Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Andrew Behla

Andrew Behla

"You've Been Hacked, Now What?" presentation from Topanga WordPress Meetup Group.

Andrew Behla

January 17, 2013
Tweet

Other Decks in Technology

Transcript

  1. You’ve BeenHacked Now What? How to Restore your WordPress Site

    and Prevent Your Site from Being Attacked
  2. Why DoHackers Do It? •Deface your site •Inject spam into

    your site •Run email scripts •Break your site •Infect computers •Because it’s fun!
  3. What Do I Do Now? •Check your index.php file •Change

    all WordPress user passwords •Change your FTP passwords •Change your cPanel or hosting passwords •Run Security Scans •Check Permissions
  4. Secure Passwords! • heRN~aim25 • WAEs37tOEd; • eff89PhASE? • BIRLs16fIX;

    • eDUcT15CoSh# • LiveS?obEse51 • strongpasswordgenerator.com
  5. Find Your Blindspots •Latest Version of WP •Vulnerable Theme •Open

    Permissions (777) •Insecure Password •Outdated timthumb.php
  6. Restore Your Site •Check if hosting has backup and can

    restore •Backup might be corrupt! •Restore from your backup •Reinstall Wordpress •Copy WP Content folder
  7. Future Prevention •Update Plugins •Update Wordpress •Update Themes •Install Security

    Plugins •Set Permissions 755 (folder) 644 (files) •Get More Secure Hosting