Transcript
Page 1: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Real Security for WordPress

Life, Liberty, and the Pursuit of Risk Reduction

Page 2: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Dre Armeda

CEO, Co-Founder of Sucuri Inc. – sucuri.net

Co-Host of The DradCast – dradcast.com

@dremeda | dre.im

I wear many hats, and love tacos

Harley enthusiast & Chargers fan

Infatuated with WordPress & web security.

I hope hope to make the internet a safer place!

Page 3: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

The Internet Rocks

Over 2 billion internet users today

480% growth in the last 11 years (Internet World Stats)

100k+ domains gained weekly (Global Domain Registry)

2 billion sites in 2015 (Tony Schneider – CEO, Automattic)

With adoption and growth comes innovation!

Page 4: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

It’s Not All Peachy

Malware – short for malicious software: A software designed to disrupt operations, gather information, or

gain unauthorized access.

Monitor your website browsing & internet usage

Forced Advertising

Redirect Affiliate Marketing Revenue

Innovative thinking sparks risk

Page 5: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

How Bad is it?

2 million+ new malware strings monthly (McAfee)

Costs US consumers over $2bil yearly (Consumer Reports)

Google issues 3mil+ warnings daily. (Google)

Google blacklists 10k websites daily on avg. (Google)

Pretty bad, and getting worse.

Page 6: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

How Does This Happen

A new type of webmaster!

Page 7: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Am I At Risk?

The percentage of risk will never be zero!

Ever See a Dodo Bird?

Page 8: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

What Can We do?

Be smart. Be consistent. Cut out the noise!

Page 9: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Cut Out The Noise

Keep Software Updated

No Soup Kitchen Servers

Reduce Access

Password Management

Backup Schedule

K.I.S.S.

Page 10: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Keep Software Updated

Leading cause for infection along with passwords

Scared to upgrade because stuff breaks?

Major vs. Point Release

Run upgrade tests

Do your homework

Information Security is everyone’s responsibility

Page 11: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

No Soup Kitchen Servers

WordPressers act like they forgot about DEV

Cross-contamination is a big deal

Segment by user and account

Not active. Not good enough

If it’s not in use, get rid of it

Production is not your archive server!

Page 12: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Reduce Access

Give people enough access to do their job, nothing more; remove access when they complete their job!

User Proper Roles

This goes for WordPress, FTP, & DB’s, etc.

Limit failed logins to thwart brute force

Practice two form auth & layered login

Least privilege to some, no privilege for most.

Page 13: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Password Management

Password still top 5 actively used password

Use unique passphrases

Use different passwords across accounts

Password Management Tools

Password is a password not to be used as your password, ever!

Page 14: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Backup Schedule

Create a schedule today!

Backup outside of your production environment

Multiple backups are awesome

Talk to your host to see what they offer

Various tools available

When they hack you, reduce downtime.

Page 15: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Tools & Services

Backups

Backup Buddy

VaultPress

Great tools and services to help you reduce risk.

Password ManagementLastPassKeyPass Password Safe1Password

Malware ScanningSucuri SiteCheckUnMask Parasites

Malware CleanupSucuri

Two Form AuthGoogle Authenticator

Limit Failed LoginsLimit Logon AttemptsSucuri (WP Plugin)

Page 16: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Thank You For Listening

No go, reduce risk. Go!


Top Related