RECENT POST
Wordpress for beginners steps by steps
Wordpress for beginners tutorials
Wordpress video tutorials for beginners
Password if have: bestblackhatforum.com

Top Best Themes

Wordpress plugins

Best wordpress plugin

From our Blog

Showing posts with label wordpress security. Show all posts
Showing posts with label wordpress security. Show all posts

Tuesday, 21 April 2015

[GET] All in One SEO Pack Pro 2.3.6.2

Official page: http://semperfiwebdesign.com

Download link: 
Link: http://www41.zippyshare.com/v/yKZzmxFW/file.html

Primary Key: 24Y2493470037207F
Secondary Key: 8KS18354E2608161Y
Note: Remember give a big big reputation (rep+++) .Wish everyone can enjoy use it. ^^

Changelog

version 2.3.7.2 – Released on September 9th, 2015

Updated for WordPress 4.3
New Spanish language translation – Thanks to Fernando Tellado
Bug fixes for issues reported by users in the support forums





Thursday, 12 March 2015

CHMOD safe way to Your WordPress Blog

CHMOD is a website security steps and WordPress PHP generally very good in particular to limit the attacks directed at the source of the website as read sensitive information, create files in the directory.

In this article, I will give some advice CHMOD safe for your website on the host, you can apply for a CHMOD on Shared Host or private servers are.

As you know PHP files for the highest authority is 6 (write and read) should CHMOD standard way for all PHP files on the source website is 644 to WordPress website you can work normally.

Particularly some file wp-config.php sensitive, .htaccess should CHMOD 400 or 404, which is not granted write access to anyone except yourself edit the files directly.



But when CHMOD 404 or 400, each time you install plugins that need repair as .htaccess files, wp-config.php, you have to edit it manually. In turn, if you want to not be so, can CHMOD 600 or 604.

CHMOD safe folder

For directories, the highest authority in addition to 7 for read, write, it also has access. Therefore, CHMOD standards for the folder to your WordPress website works well is 755.

However you can CHMOD the folder wp-admin and wp-include the 705 or 700. But please note that you must update the new WordPress version manually because it can not overwrite the files to. So when using it on CHMOD 705, when the update, please CHMOD 755.

Also, if you want a safer, you can CHMOD wp-admin folder to 101, meaning that not only has read access to write anything.

Epilogue

In this article you will probably be the last to know how safe CHMOD WordPress website then right? And I encourage you to CHMOD as to minimize unnecessary risk from malicious code or some other form of attack.

6 Simple Tips to Secure for Your WordPress Blog

The diversity of forms of attack and exploit the content on WordPress too have a secure website from simple to complex. While the application of the method of WordPress security complex, make sure you've set up your WordPress website more secure because sometimes the setup is very simple clues to the hacker broke into the website.

If you are not sure of their website's security settings or not, check out the tips below, and even if you do not do.
==> 6 Simple Tips to Secure WordPress

1. Do not use the account name "admin"



After many tests and supported many people, I noticed that a lot of people named administrator account with the website name is "admin", "administrator". This indeed is a disastrous mistake.

The use of usernames popular style this insecure world is by now have some form of attack is the Brute Force Attack; means to continuously log on to your website with a list of accounts and passwords available that a hacker has somehow been.

Therefore, the common account as "admin" can easily be found via password Brute Force Attack this form. Once installed, the website should set yourself a real difference username and unpredictable as a "thachdeptrainhatvietnam" for example.

If you have missed taking a username named "admin", do not worry, you can use the plugin WPVN - Username Changer to change directly from the user.

2. Use complex passwords



Like the use of username is "admin", the use of a password is too simple may be susceptible to other forms of attack detection Brute Force Password Attack detected after a certain time.

Ideally, place the password include uppercase letters, numbers and special characters are the best. You do not need to worry too much about not being able to remember this password, you can use software such as LastPass, StickyPassword to save passwords and automatically log on to the next.

Tips: Use Strong Password Generator to generate strong passwords.

3. Update the plugin, theme, WordPress to the latest version



One piece of advice that is also very important to regularly update the version of the plugin, WordPress and the theme you are using on the website to the latest version. So probably older versions exist some pink hole "fatal" to the timely update you will avoid the risk of it.

The updated plugin, WordPress version is extremely simple, that's when it will have the new version announced and displayed on the website, in which selected it automatically updated to the new version before.

4. Use the host quality



If you are using the normal host services (Shared Host) it is important to use the host at suppliers to ensure the most.

Because Shared Host packages are located on the same server, but just one website in the collective website on servers infected with malicious code, the website will also have the risk of intrusion in the form of Local Attack .

Therefore, you should choose the services that host the prestigious sending instead of using the vendor at the user, has not been verified.

References: 7 Shared Services Host Best WordPress.

5. Stay away from the null - piracy

Products null they are saying here is that products such as premium paid plugins, premium themes are shared widely publicized in some specialized website to share these items.

You must know that the use of premium products that are not only share such serious violations of the rights issue, you are directly put her closer to malware.

A study has shown that the majority of the null rampant on the Internet today are malicious, and it may be illegal exploitation of natural resources your host, insert hidden or worse backlink is knocked out.

6. Avoid CHMOD 777

If you only heard CHMOD not quite understand it, but then drill to learn because it is quite lengthy, but I just need to know that you avoid the CHMOD the folder to 777. With 777 decentralized setting, ie you're set that folder with a maximum aperture makes every user on the server has the right to write / delete / executable directory and the files inside, this is the reason for why you are suddenly made website malware is unknown background.

If you use the Shared Host, you should know that the best way to be ready CHMOD 755 for folders, 644 files. For the file wp-config.php sensitive, please CHMOD 444 or 440 or 400.

Epilogue

Above is synthesized 6 tips are important in your time administrator WordPress website to remember to avoid the unfortunate happen, but fortunately are 6 tips on easy implementation.

How to setting Wordfence Security for Your WordPress Blog?

Wordfence is a free plugin for WordPress best, and now it is a free plugin that specializes in security the most widely used.

The reason why it is used so much because with extremely good features that can limit many popular forms of attacks, such as Local Hack, XSS, SQL Injection and password functionality including dual layer auto scan malicious code on the host.

In this article, I will briefly introduce the function and using your Wordfence Security to secure your WordPress website better.



You can use this plugin with iThemes Wordfence Security Security for more specialized firewall.

The whole function of Wordfence Security



Before use, please list your entire functions in Wordfence Security so you know it can be done, although we may not need to use all the functions.

Additional Falcon Engine technology to create a website caching to speed up to 50 times. If you use this function, remove the plugin WP Super Cache cache as, W3 Total Cache.
Compatible with other plugins and themes, such as Woocommerce.
Automatically lock the common attacks. For example, a website that uses Wordfence which was attacked and set them to block the attack, then your website will also block attacks.
Add two layers of password validation code over the phone, like Google account so.
Vulnerability scanning through security error "HeartBleed".
Mandatory other users on the website to use complex passwords.
Automatically scans WordPress source code, plugins and themes to detect malicious code. For the source, it will compare with the source code of WordPress to see if there is a change, it will inform you.
Set up a firewall to block common attacks and spammer users, such as posing as Googlebot.
Automatically lock the attacker was black listed by checking the Advanced IP, check out WHO IS domain.
Subscribe to the change of the file on the host and you can customize the auto repair if the file has changed.
Automatically scan and find some common malicious code such as 99, R57, RootShell, Crystal Shell, Matamu, Cybershell, W4cking, Sniper, Predator, Jackal, Phantasma, GFS, Dive, Dx ... and a lot of other names.
Automatically scan pages on the website to see if paralyzed insert malicious code or not, and check whether the page has been listed on Google blacklisted or not.
Automatically finds and blocks suspicious malware.
Customize limit the bot can gather information website, to avoid being large botnet attack frequency.
Subscribe to real-time counter on your website, website statistics 404, changed and edited to remove content, ...
Subscribe to real-time statistics and visits based on the country.
Check the hard drive of the host information for a variety of DDoS attack will make your hard drive is full.
And some other minor functions.
Set Wordfence Security

I just guided through the main function, you can take the initiative to learn more other functions.
After installing the plugin Wordfence Security, they have taken the initiative to establish the important functions you need for your website to be safe.

You can go Wordfence -> Options and select the Security Level to set it manually, depending on the level, it is best if your website is normal, no one attacked, only select Level 2 only.



Block dangerous country

If your website is Vietnamese should actively blocking some hits from the countries where you do not need them in order to minimize their chance to attack.

To block countries you to Wordfence -> Country Blocking and select some countries you need to stop and then press Save Change.



Some countries should stop:

China
Russia
Israel
Turkey
Iraq
Iran
Germany

As for the remaining features you can actively explore coz it is not too difficult to understand where very own, Falcon Engine Cache function through because I did not say that it's unlikely to work on your website or not ( but I test it all worked well) so you can go to the Wordfence -> Performence to enable this functionality.

I wish you success!

How to config and use iThemes Security on your Wordpress Blog?

How to config and use iThemes Security?

Download the plugin



Find and install the plugin iThemes Security

Immediately after the installation is complete, Secure Your Site Now button to start the setup.

Then you just need to click on the two options as in the picture and the Dismiss button to finish.

Sau that you move through the Settings tab and begin exploring its options.



There are sections Go to the navigation bar, when you select each part of the window that will lead you to the area corresponding to set. Let's look at the options at the bottom of the Security iThemes offline.

The basic options iThemes Security

Global Settings

This section contains the basic settings for iThemes Security.

Write to File - This option allows other plugins automatically add content to wp-config.php and .htaccess file, you can select it to install other features of iThemes Security or plugin created cache automatically.

Email Notification --mail address to receive notifications related to iThemes Security plugin, you can add multiple email separated by a line.

Delivery Email Backup - backup file to receive e-mail address if you backup data by iThemes Securtity.

Host Lockout Message - Message error message to the log failed due to blocked IP.
User Lockout Message - Message error message if a member is locked.
Blacklist Repeat Offender - Activate using spam address list public. You should choose because it will help you get rid of the spammers on this list.
Blacklist Threshold - The number of blocked IP will be converted to a permanent lock.
Blacklist Lookback Period - Duration block spammers listed in the Blacklist Repeat Offender.
Lockout Period - The time for each lock if someone tries to log in, but failed.
Lockout White List - List of IP is not locked.
Lockout Email Notifications - Receive email notification when someone locked.
Log Type - Recording the activity log of the plugin, choose the Database Only.
Days to Keep Logs Database - The duration of the log records in the database, following the expiration of the log will be deleted.
Path to Log Files - The path of the log file.
Allow Data Tracking - Allows iThemes collect your data used to analyze them.
404 Detection

This is the option to send the message for each member to access a page fault detection and 404. You should consider this option is enabled if your page has too much because it will appeal 404 matches email box you and a lot of resources.

Minutes to Remember 404 Error (Check Period) - The time that the system itself does not remember 404 and reported at a later time.
Error Threshold - The maximum error which each member can see, if the maximum number of members on page 404 in this section will be locked. Usually happens with spam bot.
404 File / Folder White List - The file / folder it will be ignored and no error checking 404.
Away Mode

This is a feature that helps you lock the administration page in the given time, you can only get in a certain period of time. Very useful for website 1 admin and you have the option of locking the admin page when you are sleeping, working example.

Enable away mode - Turn Away Mode.
Type of Restriction - type refuse, if you visit the site each day, select Daily.
Start Time - Time to start "open ports" admin page.
End Time - Time to close the portal admin page.
Banned User

Options allow enable a member of any committee, including spam bot.

Enable HackRepair.com's blacklist feature - Turn Key spam bots list of HackRepair.com.
Enable ban users - Turn locking member (not a member of your WordPress site).
Board Hosts - List of IP will be banned, each IP is a line.
Ban User Agents - Type of User Agents will be banned, applied to the spam bot. You can to Google type in "Bad User Agents list" to get a list and put this option if you wish.
Whitelist Users - IP will not be banned.
Brute Force Protection

This option will help you against Brute Force Attack in the form of restricted logins wrong.

Enable brute force protection - Turn against Brute Force.
Max Login Attempts Per Host - Number of failed log a maximum of IP.
Max Per User Login Attempts - The number of failed log maximum of one member.
Minutes to Remember Bad Login (check period) - The time to remember the login error, if in this time period that exceeds the number of incorrect login attempts allowed, it will be blocked.
See also: What is Brute Force Attack and Prevention.

Database Backup

Optional support automatic database backup. Only turn on if you have a small database for use BackWPUp or BackupBuddy will be much better.

Full Database Backup - Backup the entire database.
Backup Method - The method backup, it will be sent via email or backup copies stored on the host or 2.
Backup Location - Links folder containing the backup file.
Backups to Retain - The backup file will be retained on the host. For example, if you put it if it is 5 more than 5, it will automatically delete the oldest backup file.
Compress Backup Files - Support compressed backup file.
Exclude Tables - The table in the database you do not want to backup.
Schedule Database Backups - Enable automatic backup.
Interval Backup - Automatically backup after a certain number of days.
File Change Detection

Features notice if there is something in the host file is altered, usually to detect the insertion shell files. But just in time to turn to because it requires resources.

Enable File Change detection - Enable detect file changes.
Scanning File Split - Split the section of code to check the turn instead of once, saves resources.
Include / Exclude Files and Folders - Option to remove or include files to detect.
Files and Folders List - a list of files / folders that you want to exclude / include to scan.
Ignore File Types - The file formats that it will be ignored.
Email File Change Notifications - Enable notification via email.
Hide Login Area

Enable change log path instead of / wp-admin same.

Login Slug - Slug path logged in, if you write the address is dangnhap your sign looks example.com/dangnhap.
Register Slug - Slug path register.
Enable Theme Compatibility - Optional automatic compatible theme.
Theme Compatibility Slug - Path 404 error.
Secure Socket Layer

This feature is applicable to our SSL if your website has SSL certificate. If you do not have SSL, most if not fault the original website.

Front End SSL Mode - Enable SSL for the website.
SSL for Login - Enable SSL for login system on the website.
SSL for Dashboard - Enable SSL for Dashboard.
Strong Password

Apply mandatory use complex passwords for security.

Enable strong password enforcement - Enable strong password required.
System Tweaks

These settings will intervene in this system are used to hosting your privacy. Since this is the advanced settings, so do not choose if you do not know what you're doing.

Protect System Files - Secure your important files of WordPress wp-config.php like, .htaccess files, wp-include, Instal ....
Disable Directory Browsing - Do not allow file browse file browser, which means that if you do not have the file directory index, it still does not show a list of files in it.
Request Methods Filter - Filter queries sent through the URL, it will block the query dangerous nature or suspicious.
Suspicious Filter Query Strings in the URL - Filtering and blocking queries dangerous nature on the URL, such as they are trying to access the files in the folder themes, plugins.
Filter Non-English Characters - One way to limit SQL Injection by blocking the query contains strange characters. Should choose.
Long Strings URL Filter - Filter the query is too long, usually in the form of SQL Injection attacker often write queries over a long URL to change the database. Should choose.
Remove File Permissions Writing - Auto CHMOD security for sensitive files, if enabled, the file will be CHMOD to 0444 instead of 0644 as the default.
Disable PHP in Uploads - Do not allow execution of PHP code in upload feature in WordPress to avoid shell membrane up to the host. Should choose.
WordPress Tweaks

These options will intervene in the WordPress source code for security.

Meta Tag Generator WordPress Remove - Delete the default WordPress meta tags themselves born to make hacking difficult to determine the version of WordPress you are using to find the bug.
Remove the Windows Live Writer header - Remove header tags to respond to queries from Windows Live Writer to avoid the form of attacks by taking advantage of this to post files illegally.
Remove the RSD (Really Simple Discovery) header - Remove header card contains xml-rpc header file to avoid the forms of attack by unauthorized taking advantage of the post.
Reduce Comment Spam - Anti-Spam in the comment.
Display Random Version - Automatically displays some random hacker version of WordPress difficult to determine the true version you are using.
Disable File Editor - Not allowed to edit themes, plug-in Dashboard.
Disable login error messages - Off to display the error log hacker is difficult to determine their error or error log.
Force users to choose a unique nickname - Do not use nicknames for members overlap.
Disables a user's author page post count is 0 if spend the weekend - Do not create separate paths author if they have not all.
After the change is done, just press the button Save all Changes.

Advanced

This is the advanced settings, restrict tampering if you fear failure or the best backup the entire database and code before using the tools in here.

Admin User

These changes will affect the website admin account.

Enable Change Admin User - Rename the username of admin.
New Admin Username - The name of the admin login.
Change User ID 1 - Change User ID of admin to avoid detection.
Change Content Directory

Options for how to change the wp-content directory, very dangerous if you used a long website. Should only apply to the new website.

Change Database Prefix

Change of database prefix instead wp_ default, this option will be less likely to error, so you can rest assured that use.

 Epilogue

These are important features that you need to talk through the Security iThemes this plugin. Although the version developed by iThemes launched not long, but according to his assessment, it still works pretty well at the moment and will continue to edit and add quite a lot. Hope for iThemes Security plugin, you will have peace of mind in securing WordPress.

How to install plugin JetPack on Your Wordpress Blog?

In the list of installed plugins needed to, JetPack to say is always the first choice because of the strong and diversified its features. This is one of the most multi-user plugin by Automattic key made. These features are also very much in the JetPack taken from services WordPress.Com so here is the solution for you do want to add that feature to self-host your WordPress website.



JetPack need to connect to wordpress.com, you need to have an account at wordpress.com. And you will not be able to use JetPack on localhost.

The function of JetPack

JetPack plugin is a set of features to improve your blog, but by no means does the function will enable you want to use the pop-up does not it go off so it was not too heavy.

The function of JetPack include:

Manage multiple WordPress sites at once from WordPress.Com service.
Statistics hits per day.
Edit Custom CSS with CSS.
Sign in to your account using wordpress.com website.
Manage authentication with Google Webmaster Tool.
Features related articles.
Write content Markdown language.
Using CDN WordPress.com images via Photon to save bandwidth and speed.
InfiniteScroll - download next article by sliding down the bottom of the website.
Customizable widget display through each different page.
Additional JSON API into the website.
Features Like the article, not the Facebook Like.
Automatically share articles on social networks to Publicize.
Receive notifications related to the operation of the website.
Replace the chassis frame Comment comments JetPack, enable logging by social networking account to comment.
Allow customers to receive new posts via email Subscriptions.
Demonstration of beautiful images with Carousel.
IMPROVED post via email.
Insert the button to share articles on social networks.
Check spelling article.
View more detailed information about Gravatar when mouse over their avatar.
Create a contact form.
Tiled Gallery - create a gallery displaying beautiful images.
Share article linked by short (shortlink) from wp.me.
Particular interface when accessing the website by phone.
Type a mathematical formula.
Additional widgets.
You can see more about the features of JetPack here.

Set JetPack plugin

Installation is as simple JetPack plugin, go to Dashboard -> Plugins -> Add New and search by WordPress.com JetPack plugin name. Then click install and activate.



After activation is complete, press the Connect button in the notification bar to WordPress.com to conduct connect your website with your wordpress.com account.



Login and connect successfully, press Activate Now button to activate.



Make sure that your website must be placed on the host, and not blocked access from the outside. If you can not connect, try contacting your hosting provider or install the plugin Slim JetPack but the feature is not sufficient for much.

Activating the features of JetPack

As I said in the first post, but JetPack is a collection of dozens of functions, but basically you just turn the lever to avoid heavier website. JetPack default settings on it will shut down a number of functions you want to turn up.

To enable the function to be used, you access the Dashboard -> JetPack -> Settings and select the function has not been bold blue background and press Activate.



Done that, now you can start to use the functions you need. Each feature is activated when to have words Configure to set up the press on the page that will each feature set.

Blog Archive

Visitor

 
Copyright © 2013 Wordpress Tips And Trick