Your Website Security is Important:

Recently, we discovered something which has been affecting WordPress sites, and we wanted to share it with you.

Many businesses who upgraded to WordPress 3.8 noticed that some of the menus in the wp-admin section weren’t working. The flyouts – when you mouse over the menu – is supposed to pop open and show the options under the menu –  but for many WordPress users this isn’t happening.

It’s not a big issue, but more like an annoying issue as you would have to click on the top menu item to show the submenus, and by then you’ve already clicked on the top item so it takes you to that instead of the sub item you wanted.  As I say, just a lot of extra clicking which you could do without!

Web Design Devon WordPress Security Service Barnstaple North DevonWhen started digging into this problem which we thought initially was just a bug, or an intended function of the new 3.8 version of WordPress (like Microsoft’s “It’s not a bug, it’s a feature” lol). However, we soon discovered the problem – and it’s not from WordPress 3.8.

We found some talk on the internet about a Base64 code injecting malware that’s been affecting WordPress sites, so on further investigation we that some base64 code had been injected into the index.php files inside the /wp-content/plugins and /wp-content/themes directory. As soon as we removed this, the menus started working again just fine.

So if you are having that same issue with the menus in your new upgrade to WordPress 3.8, chances are you may have some of this base64 code injected into some of those same files on your blog.

Can you fix it?

Yes, to fix it, you can actually delete those files or just edit them to remove the additional code that has been added. If you delete them they should be replaced the next time you update WordPress Website Design Barnstaple DevonWordPress.

A word of warning though, don’t just go off deleting files if you don’t know what you’re doing – get your webmaster to do it! The only files that are affected are the pretty much unused index.php files that reside within the subdirectories of a WordPress installation – not the main files of WordPress.

 

 

WebDesignBarnstapleDevon_DigitalMarketing_LogoHeader 488x69_Orange
Right Click Digital
1 Bridge Chambers
Barnstaple
Devon
EX31 1HB

https://rightclickdigital.co.uk

WordPress Website Design Barnstaple Devon

WordPress websites are currently under attack!

For the past few weeks, there has been an ongoing wide-scale attack on WordPress sites.

This is not isolated event, as the attacks have been ongoing, peaking just a little under a week ago.

*This is affecting everyone with a WordPress site*

So what can you do to protect your site? With just a few simple precautions, you can protect yourself.

To put things in the proper perspective, we first want to inform you about the nature of the attacks. Potential hackers are employing “Brute Force” methods to access WordPress sites.

Once they have gained access to your account, they can then use various hacks to take over or destroy your site.

What is a “Brute Force” attack? Very simply,  it is a way of guessing for valid passwords. It is not a very sophisticated attack, and is not targeting anyone in particular. What makes it dangerous is that it appears that they are employing massive botnets–casting a very wide net so to speak, making no distinction as to what kind of sites or businesses to target.

In response to this, we advis you to take the proper precautions towards making sure that your WordPress site is not affected.

There are some very simple ways to protect yourself which you can actually do yourself:

Change Your Password:

Brute Force attacks are very resource intensive and only have a chance of succeeding if your passwords are not secure. Change your password right after reading this article.

Make sure that it is a secure password, you can use this link to help you generate a secure, strong
password:

http://strongpasswordgenerator.com/

Secure Your Username:

The username is half of the equation – using a common username is effectively giving malicious hackers that part of the equation – making it that much easier for them. If you login to your WordPress dashboard and go to “users” on the left hand navigation – you will be given a list of users.

We never leave the “admin” user as live on our Client sites, but we are aware that people change them after we’ve set everything up. If you see a user called “admin” this is the default user) – you need to change the username immediately.

Roughly 90% of all the successful attempts are done through the “admin” login. So just by making this simple change you are protecting the site.

(Note that when you delete the user “admin” you will be asked if you want to attribute any posts to another user. Simply click the user you wish them to be attributed too. That way, you won’t lose the posts).

Remove any other user that you are not familiar with.

In conclusion:

We would recommend accessing your site as soon as possible to ensure that the username and passwords are secure.

We provide a 5 Point Security Plan, where our Team of WordPress Security Professionals can create multiple layers of security customised for your WordPress website:

  1. Backing up
  2. File Security
  3. Database Security
  4. Secure Settings
  5. Security Plugins

This 5 Point Security Plan involves over 28 separate lock-downs to secure your site against malicious online attacks.

Contact us today or click here for more information on our WordPress Security Service.