{"id":11331,"date":"2011-01-05T17:56:09","date_gmt":"2011-01-05T17:56:09","guid":{"rendered":"http:\/\/alexsuze.com\/?p=11331"},"modified":"2011-01-06T09:12:32","modified_gmt":"2011-01-06T09:12:32","slug":"keeping-your-sex-blog-safe-%e2%80%93-securing-your-wordpress-blog-part-2","status":"publish","type":"post","link":"https:\/\/alexsuze.com\/?p=11331","title":{"rendered":"Keeping Your Sex Blog Safe \u2013 Securing Your WordPress Blog Part 2"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"alignleft\" style=\"margin: 5px;\" title=\"Arse\" src=\"\/images\/golden-arse.jpg\" alt=\"Arse\" width=\"300\" height=\"300\" \/><a title=\"Securing Your WordPress Blog Part\" href=\"http:\/\/alexsuze.com\/?p=11315\" target=\"_blank\">Please read Part 1 of this article first<\/a>.<\/p>\n<p>Most importantly take note of this disclaimer which applies to all parts of this particular article.<\/p>\n<p>DISCLAIMER: This information is provided in good faith and without warranty of any kind. I cannot be responsible for any detrimental effects any of these changes may have on your site\/blog\/domain because all server, WordPress and domain setups are different. If you are unsure as to what you are doing, don\u2019t go any further, STOP! And ask an expert \u2013 e.g. tame techy or your hosting provider\u2019s helpdesk. Furthermore if you do decide to make some or all of the changes to your WordPress blog\/server then <strong>DO A COMPLETE BACKUP FIRST! <\/strong>Only when you are sure you have a copy of your site\u2019s files and data should you continue. Finally, making these changes will not guarantee that you are 100% safe against hackers, nothing can do that. Keep an eye on your site, take very regular backups and keep your software up to date.<\/p>\n<p>If you\u2019ve <a title=\"Securing Your WordPress Blog Part\" href=\"http:\/\/alexsuze.com\/?p=11315\" target=\"_blank\">followed the instructions in Part 1<\/a> you\u2019ll have a WordPress setup that\u2019s as lean and as up-to-date as it can be. Underlying that is the server and its configuration, plus your user IDs and passwords.<\/p>\n<p>All of the following actions have the potential to stop your blog working in some way so make a full file and database backup beforehand and make one change at a time, checking that everything seems to be working OK after each change. That way if something goes wrong you know what caused the problem.<\/p>\n<ol>\n<li>General system security \u2013 don\u2019t use dictionary words in you passwords for FTP or WordPress. Instead use hard passwords which include numbers, upper and lowercase letters and special characters such as $%^&amp;*()-@ etc. Those passwords are much harder for humans and automated cracking programs to hack. Yes, they are a pain to remember but the inconvenience is worth it. Don\u2019t ever tell anyone your password, no matter who they are. Change all your WordPress and FTP passwords to these strong passwords now. Note them down and keep them somewhere secure. A lot of people will tell you never to write them down but hey, who\u2019s going to remember a password like yU7*(f$^6h ? Oh, make your passwords at least 10 characters long too.<\/li>\n<li>Get rid of all unnecessary users from your WordPress installation. Create a new administrator called anything other than \u201cadmin\u201d, \u201cAdministrator\u201d or \u201droot\u201d and give this user a strong password plus full administrator privileges. If you don\u2019t know how to do this refer to WordPress help.<br \/>\nWhen and, only when you are happy that you have  a working alternative admin account on your WordPress blog you should delete the \u201cadmin\u201d user. Yes, that\u2019s right. So long as you have checked that the new admin user is able to log in and have full access to your WordPress Blog you don\u2019t need the \u201cadmin\u201d user \u2013 it\u2019s the first account hackers will try to attack. If it isn\u2019t there they can\u2019t hack it \ud83d\ude42<\/li>\n<li>Set your wp-config.php files access permissions to 750. They are usually set by default to 644, this isn\u2019t a good idea because 644 allows any user logged in to the server to read the database password and user from the file. You\u2019ll need to use your hosting package\u2019s cPanel or an FTP client to do this \u2013 they\u2019re all different so refer to the help provided by the host\/software vendor on how to set file permissions.<\/li>\n<li>You can stop hackers finding out what version of WP you have (and therefore exploiting any known vulnerabilities in that version) by adding this line to the functions.php of your template:\n<p>remove_action(&#8216;wp_head&#8217;, &#8216;wp_generator&#8217;);<\/p>\n<p>Potentially this can break your template unless you add it in the right place. If you insert it as the second line of your functions.php, immediately after the opening &lt;?php you should be OK but if in doubt seek advice first!<\/li>\n<li>Add the following line to the end of your robots.txt (in the root folder of your site):Disallow: \/wp-*This tells crawlers not to poke around in the WordPress folders. Of course they might not take any notice but do it anyway. Don\u2019t be tempted to disallow your root (\/) folder, if you do your site\u2019s front page will not get crawled by Google and the like. Bad times.<\/li>\n<li>Make regular backups of your blog\u2019s files and folder \u2013 yes I keep saying this but you only realise how important this is when you haven\u2019t backed up and something goes wrong. Very bad times.<\/li>\n<li>Watch out  for strange activity on your blog. Contact your host\u2019s helpdesk if weird stuff starts to happen.<\/li>\n<\/ol>\n<p>There are other things that you can do to lock the system down but I\u2019ve not mentioned them because they can compromise the features of WordPress or even stop your site working altogether. They are so dependant on how you\u2019ve implemented WordPress that you really do need to get specialist advice before implementing them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Please read Part 1 of this article first. Most importantly take note of this disclaimer which applies to all parts of this particular article. DISCLAIMER: This information is provided in &hellip; <a href=\"https:\/\/alexsuze.com\/?p=11331\" class=\"more-link\">Read More<\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[3],"tags":[2958,2959],"_links":{"self":[{"href":"https:\/\/alexsuze.com\/index.php?rest_route=\/wp\/v2\/posts\/11331"}],"collection":[{"href":"https:\/\/alexsuze.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/alexsuze.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/alexsuze.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/alexsuze.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11331"}],"version-history":[{"count":6,"href":"https:\/\/alexsuze.com\/index.php?rest_route=\/wp\/v2\/posts\/11331\/revisions"}],"predecessor-version":[{"id":11333,"href":"https:\/\/alexsuze.com\/index.php?rest_route=\/wp\/v2\/posts\/11331\/revisions\/11333"}],"wp:attachment":[{"href":"https:\/\/alexsuze.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/alexsuze.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11331"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/alexsuze.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}