Regina in Rockville, MD asks:
I saw in the news that 90,000 servers were hijacked to attack thousands of WordPress sites earlier this week. My daily blog is done in WordPress and I’m worried that my site will be targeted next. What measures can I take to protect my site?
Diana, I agree with your concern, that level of hacking is a warning to all of us and some are saying the attack last week could be the start of an even bigger assault.
What happened in this situation is that hackers searched through WordPress accounts and attempted to access them by logging in with the username “admin” and 1000 of the most common passwords, a practice known as “brute force”. Since many people use “admin” and very weak passwords such as “password”, “12345” and other obvious ones to access their WordPress sites, it wasn’t a very difficult task for these criminals to break into so many sites.
After a user’s system is compromised through an accessed WordPress site, the system is incorporated into a botnet, which is a collection of Internet computers that are instructed by their controller to forward transmissions (including spam or viruses) to other computers on the Internet. The botnet spreads the attack even wider and the results can be catastrophic.
To protect your WordPress site against this kind of attack, here are a few steps you should take:
1. Create a unique and complex password, you can find some advice on that subject in our Password Protection Pointers blog
2. If you never changed ‘admin’ as the username to access your blog, change that immediately. Like your password, your username should also be unique and complex.
3. Make sure your WordPress software is updated and that you are running the most current version.
4. Activate two-step authentication on WordPress. Two Step Authentication is a feature WordPress recently introduced and it works like this: when you log in to your WordPress.com account, you will be prompted to enter a secret number. To get this number, you download the Google Authenticator App on your smartphone. It generates a new number every 30 seconds. Open the app on your phone, type in the number it’s showing and you are authenticated.
5. Use Plugins. If you have WordPress blog plugins, keep those updated and there is a security plugin you can install called Better WP Security
6. Limit access to the admin section of your WordPress site. Hacking does not just happen outside of your company and admin access should be given to a limited number of trusted and careful employees.
7. Make sure the computers you use are free of spyware, malware, and virus infections.
8. Be aware of network vulnerabilities. Keep your firewall updated and secure and reconsider accessing your WordPress account via wifi from an internet café or other public place, where you could be using a network that is not properly secured.
If you feel any part of your technology is vulnerable to hacking, call Teltek IT today! As a full service supporter of business software and hardware, we are fully qualified to evaluate your systems and suggest improvements and upgrades if needed.
Teltek is proud to offer IT services as the fourth component to our multi-systems approach as your single source technology services company. This Managed Service Provider (MSP) offering completes our longstanding goal to provide our clients with a one-call resource for all of their business technology needs. IT outsourcing, remote back up and disaster recovery, helpdesk support, computer network relocations, security products and server/desktop virtualization are just a few of the services now available.
