Breaking WordPress

15
Breaking WordPress
  • date post

    13-Sep-2014
  • Category

    Technology

  • view

    738
  • download

    0

description

A Brief overview of WordPress and common security issues. Talks about hosting, commen WordPress infection types and features resources to help keep WordPress secure.

Transcript of Breaking WordPress

Page 1: Breaking WordPress

Breaking WordPress

Page 2: Breaking WordPress

#WHOISDAVIDYARDE

•AKA Batman

•Co-founder @ Sevenality

•Twitter: @dsmy

Page 3: Breaking WordPress

The Web is HUGE!!!There are over 1.8 Billion active websites on the

web.

• 43% of the top 1 million websites are hosted in USA itself.

• 48% of the top 100 blogs/websites run on WordPress.

• 672 Exabytes - 672,000,000,000 Gigabytes (GB) of accessible data.

Page 4: Breaking WordPress

Today’s Challenges

•Administration

•Credentials

•End-users aka wildcards

•Education

Page 5: Breaking WordPress

•Core

•Themes*

•Plugins*

•End-users*

Today’s Problem*

Page 6: Breaking WordPress

Implications of a Hacked Site

•SEO rankings wrecked

•Loss of customer trust

•Visitors exposed to malware

•Hours of time wasted assessing & repairing damage

•Loss of sales/money

Page 7: Breaking WordPress

Types of Attacks

OpportunisticOpportunistic TargetedTargeted

•Web Trolls•Ability for mass exposure•Timthumb

•Big Enterprises•Wordpress.com•Woothemes•Usually worth the time and

energy invested to compromise•Done for bigger returns

Page 8: Breaking WordPress

Top 5 WordPress Infections•Backdoors

•Difficult to detect via http

•Good time to start crying

•Pharma Attacks

•Owners usually detect

•Now shamefully selling viagra or some other drug

• Injections

•Think fake Anti-virus downloads

•Defacements

•You’re now supporting a rebel army

•Malicious Redirects

Page 9: Breaking WordPress

Know Your Environment

•What kind of security does your host use?

•What will they do if your site gets hacked?

•Will they fix it?

•Will they shut it down?

Page 10: Breaking WordPress

If server management isn’t your thing, use a managed solution.

Page 11: Breaking WordPress

• WP Engine - http://wpengine.com/

• Flywheel - http://getflywheel.com/

• MediaTemple - http://mediatemple.net/

• GoDaddy - http://www.godaddy.com/

Managed WP Hosting Providers

Page 12: Breaking WordPress

HELP!! Everything is broken and I’ve been blacklisted!!!

•Don’t panic.

•Detect

•Remove

•Protect

•Submit

Page 13: Breaking WordPress

Recommended Resources• WP Security Checklist - http://wpsecuritychecklist.com

• Clef - https://getclef.com

• iThemes Security(Better WP Security) - http://ithemes.com/security

• WP Security Lock - http://wpsecuritylock.com

• VaultPress - https://vaultpress.com

• ManageWP - https://managewp.com

Page 14: Breaking WordPress

“An ounce of prevention is worth a pound of cure.”- Benjamin Franklin

Page 15: Breaking WordPress

Thank You

•David Yarde

•Co-founder @ Sevenality

•Twitter: @dsmy

•Email: [email protected]