StudioPress Community Forums
  StudioPress Community Forums > Forums > General Discussion
For help and support, access to your downloads, or to manage your account please log into My StudioPress.

These forums have been set to read-only so you can browse the existing topics for any questions you may have.

For general discussion on WordPress, CSS and design (NOT for support) visit the new Community Forums.
 
 
Thread Tools Display Modes
  #1  
Old 06-18-2012, 09:21 AM
ebizwildfire's Avatar
ebizwildfire ebizwildfire is offline
Registered User
GenesisConnect
Pro Plus Member
 
Join Date: Nov 2008
Posts: 339
Default Question about Site / Server Security

Greetings,

The other day my entire server was hacked and all 27 of my sites had a black screen with a green skull and crossbones, and a note letting me know I had been hacked. Acckkkk!

Thank goodness, my host provider was able to help me restore my sites.

I am in the process of a huge event and hundreds of people are coming to my site every day. My host provider helped me install plugins to help speed up page views and reduce throttling.

MY QUESTION IS: What else can I do to protect my site and protect access to my hosting account.

Since they got into ALL of my sites at once, it seems that they access more than just my wordpress site.

Please help me protect my site as I'm sure this information will be useful for other forum members as well.

With MUCH appreciation,
D'vorah
__________________
D'vorah Lansky, M.Ed.
Author of Connect, Communicate, and Profit
http://ConnectCommunicateProfit.com
  #2  
Old 06-18-2012, 02:10 PM
BrianLis's Avatar
BrianLis BrianLis is offline
Community Leader
 
Join Date: Feb 2009
Location: Chicago
Posts: 1,003
Default

D'vora,
Sorry you had that awful experience. I'd only say that WordPress is getting hacked more often because WordPress is so popular. Over 70+ million sites run WP.
http://en.wordpress.com/stats/

You have two options.
1. Secure your WP sites. There's a number of things you can do harden your WP site. Typically site get hacked by bots/computers looking for weakness. Usually a few tweaks can make a big difference.

2. Back up your site. I back up my sites to a 3rd party server. That way if my entire server crashes I have a back up in another location. And should a hacker get past #1, I can restore my site from back up and change all my credentials.

Unfortunately, securing your website beyond what WP & Genesis offer in addition to backing up your site are usually premium services. I can do both for you if interested. You can PM me. Otherwise you can Google solutions for both and you should be able to learn about both and make the changes yourself if your knowable with code.
__________________
Genesis Specialist. Contact me to convert your theme.

Proud StudioPress Mod & Preferred Customizer
Automattic - WordPress Code Poet Consultant
Design | Twitter | LinkedIn

Featured Story Plugin
  #3  
Old 06-21-2012, 11:23 AM
jp2112's Avatar
jp2112 jp2112 is offline
Registered User
Genesis Member
 
Join Date: Sep 2011
Location: NYC
Posts: 492
Default

I do a few things:
  • Regularly check my site with Sucuri
  • Use Bad Behavior plugin
  • Keep WordPress and all plugins up to date, as soon as updates are available
  • Check for timthumb vulnerability
  • Make regular backups of posts/pages and theme files
  • Make sure folder permissions are 755 or less (more restrictive)
__________________
When asking for help, kindly:
1) Read the FAQ.
2) Post your URL.
3) Use [php][/php] tags when posting programming code,
or [html][/html] when posting website source code.
  #4  
Old 06-21-2012, 11:30 AM
jp2112's Avatar
jp2112 jp2112 is offline
Registered User
Genesis Member
 
Join Date: Sep 2011
Location: NYC
Posts: 492
Default

Also, do you have access to your .htaccess file? There are some things you can do there to help secure your site.
__________________
When asking for help, kindly:
1) Read the FAQ.
2) Post your URL.
3) Use [php][/php] tags when posting programming code,
or [html][/html] when posting website source code.
  #5  
Old 11-04-2012, 05:29 AM
BrianLis's Avatar
BrianLis BrianLis is offline
Community Leader
 
Join Date: Feb 2009
Location: Chicago
Posts: 1,003
Default

JP had some good ideas there as starting places. Still you'll most likely need pro help to clean a site in most cases. I'm going to close this thread. Open a new one if there are more questions.
__________________
Genesis Specialist. Contact me to convert your theme.

Proud StudioPress Mod & Preferred Customizer
Automattic - WordPress Code Poet Consultant
Design | Twitter | LinkedIn

Featured Story Plugin
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Wordpress Security question Steve@316 General Discussion 2 03-13-2012 06:08 PM
Host UK site on US server Philip Gledhill General Discussion 12 01-04-2012 03:41 AM
Will changing the name of your site folder on your server screw up your site? HealthyVoyager General Discussion 3 05-20-2010 11:22 AM


All times are GMT -5. The time now is 11:52 PM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.