Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
WordPress 3 Ultimate Security

You're reading from   WordPress 3 Ultimate Security WordPress is for everyone and so is this brilliant book on making your site impenetrable to hackers. This jargon-lite guide covers everything from stopping content scrapers to understanding disaster recovery.

Arrow left icon
Product type Paperback
Published in Jun 2011
Publisher Packt
ISBN-13 9781849512107
Length 408 pages
Edition 1st Edition
Languages
Concepts
Arrow right icon
Toc

Table of Contents (23) Chapters Close

WordPress 3 Ultimate Security
Credits
About the Author
Acknowledgement
About the Reviewers
www.PacktPub.com
Preface
So What's the Risk? Hack or Be Hacked FREE CHAPTER Securing the Local Box Surf Safe Login Lock-Down 10 Must-Do WordPress Tasks Galvanizing WordPress Containing Content Serving Up Security Solidifying Unmanaged Defense in Depth Plugins for Paranoia Don't Panic! Disaster Recovery Security Policy Essential Reference Index

Pruning hidden users


On the Dashboard's Users page, scan your privileged users for suspect additions. Maybe there's a new Administrator, else an additional Editor, and so on. Delete those, but be aware that, sometimes, this check isn't thorough enough.

The foolproof method is to pop open your database, say again with phpMyAdmin and, substituting the three mentions of the wp_ prefix for any bespoke prefix you may have, run this query from the SQL panel:

SELECT u.ID, u.user_login
FROM wp_usermeta m, wp_users u
WHERE m.meta_key = 'wp_user_level'
AND m.meta_value = 10
AND m.user_id = u.ID

By clicking on Go, your Administrators are listed if, as is the case here, that role is specified with the value of 10 in AND m.meta_value = 10. Repeat the process for Editors with a value of 7 or, for Authors, using 2. For the record, Contributors have a value of 1 and Subscribers, doubtless without prejudice, get a big fat 0:

Here, we've got two Administrators with ur-d00med-m8 looking decidedly shady. We can see that the user has an ID of 9 so, again by clicking through the SQL tab in the menu, we run the query we see in the screenshot:

Bear in mind that, if a hacker got this far, there could easily be a backdoor somewhere in your files and, while the Exploit Scanner may have thrown that or those up, it would be prudent to wipe and replace the web files. Talking of which, here's the big stuff ...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image