It’s no secret that there’s a constant threat from the loser hacker types for anyone that has a presence online. As security increases, the cyber-thugs try to improve their methods to make sure they can remain a nuisance.

On WordPress sites, the most common threat is the hacker editing your theme files and inserting their spam links.

Know If You’ve Been Hacked

Unless you specifically look at the code of your site, you may not even know that you’ve been hit. If you look at the HTML of the header and footer, and see any links that look suspicious, there’s a good chance that a hacker has been there. Many times they’ll insert links related to pharmacy/drug sites, credit card offers, insurance or refinancing/loan offers.

Looking at the Links

I use the FireFox browser, and it’s quickly becoming the browser of choice for many users. If you use FF, you can look at the links that are currently active by clicking ‘Tools’, ‘Page Info’, and finally ‘Links’.

You’ll then see the current outgoing links links listed. You should also take a look at all theme files and WordPress core files. Look for anything that appears suspicious. If you know absolutely nothing about code, you can compare it to another site, possibly a fresh WordPress installation, and see if there appears to be anything out of the ordinary.

Fixing the Problems

‘An ounce of prevention’ definitely applies here. Keeping your WordPress installation, including the theme and all plugins updated is the first step in maintaining the safest site possible. The ‘automatic updates’ feature of version 2.5 of WordPress is a Godsend. One click and your plugins are updated to the latest and greatest.

You can also secure the site further by disabling the navigation of directories on the entire site. This will prevent users from seeing what plugins that you have installed, and keep prying eyes away from other sensitive data. This can be done by adding the following to your .htaccess file (located in the root directory). This is a simple text file that was probably created when WordPress was installed (if not present).

OPTIONS -INDEXES

Also, you can secure the ‘WP-Admin’ folder by allowing access by only certain IP addresses (yours).

Insert the following, again, into your .htaccess file :

AuthUserFile /dev/null
AuthGroupFile /dev/null
AuthName "Example Access Control"
AuthType Basic
<LIMIT GET>
order deny,allow
deny from all
allow from xx.xx.xx.xx
allow from xx.xx.xxx.xx
</LIMIT>

Lastly, some people will delete the ‘theme-editor.php’ file from the ‘WP-Admin’ folder, if they can’t limit access to the ‘WP-Admin’ folder to only certain IP Addresses. It should also mentioned that, as with any secure site, you should periodically change your password…and DON’T USE ANY COMMON WORDS OR PHRASES THAT CAN BE GUESSED!!

Comments No Comments »

Well, I’ve just been called back to work after a layoff of over (4) months. I haven’t posted in a couple of days due to the sudden lack of free time. I do plan on keeping the blog updated as often as possible though.

Read the rest of this entry »

Comments No Comments »

Effective landing pages drive billions in online sales each year. In fact, they’re one of the best weapons in the savvy affiliate marketer’s arsenal. It doesn’t matter if you’re promoting books, home gyms, or exotic cars. Your landing pages are either making you money or wasting your time. But, the high-volume affiliates know

Read the rest of this entry »

Comments No Comments »

Pay-per-click (PPC) marketing is one of the quickest, most potent ways to promote affiliate products. If you can learn to control its power, you can create a six-figure affiliate income for yourself. Grab a pad and pen because we’re going to give you 10 PPC tips that you can use immediately to make more money promoting other people’s products.

Read the rest of this entry »

Comments No Comments »

As you know, there are several ways you can make a full-time income as an affiliate marketer. The key is getting the attention of the people who want whatever you’re selling. Some affiliates use pay-per-click marketing. Others use search engine optimization (SEO). In each case, there are affiliates who are making an

Read the rest of this entry »

Comments No Comments »

I was just roaming around, bouncing from one site to another, mostly looking at the Affiliate Marketing/SEO type stuff. As much as I’d like to be a major player in the field, in all honesty I’m still learning myself. I guess if you get to the point that you no longer feel like you’re still learning, it’s time to hang it up though.

Read the rest of this entry »

Comments No Comments »

Even though I’m probably online as much or more than most people, I always seem to be behind most in getting acquainted with the latest and greatest on the Internet. I’ve seen all the hype surrounding twitter and I

Read the rest of this entry »

Comments No Comments »

FireStats icon Powered by FireStats