[aklug] Re: WordPress Hack

From: Royce Williams <royce@tycho.org>
Date: Mon Feb 08 2016 - 13:00:37 AKST

I also highly recommend Bulletproof:

https://wordpress.org/plugins/bulletproof-security/

It's pretty soup-to-nuts and has a sane wizard. Gotta remember to rerun
its configurer thingie after every upgrade of the plugin, but pretty solid
in my experience.

Also recommend that you configure the minor point-release automatic
background updates (and echoing the "assuming no extreme customization"
caveat from Steve). Very nice to know that your site has upgraded itself
automatically when the Exploit-of-the-Week hits the street.

Royce

On Mon, Feb 8, 2016 at 12:48 PM, Steven Johnson <stevejzoo@gmail.com> wrote:

> The standard advice is to update Wordpress core and all the plugins...
> which may help if the updates won't break your site due to incompatibility
> of heavily customized themes or plugins.
>
> The non-free Wordfence plugin, from Wordfence.com, is mentioned frequently
> in the Wordpress and Librarians group (Facebook). There is no charge for
> the basic plugin. A key for premium services--remote scanning of the site
> for malware-- costs up to $5/month.
>
>
> Steve
> --
> Steve Johnson
> stevejzoo@gmail.com
>
>
> On Mon, Feb 8, 2016 at 11:52 AM, Bill Bouterse <bill@bouterse.com> wrote:
>
>> For those of us who MAY have a WodrPress site does anyone
>> have any suggestions?
>>
>>
>> http://arstechnica.com/security/2016/02/mysterious-spike-in-wordpress-hacks-silently-delivers-ransomware-to-visitors/
>>
>
>
>
> --
> Steve Johnson
> stevejzoo@gmail.com
>

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Mon Feb 8 11:19:15 2016

This archive was generated by hypermail 2.1.8 : Mon Feb 08 2016 - 11:19:15 AKST