<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jared Atchison<title>&#187; wordpress security</title>
</title>
	<atom:link href="http://www.jaredatchison.com/tag/wordpress-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jaredatchison.com</link>
	<description>Websites. Wordpress. Genesis.</description>
	<lastBuildDate>Tue, 07 Sep 2010 03:09:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>WordPress admin cracking script shows importance of security</title>
		<link>http://www.jaredatchison.com/2009/11/30/wordpress-admin-cracking-script/</link>
		<comments>http://www.jaredatchison.com/2009/11/30/wordpress-admin-cracking-script/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 20:44:41 +0000</pubDate>
		<dc:creator>j-atchison</dc:creator>
				<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[wordpress security]]></category>

		<guid isPermaLink="false">http://jaredatchison.com/?p=122</guid>
		<description><![CDATA[I stumbled on a very interesting article floating around Twitter this morning, one worth pointing out I believe. The short write up, titled Distributed WordPress admin account cracking, exposes a malicious script which was written specifically to crack WordPress admin passwords. The acquired script is written in PHP and performs brute force cracking attempts to [...]]]></description>
			<content:encoded><![CDATA[<p>I stumbled on a very interesting article floating around Twitter this morning, one worth pointing out I believe.</p>
<p>The short write up, titled <em><a href="http://isc.sans.org/diary.html?storyid=7663">Distributed WordPress admin account cracking</a></em>, exposes a malicious script which was written specifically to crack WordPress admin passwords.</p>
<blockquote><p>The acquired script is written in PHP and performs brute force cracking attempts to WordPress admin accounts</p>
<p>[...]</p>
<p>Now, the interesting thing about the script is that it allows distributed cracking. Information is saved in a MySQL database and the script actually connects directly to the main database. This allows the attacker to run many simultaneous scripts – each of them will take 200 new URLs and mark them with the brute forcer&#8217;s ID ($colo).</p></blockquote>
<p>There is nothing new or revolutionary about this script. If you have a beefy password and are up-to-date (2.8.6 as of today!) there&#8217;s no reason to worry. But I believe this illustrates the importance of doing everything possible to secure your website.</p>
<p><a href="http://www.jaredatchison.com/files/2009/11/wp-bruteforce2.png" rel="shadowbox[post-122];player=img;"><img class="alignright size-full wp-image-123" src="http://www.jaredatchison.com/files/2009/11/wp-bruteforce2-e1259613820287.png" alt="" width="354" height="289" /></a>In my last post, I embedded <a href="http://jaredatchison.com/2009/11/wordpress-security-tips/">Brad&#8217;s WordPress security presentation</a> he gave at WordCamp NYC. It contains simple yet effective ways to secure your WordPress installations &#8211; definitely worth a quick look.</p>
<p>I&#8217;ve had a few people ask me what are the quickest/easiest ways to get started securing their WP site. Almost every single thing in Brad&#8217;s presentation is important, but in my mind 2 things are the most important and can be executed in a matter of minutes.</p>
<p><strong>Delete your &#8216;admin&#8217; account</strong>. Yes, that&#8217;s right. Nuke it. Scripts such as the one mentioned above try to gain access to your website by logging into the admin account &#8211; the account with the user name <em>&#8216;admin</em>&#8216;. Create a new account, something like RobSmith (or anything other than admin!), give it admin privileges, and then delete the default admin user. You will thank me later.</p>
<p><strong>Don&#8217;t use wp_ as your default prefix</strong>. You probably don&#8217;t remember, but when you were flying through WordPress&#8217;s famous 5 click install one of the options it asked you for was the default WordPress prefix to use with the database. That&#8217;s right, I figured you didn&#8217;t remember. By default it&#8217;s set to <em>wp_</em> &#8211; this should be changed. If you have already setup your blog, you can change it using some phpmyadmin trickery, but make sure you know what you are doing first.</p>
<p>As WordPress becomes even more mainstream (gasp!) it will continue to be attacked by script kiddies and other nefarious characters. However by staying up to date and taking the appropriate steps to secure your site, you really don&#8217;t have anything to worry about.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jaredatchison.com/2009/11/30/wordpress-admin-cracking-script/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress Security Tips</title>
		<link>http://www.jaredatchison.com/2009/11/19/wordpress-security-tips/</link>
		<comments>http://www.jaredatchison.com/2009/11/19/wordpress-security-tips/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 23:21:44 +0000</pubDate>
		<dc:creator>j-atchison</dc:creator>
				<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[wordpress security]]></category>

		<guid isPermaLink="false">http://jaredatchison.com/?p=120</guid>
		<description><![CDATA[WDS-Brad from WebDevStudios had a good presentation on WordPress Security at Wordcamp NYC. Here&#8217;s the slideshow: WordPress Security &#8211; WordCamp NYC 2009 &#160; View more presentations from Brad Williams.]]></description>
			<content:encoded><![CDATA[<p><a href="http://twitter.com/williamsba">WDS-Brad</a> from <a href="http://webdevstudios.com/">WebDevStudios</a> had a good presentation on WordPress Security at Wordcamp NYC. Here&#8217;s the slideshow:</p>
<div style="width: 425px;text-align: left"><a title="WordPress Security - WordCamp NYC 2009" href="http://www.slideshare.net/williamsba/wordpress-security-updated">WordPress Security &#8211; WordCamp NYC 2009</a>
<p>&nbsp;</p>
<div style="font-size: 11px;font-family: tahoma,arial;height: 26px;padding-top: 2px">View more <a href="http://www.slideshare.net/">presentations</a> from <a href="http://www.slideshare.net/williamsba">Brad Williams</a>.</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.jaredatchison.com/2009/11/19/wordpress-security-tips/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
