Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-12-2009, 05:57 AM   #1
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,319
wordpress tip: secure your wordpress blogs

Hackers are people too.

Unfortunately, they're the wrong type of people; the ones who'll look for
ways to break a site and suck all your hard work into oblivion, all
because their imaginary girlfriend dumped them for a PlayStation 3 while
they were busy zapping goblins with their level 32 Warlock.

If you're using the latest version of WordPress, you're already more
secure than many, but there are still ways to be safer.

Use these 5 tips to keep your self-hosted WordPress site safe. Note: most
of these tips apply to general web development too.

1. Protect your plugin directory

Showing which plugins you have installed can expose an exploit in an
outdated plugin, and is an easy target for hackers to gain access to your
site or even worse your server.

Solution:

Create an index.html file and upload it to your /wp-content/plugins/
directory.

2. Don't expose your wordpress version

Its best to remove your wordpress version string from your theme.

If you let people know what version you are running, you can be an easy
target if you are running an older version of wordpress.

Solution:

Look for and remove this line from your themes header.php file.

Code:
<meta name="generator" content="WordPress <?php bloginfo('version'); ?>" />
3. Protect your wordpress files from search engines.

Its best if you don't have any of your core wordpress files indexed by
search engines.

Solution: add the following to your robots.txt

Code:
Disallow: /wp-*
4. Protect your wordpress admin folder.

Limiting you wordpress admin by ip address will give anyone but you or
any staff members access to your admin.

If any unauthorized people try and access your admin will be sent a
forbidden 403 error.

solution: add a .htaccess to your /wp-admin directory (not your root)

Code:
order deny,allow
deny from all
allow from 216.17.172.11 (by ip address)
allow from .fris.sprint.ca (by domain)
5. Permissions, Permissions, Permissions.

Using the correct permissions on your wordpress install is a must,
especially if you are on a shared server.

All your folder permissions should be set to 755, and files should be set
to 644.

Alternatively if you want to edit your theme in the wordpress editor, use
666.

Never use 777 for wordpress permissions, if you do, you're letting all
users on the server do what they want with the site.

On a shared or badly configured server this can mean chaos.

---

On another note I found this password manager that is free and I use it
daily. It has been mentioned on NBC, and PC Magazine.

They have a desktop version and a web version

http://www.passpack.com/en/home/



Sorry if it was long, but its important.

__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff

Last edited by fris; 01-12-2009 at 05:58 AM..
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 06:08 AM   #2
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
Great post!
__________________
/(bb|[^b]{2})/
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 06:24 AM   #3
StaceyJo
Confirmed User
 
StaceyJo's Avatar
 
Join Date: Mar 2008
Posts: 8,960
Very nice post. Thanks. I bookmark this.
__________________
/_______ WebCashMaker ______\
| _TeenageDecadence - Young Board Naked Teens. |
| ____ NonNudeGirls - Female Puberty Photos. ____ |
| _ HerSelfPics - The ORIGINAL exGF SelfPic site. __ |
\.______ xPosing - Wife Photosharing site. _______./
StaceyJo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 06:30 AM   #4
Nicky
Judge Jury and Executioner
 
Nicky's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: Sweden
Posts: 30,069
Good stuff as always Fris
__________________

gfynicky @ gmail.com
Nicky is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 07:05 AM   #5
tranza
ICQ: 197-556-237
 
Join Date: Jun 2003
Location: BRASIL !!!
Posts: 57,559
Great tip man!
__________________
I'm just a newbie.
tranza is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 07:28 AM   #6
CIVMatt
Amateur Pimpin
 
CIVMatt's Avatar
 
Industry Role:
Join Date: Aug 2004
Location: Orlando, FL
Posts: 13,075
Thanks Fris, good info
__________________
Make easy money with Webcams
CIVMatt is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 07:32 AM   #7
LiveDose
Show Yer Tits!
 
LiveDose's Avatar
 
Industry Role:
Join Date: Feb 2002
Location: Somewhere Out there...
Posts: 25,792
Bump for good info.
__________________

Scammer Alert: acer19 acer [email protected] [email protected] Money stolen using PayPal
LiveDose is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 07:38 AM   #8
alias
aliasx
 
alias's Avatar
 
Join Date: Apr 2001
Posts: 19,010
ninja tips
__________________
https://porncorporation.com
alias is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 07:41 AM   #9
Sosa
In Tushy Land
 
Sosa's Avatar
 
Join Date: Oct 2002
Location: Nebraska
Posts: 40,149
good stuff fris
Sosa is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 07:52 AM   #10
AtlantisCash
Confirmed User
 
Join Date: Dec 2005
Location: Istanbul - Turkiye
Posts: 3,169
Quote:
Originally Posted by fris View Post
Hackers are people too.

Unfortunately, they're the wrong type of people; the ones who'll look for
ways to break a site and suck all your hard work into oblivion, all
because their imaginary girlfriend dumped them for a PlayStation 3 while
they were busy zapping goblins with their level 32 Warlock.

If you're using the latest version of WordPress, you're already more
secure than many, but there are still ways to be safer.

Use these 5 tips to keep your self-hosted WordPress site safe. Note: most
of these tips apply to general web development too.

1. Protect your plugin directory

Showing which plugins you have installed can expose an exploit in an
outdated plugin, and is an easy target for hackers to gain access to your
site or even worse your server.

Solution:

Create an index.html file and upload it to your /wp-content/plugins/
directory.

2. Don't expose your wordpress version

Its best to remove your wordpress version string from your theme.

If you let people know what version you are running, you can be an easy
target if you are running an older version of wordpress.

Solution:

Look for and remove this line from your themes header.php file.

Code:
<meta name="generator" content="WordPress <?php bloginfo('version'); ?>" />
3. Protect your wordpress files from search engines.

Its best if you don't have any of your core wordpress files indexed by
search engines.

Solution: add the following to your robots.txt

Code:
Disallow: /wp-*
4. Protect your wordpress admin folder.

Limiting you wordpress admin by ip address will give anyone but you or
any staff members access to your admin.

If any unauthorized people try and access your admin will be sent a
forbidden 403 error.

solution: add a .htaccess to your /wp-admin directory (not your root)

Code:
order deny,allow
deny from all
allow from 216.17.172.11 (by ip address)
allow from .fris.sprint.ca (by domain)
5. Permissions, Permissions, Permissions.

Using the correct permissions on your wordpress install is a must,
especially if you are on a shared server.

All your folder permissions should be set to 755, and files should be set
to 644.

Alternatively if you want to edit your theme in the wordpress editor, use
666.

Never use 777 for wordpress permissions, if you do, you're letting all
users on the server do what they want with the site.

On a shared or badly configured server this can mean chaos.

---

On another note I found this password manager that is free and I use it
daily. It has been mentioned on NBC, and PC Magazine.

They have a desktop version and a web version

http://www.passpack.com/en/home/



Sorry if it was long, but its important.



fris!,

Since afew days i was thinkin to contact You for something,

May i get Your icq?
AtlantisCash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 09:00 AM   #11
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,319
icq: 704-299
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 09:06 AM   #12
Ethersync
Confirmed User
 
Ethersync's Avatar
 
Join Date: Mar 2008
Location: London, Saint-Tropez, Bermuda, Moscow
Posts: 5,289
Great advice. I wish I could set this to auto-subscribe to all threads you start
Ethersync is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 09:08 AM   #13
qxm
Confirmed User
 
Join Date: Jul 2006
Location: NoHo
Posts: 5,970
u deserve rep for this ...lol ... good post m8
__________________

ICQ: 266990876
qxm is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 09:22 AM   #14
Sarah_Jayne
Now with more Jayne
 
Sarah_Jayne's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Los Angeles
Posts: 40,077
a nice one once again
Sarah_Jayne is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 09:43 AM   #15
Axel XXX
Confirmed User
 
Axel XXX's Avatar
 
Join Date: Aug 2002
Posts: 6,924
Great post
__________________
CCBill Sponsors // ccbillsponsors.com // Your #1 Source for CCBill Sponsors!
Axel XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 10:23 AM   #16
kmanrox
aka K-Man
 
kmanrox's Avatar
 
Industry Role:
Join Date: Oct 2001
Location: The Gutter
Posts: 29,290
hey frissy, stop plagiarizing and start posting reference links to the places you're scraping content from


http://wordprezzie.com/wordpress-security-tips/
__________________
Crypto HODLr
Crypto mining
Angel investor
kmanrox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 10:24 AM   #17
dav3
Confirmed User
 
dav3's Avatar
 
Industry Role:
Join Date: May 2007
Posts: 7,348
thank you wordpress ninja!
__________________
Webmasters :: Juicy Ads :: ACWM :: Crak Revenue :: Money Tree
dav3 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 10:29 AM   #18
TyroneGoldberg
Confirmed User
 
TyroneGoldberg's Avatar
 
Join Date: Sep 2007
Posts: 1,081
good tips and will use...

thanks
TyroneGoldberg is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 10:29 AM   #19
DutchTeenCash
I like Dutch Girls
 
DutchTeenCash's Avatar
 
Join Date: Feb 2003
Location: dutchteencash.com
Posts: 21,684
great post thanks
DutchTeenCash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 10:34 AM   #20
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,319
Quote:
Originally Posted by kmanrox View Post
hey frissy, stop plagiarizing and start posting reference links to the places you're scraping content from


http://wordprezzie.com/wordpress-security-tips/
I never said i wrote it, im just gathering informaiton for people to use.

but thanks for pointing out that I should have linked that article.

__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 10:41 AM   #21
seeric
..........
 
Industry Role:
Join Date: Aug 2004
Location: ..........
Posts: 41,917
thanks man.

didn't have the dissallow wp- part

now i do.

good lookin out.
seeric is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 11:24 AM   #22
kush
Confirmed User
 
Join Date: Feb 2001
Posts: 3,382
Great tips to implement!
kush is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 12:15 PM   #23
Itchy
Datetronix.com
 
Itchy's Avatar
 
Industry Role:
Join Date: Jan 2001
Location: Chill-A-Wack BC
Posts: 6,524
I know im changeing things up on my blogs thans for the great tips
__________________


ICQ: 2588560
Skype: Pornocop

Itchy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 01:27 PM   #24
Altheon
Confirmed User
 
Altheon's Avatar
 
Join Date: May 2004
Posts: 506
I'd go with RoboForm in lieu of PassPack. With Roboform you keep the passwords on your local machine. I think people are way too trusting of these web apps.
Altheon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 03:58 PM   #25
HomerSimpson
Too lazy to set a custom title
 
HomerSimpson's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: Springfield
Posts: 13,826
finally a useful post!
__________________
Make a bank with Chaturbate - the best selling webcam program
Ads that can't be block with AdBlockers !!! /// Best paying popup program (Bitcoin payouts) !!!

PHP, MySql, Smarty, CodeIgniter, Laravel, WordPress, NATS... fixing stuff, server migrations & optimizations... My ICQ: 27429884 | Email:
HomerSimpson is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 04:08 PM   #26
Supz
Arthur Flegenheimer
 
Supz's Avatar
 
Industry Role:
Join Date: Jul 2006
Location: New York City
Posts: 11,056
This is an awesome post.
Supz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-12-2009, 05:48 PM   #27
wizzart
scriptmaster
 
wizzart's Avatar
 
Industry Role:
Join Date: May 2006
Location: Serbia
Posts: 5,237
very good tips
wizzart is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2009, 05:47 AM   #28
JTCash
Confirmed User
 
JTCash's Avatar
 
Join Date: Apr 2008
Posts: 127
That is useful! Thank you!
__________________
JTCash.com Teens Ratio 1:237
My18Teens & MyTeenVideo
ICQ 221725975
JTCash is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2009, 05:52 AM   #29
Toni_N
Confirmed User
 
Join Date: Oct 2004
Location: On the moon.
Posts: 3,511
great tips
__________________
GFY regular.
Toni_N is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2009, 11:24 AM   #30
TyroneGoldberg
Confirmed User
 
TyroneGoldberg's Avatar
 
Join Date: Sep 2007
Posts: 1,081
bump as i found out i fucked up on a certain part....
TyroneGoldberg is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2009, 11:53 AM   #31
Nookster
Confirmed IT Professional
 
Industry Role:
Join Date: Nov 2005
Location: Hollywood, CA
Posts: 3,744
Good post for those whom do not know.
Nookster is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2009, 12:06 PM   #32
gimme-website
Confirmed User
 
gimme-website's Avatar
 
Industry Role:
Join Date: Jun 2008
Location: Finland
Posts: 1,588
Important yet so simple. Thank you for excellent tips!
__________________
www.gimme-website.com
gimme-website is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-13-2009, 01:01 PM   #33
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,405
Where you reading my source code again?
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-14-2009, 11:04 AM   #34
Altheon
Confirmed User
 
Altheon's Avatar
 
Join Date: May 2004
Posts: 506
Just a warning!!!

If you use .htaccess to restrict access to the WordPress directory and you are running Super Cache or one of the other cache plugins your site will be messed up. So you may want to skip that step.
Altheon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.