Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
WordPress 3 Ultimate Security

You're reading from   WordPress 3 Ultimate Security WordPress is for everyone and so is this brilliant book on making your site impenetrable to hackers. This jargon-lite guide covers everything from stopping content scrapers to understanding disaster recovery.

Arrow left icon
Product type Paperback
Published in Jun 2011
Publisher Packt
ISBN-13 9781849512107
Length 408 pages
Edition 1st Edition
Languages
Concepts
Arrow right icon
Toc

Table of Contents (23) Chapters Close

WordPress 3 Ultimate Security
Credits
About the Author
Acknowledgement
About the Reviewers
www.PacktPub.com
Preface
So What's the Risk? Hack or Be Hacked FREE CHAPTER Securing the Local Box Surf Safe Login Lock-Down 10 Must-Do WordPress Tasks Galvanizing WordPress Containing Content Serving Up Security Solidifying Unmanaged Defense in Depth Plugins for Paranoia Don't Panic! Disaster Recovery Security Policy Essential Reference Index

Diagnosis vs. downtime


Diagnosis can take time. That can mean downtime. With a bunch of possible root causes, what's needed is a flexible fix that allows for the former, while minimizing the latter.

Initial diagnosis weeds out non-hacked hassles such as local issues, server trouble, and third party incompatibilities, typically with plugins. This stage often throws up a simple fix.

If you still have hitches, how to tackle them will vary depending on the symptoms and your level of experience.

Preparing for deep diagnosis is, for most of us, a sensible precautionary step that involves backing up the site, its database, and its logs. It also involves ensuring access to server logs. Other than using this lot for troubleshooting, the backup may be vital if you scrap something by mistake.

There are now two possible avenues of action:

  • Diagnosing with the site in place, correcting issues and possibly re-installing

  • Re-installing WordPress, straight off, then diagnosing from the compromised backup to correct the root cause

There's no right or wrong with either method, which are generally combined anyhow. Ultimately they lead to the same thing, a secure site. It's just that the route to take depends on the kind of problem you have. Chicken and egg? Yup!

Given the theory, let's get practical.

Note

This guide should not necessarily be taken in order.

While the order of play is ultimately safe all round, in practise, it may lead to more downtime than you want or need. This is where experience really helps, judging the necessary diagnostic steps against particular symptoms.

Read this entire appendix and consider your scenario before making any changes.

Crucially, don't panic, dammit! Anxiety leads to mistakes and more grief. Besides, most snags are pretty easily snared. So smile, however wryly!

Backup Backup Backup Backup Backup Backup Backup ... Why not?

You should backup the files, the database, and logs before making any changes.

Even if you have a recent backup—in which case, don't overwrite it, it is more likely uninfected—you may need something or the other. And if on-site diagnostics don't shimmy out the problem, you can later re-address the infected backup to help corner the underlying issue.

There are a host of backup strategies in Chapter 6 , by the way, just for you.

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image