (3)
  • ASP.NET C# (34)
  • JavaScripts (3)
  • IIS (0)
  • Industry (1)
  • Tools (8)
  • SEO (5)

Archives

  • September 2010 (1)
  • August 2010 (1)
  • May 2010 (1)
  • April 2010 (3)
  • March 2010 (5)
  • February 2010 (4)
  • January 2010 (11)
  • November 2009 (3)
  • October 2009 (1)
  • September 2009 (9)
  • August 2009 (3)
  • July 2009 (4)
  • June 2009 (1)
  • May 2009 (2)
  • April 2009 (8)
  • March 2009 (6)
  • February 2009 (2)
© Copyright 2009 Alec Tang. All Rights Reserved.
This site is conform to W3C Standard XHTML & CSS