Y T Nuke  
Results 1 to 5 of 5
K this is my first real contribution to BHW hope you enjoy it! Lately I ...
  1. #1
    __dark__'s Avatar
    __dark__ is offline Registered Member
    Join Date
    Feb 2010
    Posts
    63
    Reputation
    12
    Thanks
    43
    Thanked 24 Times in 15 Posts

    Default Wordpress: Avoid getting hacked

    K this is my first real contribution to BHW hope you enjoy it!

    Lately I keep seeing threads where people get hacked by using wordpress, usually when you get hacked using wordpress is by a script kiddie that googled you with a custom footprint for a given plugin you use and gained acces by sql injection.

    So here are a few steps to avoid getting hacked by script kiddies:

    1. Always install and update your wordpress blog to the latest version!
    You can do that by going to http://wordpress.org and checking the current version. They release new updates because of exploits found in their php code so its vital for you to update on time!

    2.Before installing any plugins I suggest you go to google.com and type in:

    "plugin name" + exploit
    Example:
    wp super cache exploit

    and see what that gives you, look around check the version which is exploitable, if you have the exploitable version don't install or if you have it installed disable uninstall it!

    3. Rename your wordpress admin folder when you are not using it!, for instance rename wp-admin to a random name, when you need to get into your admin panel you simply rename it back to wp-admin when you logout rename it back to something random. That will throw away the script kiddie ( I'm referring to hackers as script kiddies) because kids that hack sites through vulnerabilities just for the sake of it are not that smart to find a hidden admin folder.

    If you want to permanently rename your wordpress folder and make the new path functional I have found a few links on google

    Code:
    http://www.rockyrasonable.com/websites/wordpress-change-wp-admin-folder-name
    And many others if you just search google for it!

    4.Adding a .htacces rule to your wordpress folder

    Code:
    http://www.howtogeek.com/howto/the-geek-blog/protecting-your-wordpress-admin-panel-from-hackers-with-htaccess/
    Now you must understand that sometimes when you are on a shared hosting plan with other sites, hundred of sites, and one of the sites gets shelled, by shelling I mean a hacker manages to upload a script that allows him to upload, edit delete files from the server and sql database, your site is vulnerable as well because the shell allows him to browse through all the files on the server meaning your account aswell! some hosting providers have a protection against this many don't, so some times it might not even be your fault.

    This is how a shell looks like

    Code:
    http://corz.org/corz/c99.php
    Now, when you get hacked the best thing to do is the rollback to a backup! because when I used to be a script kiddie I for one used to plant my shells all over the place, so once they deleted my shell I'd still have acces to my other ones .

    I'll update this if anythign else pops in my mind also feel free to ask question or to add !
    Last edited by __dark__; 01-30-2012 at 08:20 PM.

  2. The Following 4 Users Say Thank You to __dark__ For This Useful Post:

    albaniax (01-30-2012), everythingred (01-30-2012), MaxWeber (01-30-2012), ziplack (01-30-2012)

  3. #2
    Join Date
    Feb 2010
    Location
    BHW
    Posts
    631
    Reputation
    126
    Thanks
    79
    Thanked 176 Times in 115 Posts

    Default Re: Wordpress: Avoid getting hacked

    Usefull info
    got mines hacked this month


  4. #3
    lablinks's Avatar
    lablinks is online now Jr. VIP
    Join Date
    Apr 2010
    Posts
    768
    Reputation
    114
    Thanks
    123
    Thanked 125 Times in 101 Posts

    Default Re: Wordpress: Avoid getting hacked

    remove all template by, plugin by, theme by
    if you don't use comments, remove them entirely from your template
    rename file upload folders

    CSS eShop - Your Dream High PR, High AUTHORITY LOW OBL Link Service

  5. The Following User Says Thank You to lablinks For This Useful Post:

    albaniax (01-30-2012)

  6. #4
    revekozu's Avatar
    revekozu is offline Junior Member
    Join Date
    Jul 2010
    Posts
    111
    Reputation
    21
    Thanks
    39
    Thanked 35 Times in 22 Posts

    Default Re: Wordpress: Avoid getting hacked

    The vulnerability in WP Supercache was fixed with recent versions of wp, right?

  7. #5
    __dark__'s Avatar
    __dark__ is offline Registered Member
    Join Date
    Feb 2010
    Posts
    63
    Reputation
    12
    Thanks
    43
    Thanked 24 Times in 15 Posts

    Default Re: Wordpress: Avoid getting hacked

    from what I've red wp super cache is safe now and was safe before, it had an exploit but it didn't expose the website to rooting.

AdStract


Advertise on Black Hat World

Similar Threads

  1. HELP! Wordpress blogsites hacked
    By kyaw2x in forum Black Hat SEO
    Replies: 31
    Last Post: 04-18-2012, 11:30 AM
  2. Some assistance needed! Wordpress site hacked.
    By super11 in forum BlackHat Lounge
    Replies: 6
    Last Post: 06-21-2011, 08:51 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
  SEnukeX SEO Software
Proudly Powered by Hostwinds.com Web Hosting Click Here For Exclusive BHW Discounts!

Cheap Web Hosting


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76