Protect your Wordpress Blogs!

makingfastcash22

Senior Member
Joined
Feb 15, 2009
Messages
1,159
Reaction score
180
Hey guys and gals!

I thought I might inform you about a couple of free plugins that can save your ass and our cash.

My amazon sales have been dropping on some of my autoblogs and I finally figured out that my blogs were open to being hacked.

So I installed wp firewall plugin and then next day I get an alert stating that it blocked a sql injection.

Also all of my problems seemed to stem from having w3 total cache.

I was a big believer in the plugin, but I found out that they got hacked and I believe this is where things started to get ugly for my autoblogs.


SO I rebuild many of them completely as the databases where plagued with iframe injections.

So now I install these plugins

wp firewall
ulitmate security checker- adjust to u get a good grade
secure wordpress
login lockdown
tim thumb vulnerability scanner-another hacker issue
antivirus- scans the theme for hacker issues
wp super cache - no longer using w3 total cache

You can also install exploit scanner and run that to see if there are any issues as well.

Well hope this saves you some time and money, I lost a lot of both!
 
Thanks for sharing :-)
I appreciate it because I have a few blogs on wordpress
 
i don't have any blogs up at the moment, but i thought i'd click on the thread and read it anyway. thanks for the tip. i'll keep it in mind for when i put up the few blogs that i'm working on at the moment. :)
 
Thanks OP! I've installed your recommended plugins. Already feel better.
 
also take a look at TAC - Theme Authenticity Checker
this plugin searches for malicious codes in themes
 
Thanks for the suggestions!

I had an issue lately where my blog kept redirecting to other sites. After I updated WordPress, it seemed to stop.

If you update, also backup your database. Sometimes WordPress likes to delete the database, when and sometimes after you update. I'm unsure why.
 
Any suggestions on how loading this amount of plugins decreases site speed?
 
From what I saw the only vulnerability's come from plugins, I use only wp super cache and the google site map.

I will be using wp firewall just for show, another BHW member got his WP hacked, he was using all the wp firewall and security plugins but this didn't stooped some angry arabs
 
Any suggestions on how loading this amount of plugins decreases site speed?

Some plugins that render something on the front-end can marginally affect site speed. While the ones that work in the back-end may/may not affect the site speed.

If you want to check how plugins are causing slow speed, install Page Speed addon for FireBug.
 
Add Silence is Golden plugin too.

This is for those who are redirected to another site.
 
so are the hackers inserting their own affiliate links or something?
 
Links to there website. Sometimes they put anchor text to gain link juice to their website. Pretty clever. Most wordpress themes that are shared nowadays have encrypted php codes.
 
Are you kidding me?... Sh*t... I went from having 15% of my income coming from Amazon down to less then 3%, I thought it was because of the season...

Being black hat means you find the edge of the rules... Being a thief means you don't care about the rules...

Is there any way to remove what has been done? Or do I have to rebuild my sites?

Is there any way to find the Iframe injections? Is there any way to remove them in bulk?
 
Last edited:
To determine if there are exploits/hacks in themes/plugins, install Exploit scanner. Eventhough you haven't activated the theme/plugin, it will still scan them. You can just upload them to determine if there are exploits.

Here are some helpful decoders for exploits:

Code:
http://www.tareeinternet.com/scripts/decrypt.php
http://www.tareeinternet.com/scripts/byterun.php
http://www.motobit.com/util/base64-decoder-encoder.asp
 
Are you kidding me?... Sh*t... I went from having 15% of my income coming from Amazon down to less then 3%, I thought it was because of the season...

Being black hat means you find the edge of the rules... Being a thief means you don't care about the rules...

Is there any way to remove what has been done? Or do I have to rebuild my sites?

Is there any way to find the Iframe injections? Is there any way to remove them in bulk?

I too would like to know the answer to that. Would most of them show up as standard Iframe code? Or would it be encrypted?
 
Back
Top