Make Safe your Wp-admin from defacer!

Discussion in 'WordPress' started by hadie87, Aug 25, 2010.

  1. #1
    hI GUYS,
    Yesterday i have chat with my friend (he is defacer) and he look some sample a blog that he has defaced. And i ask to him, How to make safe wp-admin (wordpress) from defacer?
    and he give me question like this.
    1. Make a file with name .httaccess
    2. put this code and .httaccess

    <Files ~ "(\.php.?|\.pl|\.cgi)$">
    order deny,allow
    deny from all
    allow from [B]xxx[/B].
    allow from [B]xxx[/B].
    </Files>
    Code (markup):
    Change xxx. with your IP that you mostly use to access your wp-admin

    3. Upload you file in to root/wp-admin/

    Finish.

    If you not sure with this tips, you can suggest your friend (with other IP address) to open your wp-admin.

    regard

    hadie:)
     
    hadie87, Aug 25, 2010 IP
  2. WallaceYeung

    WallaceYeung Notable Member

    Messages:
    3,377
    Likes Received:
    164
    Best Answers:
    0
    Trophy Points:
    230
    Digital Goods:
    1
    #2
    WallaceYeung, Aug 26, 2010 IP
  3. hadie87

    hadie87 Guest

    Messages:
    87
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    thanks for wallaceYeung. Your methode is very Completed. and now i really understand how to make safe my Wordpress :D
     
    hadie87, Aug 26, 2010 IP
  4. WallaceYeung

    WallaceYeung Notable Member

    Messages:
    3,377
    Likes Received:
    164
    Best Answers:
    0
    Trophy Points:
    230
    Digital Goods:
    1
    #4
    it's great if you find this post useful for you.
     
    WallaceYeung, Aug 26, 2010 IP
  5. psharma

    psharma Prominent Member

    Messages:
    1,955
    Likes Received:
    85
    Best Answers:
    4
    Trophy Points:
    345
    #5
    Yes, these must cover most of the security attacks.
     
    psharma, Aug 26, 2010 IP
  6. RECEP

    RECEP Well-Known Member

    Messages:
    1,855
    Likes Received:
    23
    Best Answers:
    0
    Trophy Points:
    195
    #6
    thanks nice idea
     
    RECEP, Sep 2, 2010 IP
  7. hadie87

    hadie87 Guest

    Messages:
    87
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Hemm, i have try this trick for all my blog.:D
     
    hadie87, Sep 4, 2010 IP
  8. simonok

    simonok Peon

    Messages:
    4
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #8
    This idea will only allow your ip address to access the wp-admin folder, if you have the same ip address or don't post from another location then its fine. However its not fine if you post from different locations. There is a plugin called login lockdown that is good.
     
    simonok, Sep 4, 2010 IP