See also the main SAAFE.info site for more Support And Advice For Escorts

Author Topic: Got a WordPress-based site?  (Read 1462 times)

xw5

  • Administrator
  • Sr. Member
  • *****
  • Posts: 5,850
    • I should be updating this instead...
Got a WordPress-based site?
« on: 06 June 2013, 10:51:36 pm »
If you have a website using WordPress (the software, rather than one hosted on the WordPress.com blogging site) you need to ensure that you have something to limit the effects of the endless attempts to break into it.

Especially if you have an account on your site called 'admin' (the default when you set up a WordPress account and thus the first one hackers go for) I recommend you install a plugin called Limit Login Attempts. This bans anyone who gets the password wrong more than a couple of times in a few hours.

Sites by YourEscortSite.com all have it as part of the basic setup :) and there's also something on the webserver watching out for things like this, catching them on the first few attempts on any of the sites, rather than waiting until they've had a go at all of them. What has prompted this post is that it triggered a dozen times - that's hack attempts coming from a dozen different places - in a minute a bit earlier this evening. It's stayed at a much higher level than usual since, so there's clearly an organised attempt to get into WordPress-based sites at the moment.

Oh, unless you know exactly what you are doing, I recommend that you do not install the Better WordPress Security or WordFence plugins - you can easily lock yourself and everyone else out of your site with them.
'The Ian formerly known as SW5'. What they said: "Indispensable", "You are our best resource", and (hours later!) "I'm afraid that you're being made redundant..."

Winding down YourEscortSite.com

xw5

  • Administrator
  • Sr. Member
  • *****
  • Posts: 5,850
    • I should be updating this instead...
Re: Got a WordPress-based site?
« Reply #1 on: 27 June 2013, 06:15:51 pm »
This afternoon has seen another flood of hack attempts against YES sites - again, if you have a site that uses the WordPress software (rather than being something like yetanotherescort.wordpress.com), you do need to make sure you are protected from this sort of thing.
'The Ian formerly known as SW5'. What they said: "Indispensable", "You are our best resource", and (hours later!) "I'm afraid that you're being made redundant..."

Winding down YourEscortSite.com

SuckMyArtHole

  • Guest
Re: Got a WordPress-based site?
« Reply #2 on: 30 June 2013, 06:04:46 pm »
You need to know what you are doing with word press.

First thing is stay away from the word press free sites and use a hosted one as word press has a standard security vulnerability that needs fixing.  If any one needs help with sites or hosting drop me a line.  Plus passwords should be in a certain style.  Be very lone and contain a mixyure of numbers upper lower case and symbols.  I recommend over 25 characters as anything under is easy to brute force entry.

Ruby

xw5

  • Administrator
  • Sr. Member
  • *****
  • Posts: 5,850
    • I should be updating this instead...
Re: Got a WordPress-based site?
« Reply #3 on: 30 June 2013, 09:05:23 pm »
WordPress and/or - preferably and - the server needs to be set up so people can't do brute force attacks. But as far as passwords go, xkcd has it right: length and memorability beat silly symbols! https://xkcd.com/936/

Passwords certainly should be lone :) and there's a list of the two million most popular ones you can test yours against...
'The Ian formerly known as SW5'. What they said: "Indispensable", "You are our best resource", and (hours later!) "I'm afraid that you're being made redundant..."

Winding down YourEscortSite.com