Michele Butcher WordPress Specialist, Site Cleaner, and Trainer for WP Security Lock One Woman Wonder at Can’t Speak Geek WordPress Website Designer @michele_butcher
Why do hackers hack? Make bank Build a zombie site army Share their nasty malware with the world Get your information They are bored They want to see if they can do it @michele_butcher
How do they get in? Guess your login. If you know it so can someone else. (Brute force attack or man in the middle) Denial of Service attack (DDoS) flood your site with more traffic than it can handle Through a theme, file or plugin Through your FTP or CPanel. (Files set to read, write,execute. Brute force, anonymous login, shared hosting infection) @michele_butcher
Even a test site or a knitting site with only 2 visitors can be hacked. It can happen to your site. @michele_butcher It has happened to me, it can happen to you.
Be Mindful of what information you put on your website. If you will not put the the information on a flier or in a commercial, do not put it on your website.
If you fear you might lose information, save it in more than one spot. Bitcasa, Carbonite, and external hard drives are great options of backing up data. @michele_butcher Back Up Your Information
Anti-virus Protect your unit! Yes I even have an anti-virus on my Mac! AVG and Avast have free versions as well as paid. Kaspersky is great with Windows and Macs. @michele_butcher
What to do when you have temporary people in your dashboard Set up a file change detection notification to know what they are changing in your site. @michele_butcher
Only give them access to what they NEED not what they want. Just because they want to be an admin does not automatically make them one. Guest bloggers should not be anymore than a contributor.
If it is only a temporary login, delete their login when they have completed their job. If they have posts on your site, you can knock them down to subscribers so they can not change anything on your site. If they are only doing work, delete them when their job is done.
iThemes Security Pro Great all encompassing best practices WordPress security plugin. Two versions a free and a premium. http://ithemes.com/security @michele_butcher Brute Protect If you are mainly worried about DDoS attacks, Brute Protect has you covered. http://bruteprotect.com
Set up a file change detection notification to know what they are changing in your site. iThemes Security and other security plugins give you the option to see what all users are doing when logged into the dashboard.
Who can scan my site for malware? Google Webmaster Tools http://google.com/ webmaster VirusTotal https://virustotal.com iThemes Security Pro htttp://ithemes.com/ security @michele_butcher
Update! Update! Update! Update core, update plugins, update themes, update content, update everything and update often! The biggest source of nearly all hacks as once something is patched, it is trivial to get into the old stuff. @michele_butcher
If you use themes or plugins at any of the envato (Themeforest, code canyon) always check the box to be notified of updates. they will not tell you otherwise This is why the RevSlider SoakSoak infection was so widespread. Many didn't know the plugin was built within the theme.
Have a minimalist approach to plugins and themes. Only have the plugins you are using at that time on your site. You can always upload them again later. Only have your theme you are using on your site. If something is not active, delete it. @michele_butcher
Back up your site! Somewhere, anywhere, just have a backup copy. BackupBuddy from iThemes is a great choice. iThemes Security will do a database backup for you. http://ithemes.com/backupbuddy @michele_butcher
Always back up to someplace OTHER than your server. If the server gets hacked, so does your backup. Even backing a copy to Dropbox or your computer is a better option. @michele_butcher
Who cleans hacked websites? Well I do over at WP Security Lock ~Smile~ http://wpsecuritylock.com I apologize… had to do one shameful plug. @michele_butcher
Thank you for attending! Slides can be found at https://mlb.pw/LadyBlogger Michele Butcher @michele_butcher http://wpsecuritylock.com http://cantspeakgeek.com