6 ways to prevent wordpress brute force attacks - wordpress security

18
6 WAYS To Prevent WordPress BRUTE FORCE ATTACKS RIGHT NOW

Upload: honest-online-solutions

Post on 09-Jun-2015

895 views

Category:

Technology


2 download

DESCRIPTION

Protect yourself from WordPress brute force attacks in under 10 minutes. Slideshow by Mike Hulleman Twitter: @contact_mike Permalink: www.gethonest.ca/wordpress-bf �

TRANSCRIPT

Page 1: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

6 WAYSTo Prevent WordPress

BRUTE FORCE ATTACKSRIGHT NOW

Page 2: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

A PUBLIC NOTICEHackers are reportedly utilizing over 90,000 servers to compromise WordPress websites’ administrator panels by exploiting hosts with “admin” as account name, and weak passwords which are being

resolved through brute force attack methods.

- Original release date: April 15, 2013

Honest Online | gethonest.ca

Page 3: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

A PUBLIC NOTICEYou can find out more from the United States

Computer Emergency Readiness Team Shortcut: www.gethonest.ca/cert

Honest Online | gethonest.ca

Page 4: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

STEP ONE

Honest Online | gethonest.ca

Page 5: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Back up your website

You can do this with WordPress plugins or your web hosting control panel;

If you’re not sure how, don’t hesitate to ask your website company or hosting provider for assistance

Honest Online | gethonest.ca

Page 6: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

STEP TWO

Honest Online | gethonest.ca

Page 7: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Add a new userManage your WordPress website from a user profile with a unique

login name

Honest Online | gethonest.ca

Page 8: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Delete the “admin” user profile, or demote it to subscriber

Honest Online | gethonest.ca

Add a new user

Page 9: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

STEP THREE

Honest Online | gethonest.ca

Page 10: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Update WordPress & its plugins

Confirm with your website company that this will not negatively impact

any website customizations

Honest Online | gethonest.ca

Page 11: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

STEP FOUR

Honest Online | gethonest.ca

Page 12: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Install WordPress security plugins

Login Lockdown, WP Login Security 2, Limit Login Attempts and others will block

brute force attacks by limiting the permitted number of failed login attempts

Honest Online | gethonest.ca

Page 13: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Install WordPress security plugins

You can also change your standard WordPress login URL with plugins such as Better WP Security, Pretty

Login URLs, Aspexi Easy Login URL; For safety, consult your web company to ensure these plugins will not conflict with any website

customizations

Honest Online | gethonest.ca

Page 14: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

STEP FIVE

Honest Online | gethonest.ca

Page 15: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Password protect access to your WP-Login page

Most web hosting companies have the option for password protected directories in their Control Panel;

If you need help, consult your website hosting provider or website design company

Honest Online | gethonest.ca

Page 16: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

STEP SIX

Honest Online | gethonest.ca

Page 17: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

Google Authenticator

If you’re still not satisfied with the previously mentioned options,

try this plugin for two-factor authentication www.gethonest.ca/twofactor

Honest Online | gethonest.ca

Page 18: 6 Ways to Prevent WordPress Brute Force Attacks - WordPress Security

A Message From Honest Online

Slideshow brought to you by

Michael HullemanTwitter: @contact_mike

Email: [email protected]

You can find this slideshow atwww.gethonest.ca/wordpress-bf

Honest Online | gethonest.ca