<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jaydip Parikh &#187; Security</title>
	<atom:link href="http://www.jaydip.info/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jaydip.info</link>
	<description>Blog by Internet Marketing Consultant to share knowledge / info about Internet Marketing, SEO, SMO, Blogging, Wordpress.</description>
	<lastBuildDate>Thu, 08 Jul 2010 12:15:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>10 Plugins to Lock Down Your WordPress Blog</title>
		<link>http://www.jaydip.info/10-plugins-lock-wordpress-blog/</link>
		<comments>http://www.jaydip.info/10-plugins-lock-wordpress-blog/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 21:04:04 +0000</pubDate>
		<dc:creator>Jaydip</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Plugins]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.jaydip.info/?p=298</guid>
		<description><![CDATA[This is guest post by TOM For years, WordPress has been known for its weak security. The security issues WordPress has had is a laundry list of hacks and exploits that malicious users can use to access personal information, post unauthorized content or simply wreck your site, none of which you want to suffer. Simple [...]]]></description>
			<content:encoded><![CDATA[<p></p><!-- RSPEAK_STOP --> <a href='http://wr.readspeaker.com/webreader/webreader.php?cid=6df46d3a41394cd525ada05ff0b3e40b&t=wordpress_free&url=http://www.jaydip.info/10-plugins-lock-wordpress-blog/&title=10 Plugins to Lock Down Your WordPress Blog' onclick='readpage(this.href, 298); return false;'> <img src='http://graphics.readspeaker.com/images/wr/listen_en_uk.gif' style='border-style: none;' alt='Listen with webReader'></a><div id='WR_298'></div> <!-- RSPEAK_START --> <p style="text-align: justify;"><em>This is guest post by <strong>TOM</strong></em></p>
<p style="text-align: justify;">For years, WordPress has been known for its weak security. The security issues WordPress has had is a laundry list of hacks and exploits that malicious users can use to access personal information, post unauthorized content or simply wreck your site, none of which you want to suffer.</p>
<p style="text-align: justify;">Simple things like changing your default password and changing your mySQL table prefixes are the preventative measures that most webmasters can do, but you shouldn’t stop there. Hackers can intercept data exchanges between your server and your computer and user’s computers to get passwords and other information. Your themes and plugins could be compromised, sending sensitive information to outside computers or even allowing hackers access to your server. Spam attacks, iFrame injections, mySQL injections, and a host of other security risks associated with WordPress can leave your blog open to disaster. Fortunately, a number of plugins are available that will automate these security tasks and make your blog less vulnerable to attack. Below, you will find 10 plugins that you can use to lockdown your WordPress blog. You can click the link to go to each plugin’s Web site to get more information about how the plugin works and how to install the plugin into your WordPress site.</p>
<p style="text-align: justify;"><strong>1. <a target="_blank" rel="nofloow" href="http://www.taragana.com/products/free-wordpress-plugins/wordpress-guard-plugin">Angsuman&#8217;s WordPress Guard Plugin</a></strong> This plugin protects your WordPress blog from brute force password attacks. Brute force is where a hacker will attempt possible password combinations until it finds one that works on your site. It also exploits that attack outdated plugins and software that can give hackers access to your blog.</p>
<p style="text-align: justify;"><strong>2. <a target="_blank" rel="nofollow" href="http://herselfswebtools.com/">Bot Block</a></strong> This plugin prevents automated registrations on your site. It blocks multiple users from signing up from the same IP address and also looks up user IP addresses on a blacklist. Any blacklisted IP addresses are not allowed to register.</p>
<p style="text-align: justify;"><strong>3. <a target="_blank" rel="nofollow" href="http://www.askapache.com/wordpress/htaccess-password-protect.html">AskApache Password Protect</a></strong> This plugin adds additional filesystem level password protection via .htaccess files, making it easy to set and change the password for WordPress directories on your server itself to prevent unauthorized attacks that can occur outside WordPress.</p>
<p style="text-align: justify;"><strong>4. <a target="_blank" rel="nofollow" href="http://www.blogsecurify.com/">WP Blogsecurify</a></strong> WP Blogsecurify works in several ways to harden WordPress. First, it forces logins to occur via SSL, reducing the chance that passwords and user names can be intercepted. Second, it prevents the leakage of session identifiers so that they can’t suffer from hijack exploits. Finally, it conceals database error information, so that information can’t be used in an attack.</p>
<p style="text-align: justify;"><strong>5. <a target="_blank" rel="nofollow" href="http://wordpress.org/extend/plugins/wp-security-scan/">WP Security Scan</a></strong> This multipurpose plugin will hide your WordPress version so it doesn’t advertise what specific vulnerabilities apply to your installation. It also checks for permission and password issues that leave your blog at risk.</p>
<p style="text-align: justify;"><strong>6. <a target="_blank" rel="nofollow" href="http://www.bad-neighborhood.com/login-lockdown.html">Login LockDown</a></strong> Login LockDown logs all unsuccessful attempts to log in to your blog and records the IP address and time of each attempt. It will lockout IP ranges associated with failed logins to discourage malicious attempts to access your site.</p>
<p style="text-align: justify;"><strong>7. <a target="_blank" rel="nofollow" href="http://www.hybrid6.com/webgeek/plugins/wp-spamfree">WP-SpamFree</a></strong> This plugin works in a similar manner to Akismet to identify comments that are spam so they are not displayed on your blog. Spam comments can include links to malicious Web sites, or malicious code that can execute on your blog. This is an effective tool that helps deal with the WordPress comment spam problem.</p>
<p style="text-align: justify;"><strong>8. <a target="_blank" rel="nofollow" href="http://www.bad-neighborhood.com/login-lockdown.html">Admin-SSL</a></strong> Admin-SSL funnels all your administrative activity through SSL, locking it down so no information can be intercepted between your computer and your blog. This works for both dedicated SSL and shared SSL configurations.</p>
<p style="text-align: justify;"><strong>9. <a target="_blank" rel="nofollow" href="http://f00f.de/blog/2007/10/02/plugin-anonymous-wordpress-plugin-updates.html">Anonymous WordPress Plugin Updates</a></strong> Since WordPress transmits information useful to hackers as it looks for plugin updates, Anonymous WordPress Plugin Updates can be used to remove identifying information such as your WordPress version and the URL of your blog. By keeping your plugin updates anonymous, you can make it harder for people to attack your site using data from plugin Web sites.</p>
<p style="text-align: justify;"><strong>10. <a target="_blank" rel="nofollow" href="http://builtbackwards.com/projects/tac/">Theme Authenticity Checker</a></strong> This plugin checks to see if a theme you’ve uploaded contains malicious code. Since so many free themes are out there, you never know if someone has embedded back door access that they can use to manipulate your site.</p>
<p style="text-align: justify;"><em>Tom is a designer and writer who works for a UK based specialist offering <a target="_blank" rel="nofollow" href="http://www.cartridgesave.co.uk/ink-cartridges/HP/DeskJet.html">HP Deskjet cartridges</a>, toner, paper and other print accessories. You can read more of his posts on <a target="_blank" rel="nofollow" href="http://www.cartridgesave.co.uk/news/">their blog</a>.</em></p>
 <!-- RSPEAK_STOP --><img src="http://www.jaydip.info/?ak_action=api_record_view&id=298&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.jaydip.info/10-plugins-lock-wordpress-blog/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Secure your Blog from Unauthorised Access : Make your Blog more Safe.</title>
		<link>http://www.jaydip.info/secure-your-blog-from-unauthorised-access-make-your-blog-more-safe/</link>
		<comments>http://www.jaydip.info/secure-your-blog-from-unauthorised-access-make-your-blog-more-safe/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 04:48:58 +0000</pubDate>
		<dc:creator>Jaydip</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Blogger]]></category>
		<category><![CDATA[Plugins]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.jaydip.info/?p=64</guid>
		<description><![CDATA[I must feel regret not be regular updating my site. I was busy due to my commitments and some other issues. Now a day’s my schedule is too tight so not be able to write regular, on top of that my all sites get Virus attack so me and Dhaval (my younger Bro – Who [...]]]></description>
			<content:encoded><![CDATA[<p></p><!-- RSPEAK_STOP --> <a href='http://wr.readspeaker.com/webreader/webreader.php?cid=6df46d3a41394cd525ada05ff0b3e40b&t=wordpress_free&url=http://www.jaydip.info/secure-your-blog-from-unauthorised-access-make-your-blog-more-safe/&title=Secure your Blog from Unauthorised Access : Make your Blog more Safe.' onclick='readpage(this.href, 64); return false;'> <img src='http://graphics.readspeaker.com/images/wr/listen_en_uk.gif' style='border-style: none;' alt='Listen with webReader'></a><div id='WR_64'></div> <!-- RSPEAK_START --> <p style="text-align: justify;">I must feel regret not be regular updating my site. I was busy due to my commitments and some other issues. Now a day’s my schedule is too tight so not be able to write regular, on top of that my all sites get Virus attack so me and <a target="_blank" href="http://www.dhavalparikh.info" target="_blank">Dhaval</a> (my younger Bro – Who is PHP techy ) was very busy to control the situations. Now all fine and I learn a lesson that How we can secure our Blog / wordpress Site.</p>
<p style="text-align: justify;">Today I want to share my personal experience about <strong>how to secure your blog from Hacking, Virus Attack and from unauthorised access.</strong></p>
<p style="text-align: justify;">After attack on my site, I had visited many sites which talk about WordPress Security. The conclusion as well as common things are as follows.</p>
<p style="text-align: justify;">
<ul style="text-align: justify;">
<li>Keep latest version of WordPress and keep it updated time to time. You must keep visiting WordPress official blog or subscribe for it. This will help to get an updation about WordPress. Don’t waste time to update the WordPress patch if it “Security Patch”</li>
<li>You must change default password which is generated by WordPress and Password should not be easy to remember. Password should be combination of Special Character, Numeric and alphabets.</li>
<li>You should block Search Engine to crawl your WordPress related folders. Now don’t think much how to do this just add following line to your robots.txt</li>
</ul>
<blockquote>
<p style="text-align: justify;">Disallow: /wp-*</p>
</blockquote>
<ul style="text-align: justify;">
<li>Did you ever realised that people can check which plugin you are using. Got shocked ? check just <strong>yoursite.com/wp-content/plugins/ </strong>If your hosting provider is good service then you will get an error else you will get shocked. Now what to do ? Confused ? Don’t worry guys. Say thanks to <strong><a target="_blank" href="http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/" target="_blank">Matt Cutts</a></strong> he has shared brilliant idea. Just make one blank file named “Index.html” and put it at same folder. Now any one visit this folder they just get blank page or Install plugin named <strong>“<a target="_blank" href="http://wordpress.org/extend/plugins/secure-wordpress/" target="_blank">Secure WordPress</a>” </strong>
<div id="attachment_67" class="wp-caption alignnone" style="width: 300px">
	<strong><strong><img class="size-medium wp-image-67" title="Secure-WordPress-Plugin" src="http://www.jaydip.info/wp-content/Secure-WordPress-Plugin-300x255.png" alt="Secure-WordPress-Plugin" width="300" height="255" /></strong></strong>
	<p class="wp-caption-text">Secure-WordPress-Plugin</p>
</div>
<p><strong> </strong></li>
<li> You must remove WordPress version information line from Meta : That line is look like following string (</li>
</ul>
<p style="text-align: justify;">If you had installed <strong>“<a target="_blank" href="http://wordpress.org/extend/plugins/secure-wordpress/" target="_blank">Secure WordPress</a>”</strong> plugin then you need not to worry too much this plugin will do the same. )</p>
<blockquote>
<p style="text-align: justify;">&lt;meta content=&#8221;WordPress &lt;?php bloginfo(&#8216;version&#8217;); ?&gt;&#8221; /&gt;</p>
</blockquote>
<ul style="text-align: justify;">
<li>Now you must lock your Login Page to make sure no one unauthorised person will login into system. Need not to worry you can check this plugin : <a target="_blank" href="http://bad-neighborhood.blogsblogsblogs.com/2007/08/29/login-lockdown-a-new-wordpress-security-plugin/" target="_blank"><strong>Login LockDown</strong></a> . This will block your login page if any one try to hack for certain bad attempt.
<p><div id="attachment_66" class="wp-caption alignnone" style="width: 300px">
	<img class="size-full wp-image-66" title="Login LockDown WordPress Security Plugin" src="http://www.jaydip.info/wp-content/lockdown.jpg" alt="Login LockDown WordPress Security Plugin" width="300" height="213" />
	<p class="wp-caption-text">Login LockDown WordPress Security Plugin</p>
</div></li>
</ul>
<ul style="text-align: justify;">
<li>Now finally you want to implement multiple level of security then you must look at <strong><a target="_blank" href="http://wordpress.org/extend/plugins/askapache-password-protect/" target="_blank">AskApache Password Protect </a></strong> &#8220;This plugin doesn&#8217;t control WordPress or mess with your database, instead it utilizes fast, tried-and-true built-in Security features to add multiple layers of security to your blog. This plugin is specifically designed and regularly updated specifically to stop automated and unskilled attackers attempts to exploit vulnerabilities on your blog resulting in a hacked site. &#8221;   (This will work if you are using Apache Server)</li>
</ul>
<p style="text-align: justify;">This will provide your blog to more security and more reliability so that you can focus more on your work and feel protected.</p>
<p style="text-align: justify;">Check Official Update from WordPress Blog : <a target="_blank" href="http://wordpress.org/development/2009/09/keep-wordpress-secure/" target="_blank">How to Keep WordPress Secure</a></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
 <!-- RSPEAK_STOP --><img src="http://www.jaydip.info/?ak_action=api_record_view&id=64&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.jaydip.info/secure-your-blog-from-unauthorised-access-make-your-blog-more-safe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
