webinar: how i can hack your wordpress website in 5 minutes featuring dre armeda of sucuri security

16
Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security Real Security for WordPress Life, Liberty, and the Pursuit of Risk Reduction

Upload: pam-ann-marketing

Post on 29-Jan-2015

104 views

Category:

Education


0 download

DESCRIPTION

How I Can Hack Your WordPress Website in 5 Minutes Featuring Dre Armeda Wednesday, March 6, 2013 12pm EST / 9am PST Watch Dre perform a LIVE WordPress hack and learn how to avoid one on your site! Ever wonder if your site, your visitors, or business is safe on the internet? This session by Dre Armeda will show a demo on how quickly your site can be hacked, and your reputation put on the line. Dre will cover various scenarios that can affect your website like Pharma Hack, SEO Poisoning, and malicious redirects. He will then aid you by providing some tips to help reduce risk now and forever. Information Security is everyone’s responsibility, and should be a consideration on any web project, beginning to end. Takeaways 1. Better understanding of overall risks to running a website 2. Understand common website attack types 3. How to better approach website security 4. What to do if you or a loved one is attacked/infected 5. Tools to help you get back on track Register here: http://bit.ly/WordPressHackReg Brought to you by Sucuri Security and Pam Ann Marketing.

TRANSCRIPT

Page 1: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Real Security for WordPress

Life, Liberty, and the Pursuit of Risk Reduction

Page 2: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Dre Armeda

CEO, Co-Founder of Sucuri Inc. – sucuri.net

Co-Host of The DradCast – dradcast.com

@dremeda | dre.im

I wear many hats, and love tacos

Harley enthusiast & Chargers fan

Infatuated with WordPress & web security.

I hope hope to make the internet a safer place!

Page 3: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

The Internet Rocks

Over 2 billion internet users today

480% growth in the last 11 years (Internet World Stats)

100k+ domains gained weekly (Global Domain Registry)

2 billion sites in 2015 (Tony Schneider – CEO, Automattic)

With adoption and growth comes innovation!

Page 4: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

It’s Not All Peachy

Malware – short for malicious software: A software designed to disrupt operations, gather information, or

gain unauthorized access.

Monitor your website browsing & internet usage

Forced Advertising

Redirect Affiliate Marketing Revenue

Innovative thinking sparks risk

Page 5: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

How Bad is it?

2 million+ new malware strings monthly (McAfee)

Costs US consumers over $2bil yearly (Consumer Reports)

Google issues 3mil+ warnings daily. (Google)

Google blacklists 10k websites daily on avg. (Google)

Pretty bad, and getting worse.

Page 6: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

How Does This Happen

A new type of webmaster!

Page 7: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Am I At Risk?

The percentage of risk will never be zero!

Ever See a Dodo Bird?

Page 8: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

What Can We do?

Be smart. Be consistent. Cut out the noise!

Page 9: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Cut Out The Noise

Keep Software Updated

No Soup Kitchen Servers

Reduce Access

Password Management

Backup Schedule

K.I.S.S.

Page 10: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Keep Software Updated

Leading cause for infection along with passwords

Scared to upgrade because stuff breaks?

Major vs. Point Release

Run upgrade tests

Do your homework

Information Security is everyone’s responsibility

Page 11: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

No Soup Kitchen Servers

WordPressers act like they forgot about DEV

Cross-contamination is a big deal

Segment by user and account

Not active. Not good enough

If it’s not in use, get rid of it

Production is not your archive server!

Page 12: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Reduce Access

Give people enough access to do their job, nothing more; remove access when they complete their job!

User Proper Roles

This goes for WordPress, FTP, & DB’s, etc.

Limit failed logins to thwart brute force

Practice two form auth & layered login

Least privilege to some, no privilege for most.

Page 13: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Password Management

Password still top 5 actively used password

Use unique passphrases

Use different passwords across accounts

Password Management Tools

Password is a password not to be used as your password, ever!

Page 14: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Backup Schedule

Create a schedule today!

Backup outside of your production environment

Multiple backups are awesome

Talk to your host to see what they offer

Various tools available

When they hack you, reduce downtime.

Page 15: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Tools & Services

Backups

Backup Buddy

VaultPress

Great tools and services to help you reduce risk.

Password ManagementLastPassKeyPass Password Safe1Password

Malware ScanningSucuri SiteCheckUnMask Parasites

Malware CleanupSucuri

Two Form AuthGoogle Authenticator

Limit Failed LoginsLimit Logon AttemptsSucuri (WP Plugin)

Page 16: WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security

Thank You For Listening

No go, reduce risk. Go!