<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Running A Website &#187; passwords</title>
	<atom:link href="http://www.runningawebsite.com/tag/passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.runningawebsite.com</link>
	<description>Practical tips and advice for running a successful website!</description>
	<lastBuildDate>Thu, 07 Oct 2010 10:20:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Recent Hack Attempt on my Blog</title>
		<link>http://www.runningawebsite.com/recent-hack-attempt-on-my-blog/</link>
		<comments>http://www.runningawebsite.com/recent-hack-attempt-on-my-blog/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 16:58:19 +0000</pubDate>
		<dc:creator>Dan Harrison</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[backups]]></category>
		<category><![CDATA[hack attempt]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Wordpress security]]></category>

		<guid isPermaLink="false">http://www.danharrison.co.uk/?p=476</guid>
		<description><![CDATA[Yup, at the weekend, the DanHarrison.co.uk site was compromised by an Algerian &#8216;hacking&#8217; team. However, despite good security practices, the site still got hacked. I followed the most basic rules, such as keeping all plugins and the main WordPress install up-to-date, as well as strong passwords. And I still got hacked. Just to be clear, ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.runningawebsite.com%2Frecent-hack-attempt-on-my-blog%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.runningawebsite.com%2Frecent-hack-attempt-on-my-blog%2F&amp;source=DanJHarrison&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.runningawebsite.com/wp-content/uploads/2009/09/padlock.jpg"><img src="http://www.runningawebsite.com/wp-content/uploads/2009/09/padlock.jpg" alt="padlock" title="padlock" width="400" height="267" class="aligncenter size-full wp-image-477" /></a></p>
<p>Yup, at the weekend, the DanHarrison.co.uk site was compromised by an Algerian &#8216;hacking&#8217; team. However, despite good security practices, the site still got hacked. I followed the most basic rules, such as keeping all plugins and the main WordPress install up-to-date, as well as strong passwords. And I <strong>still</strong> got hacked.<span id="more-476"></span></p>
<p>Just to be clear, these are the basic security principles I always abide by:</p>
<ul>
<li>WordPress installation is always up to date.</li>
<li>All plugins are updated pretty much as soon as they are updated.</li>
<li>All database, ftp and account passwords are long and random (digits, characters, symbols, etc). </li>
<li>No password is used for any other site I own</li>
<li>File permissions are set at the most strict &#8211; depending on what&#8217;s required.</li>
<li>I keep regular file and database backups. All automated to backup every single day.</li>
</ul>
<p>However, despite all of that, I was still hacked. I am working my way through <a href="http://www.jtpratt.com/series/wordpress-security-guide/">JT Pratt&#8217;s security guide</a> as a basis for making the site more secure. Essentially I&#8217;m locking down everything I can. However, with having many websites, I want to automate it as much as possible to save me time. <em>Just before you ask, someone I know with 0 plugins still got hacked.</em></p>
<p>There&#8217;s a high chance of getting hacked at some point because you&#8217;re running a dynamic website. However, doing everything you can to make it too much effort for a hacker is a very good idea. And if nothing else, make sure you <strong>regularly backup your website</strong>!</p>
<h3>Updates</h3>
<p>Here are some more useful security articles I&#8217;ve since discovered:</p>
<ul>
<li><a href="http://www.wolf-howl.com/seo/wordpress-seo-security/">WordPress Security Tips</a> (more plugin ideas and advice)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.runningawebsite.com/recent-hack-attempt-on-my-blog/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
	</channel>
</rss>

