Security Basics mailing list archives

Re: What is the threat on WordPress User


From: Matti Oinas <matti.oinas () gmail com>
Date: Thu, 16 Aug 2012 21:52:56 +0300

Hi,

Securing wordpress is a bit more difficult than solving every unsolved problem in mathematics and physics. If registration is only for comments then I would suggest looking for octopress which generates static files for transfer to server so there is no dynamic code running on server and comments can be brought in using external services. Octopress has some ready plugins for different services.

- Matti

On 08/16/2012 02:16 PM, Gautam wrote:
HI,

I am building a small WordPress blog, i think i have done all that is
required from security point of view however recently i notice that
there some of fake user registration.

They are not many since i have captcha enabled and auto registration
using some scripts or bot is not possible. May be 2 or 3 a day, and
most of them are from PRC :-)

I want to know does anyone here thinks this is something i need to
keep a watch on, something like a early warning sign.




------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: