SlideShare une entreprise Scribd logo
1  sur  16
Real Security for WordPress
                 Life, Liberty, and the Pursuit of Risk Reduction




Real Security for WordPress   Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Dre Armeda



                                              CEO, Co-Founder of Sucuri Inc. – sucuri.net
                                               Co-Host of The DradCast – dradcast.com

                                                          @dremeda | dre.im

                                                     I wear many hats, and love tacos
                                                     Harley enthusiast & Chargers fan
                                                Infatuated with WordPress & web security.
                                             I hope hope to make the internet a safer place!




Real Security for WordPress   Dre Armeda   @dremeda       Sucuri.net     @sucuri_security
The Internet Rocks
                  With adoption and growth comes innovation!



                 Over 2 billion internet users today
           480% growth in the last 11 years (Internet World Stats)
           100k+ domains gained weekly (Global Domain Registry)
            2 billion sites in 2015 (Tony Schneider – CEO, Automattic)




Real Security for WordPress     Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
It’s Not All Peachy
                              Innovative thinking sparks risk



 Malware – short for malicious software: A software
designed to disrupt operations, gather information, or
             gain unauthorized access.

        Monitor your website browsing & internet usage
                      Forced Advertising
             Redirect Affiliate Marketing Revenue


Real Security for WordPress       Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
How Bad is it?
                              Pretty bad, and getting worse.



       2 million+ new malware strings monthly (McAfee)
     Costs US consumers over $2bil yearly (Consumer Reports)
         Google issues 3mil+ warnings daily. (Google)
     Google blacklists 10k websites daily on avg. (Google)




Real Security for WordPress      Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
How Does This Happen
                              A new type of webmaster!




Real Security for WordPress    Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Am I At Risk?
                              Ever See a Dodo Bird?




   The percentage of risk
     will never be zero!


Real Security for WordPress   Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
What Can We do?
                     Be smart. Be consistent. Cut out the noise!




Real Security for WordPress     Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Cut Out The Noise
                                              K.I.S.S.



                                Keep Software Updated
                               No Soup Kitchen Servers
                                   Reduce Access
                                Password Management
                                  Backup Schedule




Real Security for WordPress      Dre Armeda       @dremeda   Sucuri.net   @sucuri_security
Keep Software Updated
                Information Security is everyone’s responsibility



      Leading cause for infection along with passwords
          Scared to upgrade because stuff breaks?
                  Major vs. Point Release
                     Run upgrade tests
                     Do your homework




Real Security for WordPress   Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
No Soup Kitchen Servers
                        Production is not your archive server!



            WordPressers act like they forgot about DEV
                Cross-contamination is a big deal
                  Segment by user and account
                  Not active. Not good enough


             If it’s not in use, get rid of it

Real Security for WordPress    Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Reduce Access
                  Least privilege to some, no privilege for most.



  Give people enough access to do their job, nothing
  more; remove access when they complete their job!

                          User Proper Roles
              This goes for WordPress, FTP, & DB’s, etc.
               Limit failed logins to thwart brute force
                Practice two form auth & layered login


Real Security for WordPress    Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Password Management
    Password is a password not to be used as your password, ever!



            Password still top 5 actively used password
                      Use unique passphrases
             Use different passwords across accounts
                   Password Management Tools




Real Security for WordPress   Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Backup Schedule
                       When they hack you, reduce downtime.



                    Create a schedule today!
        Backup outside of your production environment
                Multiple backups are awesome
            Talk to your host to see what they offer
                     Various tools available




Real Security for WordPress    Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Tools & Services
                Great tools and services to help you reduce risk.

Backups                        Password Management              Malware Scanning
  Backup Buddy                    LastPass                        Sucuri SiteCheck
  VaultPress                      KeyPass Password                UnMask Parasites
                                  Safe
                                  1Password

Malware Cleanup                Two Form Auth                  Limit Failed Logins
  Sucuri                         Google                          Limit Logon
                                 Authenticator                   Attempts
                                                                 Sucuri (WP
                                                                 Plugin)




Real Security for WordPress    Dre Armeda   @dremeda   Sucuri.net   @sucuri_security
Thank You For Listening
                              No go, reduce risk. Go!




Real Security for WordPress   Dre Armeda   @dremeda     Sucuri.net   @sucuri_security

Contenu connexe

Dernier

Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Jisc
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...JhezDiaz1
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxMULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxAnupkumar Sharma
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONHumphrey A Beña
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptxmary850239
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPCeline George
 
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfAMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfphamnguyenenglishnb
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Barangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptxBarangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptxCarlos105
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designMIPLM
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...Nguyen Thanh Tu Collection
 
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdfLike-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdfMr Bounab Samir
 
Roles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in PharmacovigilanceRoles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in PharmacovigilanceSamikshaHamane
 

Dernier (20)

Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxMULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx
 
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdfTataKelola dan KamSiber Kecerdasan Buatan v022.pdf
TataKelola dan KamSiber Kecerdasan Buatan v022.pdf
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERP
 
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptxFINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
FINALS_OF_LEFT_ON_C'N_EL_DORADO_2024.pptx
 
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdfAMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
AMERICAN LANGUAGE HUB_Level2_Student'sBook_Answerkey.pdf
 
Raw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptxRaw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptx
 
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptxYOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
 
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptxLEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
 
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Kamla Market (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
Barangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptxBarangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptx
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-design
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
 
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdfLike-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
Like-prefer-love -hate+verb+ing & silent letters & citizenship text.pdf
 
Roles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in PharmacovigilanceRoles & Responsibilities in Pharmacovigilance
Roles & Responsibilities in Pharmacovigilance
 
OS-operating systems- ch04 (Threads) ...
OS-operating systems- ch04 (Threads) ...OS-operating systems- ch04 (Threads) ...
OS-operating systems- ch04 (Threads) ...
 

En vedette

Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 

En vedette (20)

Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 

WEBINAR: How I Can Hack Your WordPress Website in 5 Minutes featuring Dre Armeda of Sucuri Security

  • 1. Real Security for WordPress Life, Liberty, and the Pursuit of Risk Reduction Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 2. Dre Armeda CEO, Co-Founder of Sucuri Inc. – sucuri.net Co-Host of The DradCast – dradcast.com @dremeda | dre.im I wear many hats, and love tacos Harley enthusiast & Chargers fan Infatuated with WordPress & web security. I hope hope to make the internet a safer place! Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 3. The Internet Rocks With adoption and growth comes innovation! Over 2 billion internet users today 480% growth in the last 11 years (Internet World Stats) 100k+ domains gained weekly (Global Domain Registry) 2 billion sites in 2015 (Tony Schneider – CEO, Automattic) Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 4. It’s Not All Peachy Innovative thinking sparks risk Malware – short for malicious software: A software designed to disrupt operations, gather information, or gain unauthorized access. Monitor your website browsing & internet usage Forced Advertising Redirect Affiliate Marketing Revenue Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 5. How Bad is it? Pretty bad, and getting worse. 2 million+ new malware strings monthly (McAfee) Costs US consumers over $2bil yearly (Consumer Reports) Google issues 3mil+ warnings daily. (Google) Google blacklists 10k websites daily on avg. (Google) Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 6. How Does This Happen A new type of webmaster! Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 7. Am I At Risk? Ever See a Dodo Bird? The percentage of risk will never be zero! Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 8. What Can We do? Be smart. Be consistent. Cut out the noise! Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 9. Cut Out The Noise K.I.S.S. Keep Software Updated No Soup Kitchen Servers Reduce Access Password Management Backup Schedule Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 10. Keep Software Updated Information Security is everyone’s responsibility Leading cause for infection along with passwords Scared to upgrade because stuff breaks? Major vs. Point Release Run upgrade tests Do your homework Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 11. No Soup Kitchen Servers Production is not your archive server! WordPressers act like they forgot about DEV Cross-contamination is a big deal Segment by user and account Not active. Not good enough If it’s not in use, get rid of it Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 12. Reduce Access Least privilege to some, no privilege for most. Give people enough access to do their job, nothing more; remove access when they complete their job! User Proper Roles This goes for WordPress, FTP, & DB’s, etc. Limit failed logins to thwart brute force Practice two form auth & layered login Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 13. Password Management Password is a password not to be used as your password, ever! Password still top 5 actively used password Use unique passphrases Use different passwords across accounts Password Management Tools Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 14. Backup Schedule When they hack you, reduce downtime. Create a schedule today! Backup outside of your production environment Multiple backups are awesome Talk to your host to see what they offer Various tools available Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 15. Tools & Services Great tools and services to help you reduce risk. Backups Password Management Malware Scanning Backup Buddy LastPass Sucuri SiteCheck VaultPress KeyPass Password UnMask Parasites Safe 1Password Malware Cleanup Two Form Auth Limit Failed Logins Sucuri Google Limit Logon Authenticator Attempts Sucuri (WP Plugin) Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security
  • 16. Thank You For Listening No go, reduce risk. Go! Real Security for WordPress Dre Armeda @dremeda Sucuri.net @sucuri_security