jeremonster
Regular Member
- Oct 27, 2010
- 218
- 64
What is up with so many people trying to hack my WordPress sites? I have always believed that a strong password is the key to not having your WordPress site hacked and replaced with some casino or Viagra crap (it happened to me in the early days). By default WordPress does not limit the number of attempts someone can make when trying to log in. This makes it very easy for a well programmed "Bot" to go wild with login attempts.
I have this one WordPress website that gets around 8,000 unique views a month and is targeted on entertainment. I noticed some serious traffic to my default install /WP-Admin. I installed a plugin that limits login attempts and then blocks the IPs for any amount of time that I choose. I was shocked that there were so many attempts to hack my site. I blocked 42 IPs on the first day. I really had no idea that so many attempts were made on my sites. So, I decided to share some WordPress security tips for the new guys or those like me who focus on other things.
Simple steps to protect your WordPress site:
1: Crazy Strong Password! There are some random password generators that you can use and modify. Don't use something simple!
2: I am sure that everyone here already knows we should never leave the WordPress user name as "Admin", right?
3: Change the location of your admin login so that it is not domain.com/wp-admin
4: Back up your database regularly so that you have a restore point in the event you are hacked.
5: Lock the write access to your files to limit any damage, this may not always make sense, but it can make sure your site is safe.
6: Limit login attempts (free plugin that you can manage how long the IPs are blocked and how many attempts they get.
7: Stay updated with WordPress and plugins
8: Pray that your hosting is secure and say seven Hail Marys.
9: Research some good security plugins that you feel meet your needs and install them.
10: No, Seriously... Change your Damn password!
Hope this helps secure your blogs and sites until the next Google Algorithm removes us from the SERPs.:drinking2
I have this one WordPress website that gets around 8,000 unique views a month and is targeted on entertainment. I noticed some serious traffic to my default install /WP-Admin. I installed a plugin that limits login attempts and then blocks the IPs for any amount of time that I choose. I was shocked that there were so many attempts to hack my site. I blocked 42 IPs on the first day. I really had no idea that so many attempts were made on my sites. So, I decided to share some WordPress security tips for the new guys or those like me who focus on other things.
Simple steps to protect your WordPress site:
1: Crazy Strong Password! There are some random password generators that you can use and modify. Don't use something simple!
2: I am sure that everyone here already knows we should never leave the WordPress user name as "Admin", right?
3: Change the location of your admin login so that it is not domain.com/wp-admin
4: Back up your database regularly so that you have a restore point in the event you are hacked.
5: Lock the write access to your files to limit any damage, this may not always make sense, but it can make sure your site is safe.
6: Limit login attempts (free plugin that you can manage how long the IPs are blocked and how many attempts they get.
7: Stay updated with WordPress and plugins
8: Pray that your hosting is secure and say seven Hail Marys.
9: Research some good security plugins that you feel meet your needs and install them.
10: No, Seriously... Change your Damn password!
Hope this helps secure your blogs and sites until the next Google Algorithm removes us from the SERPs.:drinking2