A look at Wordpress security, how to spot a comprised site, how to fix it, and how to prevent future attacks. Presented to the March 2013 London Wordpress Meetup.
.php files 1. new files 2. modified files 2. .htaccess (can be used to deliver payloads) 3. !! Site may have been compromised months prior to defacement!! 4. Scanners - sucuri.net vs wordfence