Top Banner
WordPress Security Basics Chris Burgess @chrisburgess
34

WordPress Security Basics - Melbourne WordPress User Meetup

Apr 15, 2017

Download

Technology

Chris Burgess
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: WordPress Security Basics - Melbourne WordPress User Meetup

WordPressSecurityBasics

ChrisBurgess@chrisburgess

Page 2: WordPress Security Basics - Melbourne WordPress User Meetup

BadNews

Thereisnosuchthingasabsolutesecurity.Nothingis100%secure.

Page 3: WordPress Security Basics - Melbourne WordPress User Meetup

GoodNews

Therearemanythingswecandotodrasticallyreducetherisks.

Page 4: WordPress Security Basics - Melbourne WordPress User Meetup

Contextiseverything…

Page 5: WordPress Security Basics - Melbourne WordPress User Meetup

“MostsuccessfulWordPresshackattacksaretypicallytheresultof

humanerror,beitaconfigurationerrororfailingtomaintainWordPress,suchaskeepingcoreandallpluginsupto

date,orinstallinginsecurepluginsetc.”-RobertAbela(@robertabela)

Page 6: WordPress Security Basics - Melbourne WordPress User Meetup

Source:http://www.wpwhitesecurity.com/wordpress-security/statistics-highlight-main-source-wordpress-vulnerabilities/

Page 7: WordPress Security Basics - Melbourne WordPress User Meetup

OverviewTakeSecuritySeriouslyUpdatesThemesandPluginsPasswordsBackupsandMaintenanceHardeningWordPressandSSLwillbecoveredinthefollowingpresentations

Page 8: WordPress Security Basics - Melbourne WordPress User Meetup

TakeSecuritySeriously

Page 9: WordPress Security Basics - Melbourne WordPress User Meetup

DefenseinDepth

Page 10: WordPress Security Basics - Melbourne WordPress User Meetup

Source:http://wptavern.com/

Page 11: WordPress Security Basics - Melbourne WordPress User Meetup

KeepWordPressUpdated

Page 12: WordPress Security Basics - Melbourne WordPress User Meetup

Updates

•  “Patchearlyandpatchoften”•  Thisisanothergoodreasontohaveatesting/stagingenvironment

Page 13: WordPress Security Basics - Melbourne WordPress User Meetup
Page 14: WordPress Security Basics - Melbourne WordPress User Meetup

UseReputablePlugins

Page 15: WordPress Security Basics - Melbourne WordPress User Meetup

UseReputableThemes

Page 16: WordPress Security Basics - Melbourne WordPress User Meetup

Trust

Page 17: WordPress Security Basics - Melbourne WordPress User Meetup
Page 18: WordPress Security Basics - Melbourne WordPress User Meetup

TheWeakestLink

Page 19: WordPress Security Basics - Melbourne WordPress User Meetup
Page 20: WordPress Security Basics - Melbourne WordPress User Meetup
Page 21: WordPress Security Basics - Melbourne WordPress User Meetup

PasswordManagement

•  LastPass,1Password,Roboform,KeePass,Dashlane

•  SecretServer,LastPassEnterprise,PassPack•  UseTwo-factorauthenticationwhereverpossible

Page 22: WordPress Security Basics - Melbourne WordPress User Meetup

PerformRegularBackupsandMaintenance

Page 23: WordPress Security Basics - Melbourne WordPress User Meetup

PrepareforProblems

Page 24: WordPress Security Basics - Melbourne WordPress User Meetup
Page 25: WordPress Security Basics - Melbourne WordPress User Meetup

BackupOptions

•  ServerLevelBackups– cPanel/Plesk– Replication– Snapshots

•  BackupServices•  BackupPlugins•  ManualBackups•  Exports

Page 26: WordPress Security Basics - Melbourne WordPress User Meetup

HardeningWordPress

Page 27: WordPress Security Basics - Melbourne WordPress User Meetup

HardeningWordPress

•  Allinoneplugins:Sucuri,Wordfence,iThemesSecurity

•  Oryoucantakeamoremodularapproach,butchoosewisely

•  SecurityServices•  ManualHardening

Page 28: WordPress Security Basics - Melbourne WordPress User Meetup

GoogleSearchConsole(formerlyWebmasterTools)

Page 29: WordPress Security Basics - Melbourne WordPress User Meetup
Page 30: WordPress Security Basics - Melbourne WordPress User Meetup

HowcanIlearnmore?

Page 31: WordPress Security Basics - Melbourne WordPress User Meetup
Page 32: WordPress Security Basics - Melbourne WordPress User Meetup

VerizonDBIR

http://news.verizonenterprise.com/2015/04/2015-data-breach-report-info/

Page 33: WordPress Security Basics - Melbourne WordPress User Meetup

Resources

•  https://wordpress.org/about/security/•  https://wordpress.org/news/category/security/

•  http://codex.wordpress.org/Hardening_WordPress

•  http://codex.wordpress.org/Brute_Force_Attacks#Protect_Your_Server

Page 34: WordPress Security Basics - Melbourne WordPress User Meetup

Thanks!

ChrisBurgess@chrisburgess