Breaking WordPress
#WHOISDAVIDYARDE
• AKA Batman
• Co-founder @ Sevenality
• Twitter: @dsmy
The Web is HUGE!!!
There are over 1.8 Billion active websites on the web.
• 43% of the top 1 million websites are hosted in USA itself.
• 48% of the top 100 blogs/websites run on WordPress.
• 672 Exabytes - 672,000,000,000 Gigabytes (GB) of accessible data.
Today’s Challenges
• Administration
• Credentials
• End-users aka wildcards
• Education
• Core
• Themes*
• Plugins*
• End-users*
Today’s Problem*
Implications of a Hacked Site
• SEO rankings wrecked
• Loss of customer trust
• Visitors exposed to malware
• Hours of time wasted assessing & repairing damage
• Loss of sales/money
Types of Attacks
Opportunistic Targeted
• Web Trolls
• Ability for mass exposure
• Timthumb
• Big Enterprises
• Wordpress.com
• Woothemes
• Usually worth the time and energy
invested to compromise
• Done for bigger returns
Top 5 WordPress Infections
• Backdoors
• Difficult to detect via http
• Good time to start crying
• Pharma Attacks
• Owners usually detect
• Now shamefully selling viagra or some other drug
• Injections
• Think fake Anti-virus downloads
• Defacements
• You’re now supporting a rebel army
• Malicious Redirects
Know Your Environment
• What kind of security does your host use?
• What will they do if your site gets hacked?
• Will they fix it?
• Will they shut it down?
If server management isn’t your thing, use a managed
solution.
• WP Engine - http://wpengine.com/
• Flywheel - http://getflywheel.com/
• MediaTemple - http://mediatemple.net/
• GoDaddy - http://www.godaddy.com/
Managed WP Hosting Providers
HELP!! Everything is broken and I’ve been
blacklisted!!!
• Don’t panic.
• Detect
• Remove
• Protect
• Submit
Recommended Resources• WP Security Checklist - http://wpsecuritychecklist.com
• Clef - https://getclef.com
• iThemes Security(Better WP Security) - http://ithemes.com/security
• WP Security Lock - http://wpsecuritylock.com
• VaultPress - https://vaultpress.com
• ManageWP - https://managewp.com
“An ounce of prevention is worth a pound of cure.”
- Benjamin Franklin
Thank You
• David Yarde
• Co-founder @ Sevenality
• Twitter: @dsmy
• Email:
david@sevenality.com

More Related Content

PDF
Identifying a Compromised WordPress Site
KEY
10 Ways to Secure WordPress
PDF
10 Ways to Speed Up and Secure your WP Site
PPTX
Why it's not your host's fault
PDF
Keep Your SIte Secure
PDF
VaultPress: A Plugin for your Backup needs
PDF
WP Super Cache - Topanga WordPress Meetup
PPTX
Stephen Cronin - WordPress and Government
Identifying a Compromised WordPress Site
10 Ways to Secure WordPress
10 Ways to Speed Up and Secure your WP Site
Why it's not your host's fault
Keep Your SIte Secure
VaultPress: A Plugin for your Backup needs
WP Super Cache - Topanga WordPress Meetup
Stephen Cronin - WordPress and Government

Similar to Breaking WordPress (20)

PDF
Security Presentation for Boulder WordPress Meetup
PPTX
WordPress Security and Best Practices
PPTX
Understanding word press security wwc-4-7-17
PPT
Secure All The Things!
PDF
ResellerClub Ctrl+F5 - WordPress Security session
PDF
Your WordPress Site is and is not Hacked - You don't know until you check
PDF
Head Slapping WordPress Security
PPTX
How WordPress Sites Get Hacked
PDF
Beefy WordPress Security Wordcamp 2012 by Tammy Lee
PDF
WordPress Security Presentation
PDF
WordPress Security Essentials
KEY
Higher Order WordPress Security
PDF
Your WordPress Website Is/Not Hacked
PDF
Securing your WordPress powered Website
PPTX
Protect Your WordPress From The Inside Out
PPTX
WordPress Security - WordPress Meetup Copenhagen 2013
PDF
Word camp2011 introwordpresssecurity
PDF
WordPress Security Essentials WordCamp Denver 2012
PDF
WordPress Security from WordCamp NYC 2012
PPTX
How secure is WordPress ?
Security Presentation for Boulder WordPress Meetup
WordPress Security and Best Practices
Understanding word press security wwc-4-7-17
Secure All The Things!
ResellerClub Ctrl+F5 - WordPress Security session
Your WordPress Site is and is not Hacked - You don't know until you check
Head Slapping WordPress Security
How WordPress Sites Get Hacked
Beefy WordPress Security Wordcamp 2012 by Tammy Lee
WordPress Security Presentation
WordPress Security Essentials
Higher Order WordPress Security
Your WordPress Website Is/Not Hacked
Securing your WordPress powered Website
Protect Your WordPress From The Inside Out
WordPress Security - WordPress Meetup Copenhagen 2013
Word camp2011 introwordpresssecurity
WordPress Security Essentials WordCamp Denver 2012
WordPress Security from WordCamp NYC 2012
How secure is WordPress ?
Ad

More from David Yarde (12)

PDF
Lovable Influence and Innovation
PDF
Changemaking Through Design Thinking
PDF
The Art of Working with Non-Developers: PHP World Edition
PDF
The Art of Working with Non-Developers: Finding common ground on the road to ...
PDF
Branding Yourself and Your Business - Building a Brand that can Adapt and Thrive
PDF
Ready. Set. Handoff. - Improving the Project Handoff Experience.
PDF
Managing Project Expectations and Roadblocks
PDF
Designing for WordPress: Using User Experience to tell a Strong Brand Story
PDF
Timeless Branding
PPTX
Branded Content Strategies
PPTX
Minimum Lovable Brands
PDF
Branding for Success
Lovable Influence and Innovation
Changemaking Through Design Thinking
The Art of Working with Non-Developers: PHP World Edition
The Art of Working with Non-Developers: Finding common ground on the road to ...
Branding Yourself and Your Business - Building a Brand that can Adapt and Thrive
Ready. Set. Handoff. - Improving the Project Handoff Experience.
Managing Project Expectations and Roadblocks
Designing for WordPress: Using User Experience to tell a Strong Brand Story
Timeless Branding
Branded Content Strategies
Minimum Lovable Brands
Branding for Success
Ad

Recently uploaded (20)

PDF
Hindi spoken digit analysis for native and non-native speakers
PPTX
Final SEM Unit 1 for mit wpu at pune .pptx
PDF
Five Habits of High-Impact Board Members
PPT
What is a Computer? Input Devices /output devices
PDF
WOOl fibre morphology and structure.pdf for textiles
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
Assigned Numbers - 2025 - Bluetooth® Document
PPTX
O2C Customer Invoices to Receipt V15A.pptx
PDF
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
Taming the Chaos: How to Turn Unstructured Data into Decisions
PDF
A review of recent deep learning applications in wood surface defect identifi...
PPTX
Tartificialntelligence_presentation.pptx
PPTX
Modernising the Digital Integration Hub
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
Hindi spoken digit analysis for native and non-native speakers
Final SEM Unit 1 for mit wpu at pune .pptx
Five Habits of High-Impact Board Members
What is a Computer? Input Devices /output devices
WOOl fibre morphology and structure.pdf for textiles
DP Operators-handbook-extract for the Mautical Institute
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
Assigned Numbers - 2025 - Bluetooth® Document
O2C Customer Invoices to Receipt V15A.pptx
TrustArc Webinar - Click, Consent, Trust: Winning the Privacy Game
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Taming the Chaos: How to Turn Unstructured Data into Decisions
A review of recent deep learning applications in wood surface defect identifi...
Tartificialntelligence_presentation.pptx
Modernising the Digital Integration Hub
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
Univ-Connecticut-ChatGPT-Presentaion.pdf
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor

Breaking WordPress

  • 2. #WHOISDAVIDYARDE • AKA Batman • Co-founder @ Sevenality • Twitter: @dsmy
  • 3. The Web is HUGE!!! There are over 1.8 Billion active websites on the web. • 43% of the top 1 million websites are hosted in USA itself. • 48% of the top 100 blogs/websites run on WordPress. • 672 Exabytes - 672,000,000,000 Gigabytes (GB) of accessible data.
  • 4. Today’s Challenges • Administration • Credentials • End-users aka wildcards • Education
  • 5. • Core • Themes* • Plugins* • End-users* Today’s Problem*
  • 6. Implications of a Hacked Site • SEO rankings wrecked • Loss of customer trust • Visitors exposed to malware • Hours of time wasted assessing & repairing damage • Loss of sales/money
  • 7. Types of Attacks Opportunistic Targeted • Web Trolls • Ability for mass exposure • Timthumb • Big Enterprises • Wordpress.com • Woothemes • Usually worth the time and energy invested to compromise • Done for bigger returns
  • 8. Top 5 WordPress Infections • Backdoors • Difficult to detect via http • Good time to start crying • Pharma Attacks • Owners usually detect • Now shamefully selling viagra or some other drug • Injections • Think fake Anti-virus downloads • Defacements • You’re now supporting a rebel army • Malicious Redirects
  • 9. Know Your Environment • What kind of security does your host use? • What will they do if your site gets hacked? • Will they fix it? • Will they shut it down?
  • 10. If server management isn’t your thing, use a managed solution.
  • 11. • WP Engine - http://wpengine.com/ • Flywheel - http://getflywheel.com/ • MediaTemple - http://mediatemple.net/ • GoDaddy - http://www.godaddy.com/ Managed WP Hosting Providers
  • 12. HELP!! Everything is broken and I’ve been blacklisted!!! • Don’t panic. • Detect • Remove • Protect • Submit
  • 13. Recommended Resources• WP Security Checklist - http://wpsecuritychecklist.com • Clef - https://getclef.com • iThemes Security(Better WP Security) - http://ithemes.com/security • WP Security Lock - http://wpsecuritylock.com • VaultPress - https://vaultpress.com • ManageWP - https://managewp.com
  • 14. “An ounce of prevention is worth a pound of cure.” - Benjamin Franklin
  • 15. Thank You • David Yarde • Co-founder @ Sevenality • Twitter: @dsmy • Email: david@sevenality.com