MackCollier.com

  • Blog
  • Mack’s Bio
  • Work With Mack
    • See Mack’s Work
  • Buy Think Like a Rock Star
  • Book Mack to Speak

May 5, 2013 by Mack Collier

A Few Simple Tips For Making Your Blog More Secure

J0178041

Go here to let Sucuri scan your blog for free to tell you if you’ve been hacked or have malware.

So over the last few months I had been chasing a nagging malware issue on this blog.  It looks like (knocking on keyboard) it’s finally cleaned out, so I wanted to share what I learned so hopefully you’ll be able to avoid some of the same problems.

First, here’s what I think happened:  It looks like somehow someone got access to the blog, either via stealing a password (doubtful) or exploiting a security hole in an outdated plugin (likely).  Then what they did was they added code to the template and plugins that let traffic be redirected from this blog, to their site.

Here’s what I did to clean it up:

First, I tried to download some security plugins to give me an idea of what had happened.  I added Wordfence, Better WP Security and Bulletproof Security.  What I liked about WordFence is that it scans your WordPress and plugin files and will tell you if any have been changed and will show you the exact changes that were made.  Better WP Security gives you a nice checklist of options you can take to make your blog more secure.  Plus, it gives you the ability to ban users that repeatedly try to login to your blog or access security holes in the setup.  Bulletproof Security has a few additional options and honestly I have it more as a ‘it can’t hurt’ option than anything else.

But the problem was, at best these plugins were alerting me to the fact that there were issues, but couldn’t fix them all.  So I ended up paying to get Sucuri’s service for my blog.  Sucuri costs $90 a year for one site/blog, but it was worth it.  They were able to go in and clean up my blog, and then give me tips and ideas on how to keep a re-infection from happening.  The problem was that the issue kept popping back up.  We’d clean the blog up, it would be fine for the next few days, then suddenly the following Friday or Sat, Google would blacklist the blog and we’d start the process all over again.

It turns out that what was happening was someone had access to the blog, and they were going in every Thursday and changing files to have traffic be re-directed to their sites.  This was somehow taking place the following day, and then triggering the Google blacklist.  After it happened about 3 weeks in a row, I finally figured out what was happening, and was able to alert Sucuri as soon as the files were changed on a Thursday, and they cleaned it up within a few hours and we never saw the blacklist from Google.

Also, I noticed that one of WordPress’ core files had been modified, Sucuri changed that back.  I went in and changed my WordPress password, and in two weekends since, there have been zero problems and no files have been changed.  So it seems that the problem, at least for now, is gone.

So if you want to avoid this headache, here’s some simple tips:

  • Create strong passwords for your blog, including numbers and letters.  It’s best to mix in upper and lower case letters, plus a few special characters as well.
  • Update WordPress and all your Plugins as SOON as the updates are available.  I learned this the hard way, but often plugins are updated simply to close an existing security hole.  Before I *hated* updating plugins and would often wait till I had several that needed updating before I would.  Never again.
  • If you have a user as ‘admin’ then delete it.  That’s the user account that hackers target the most.

BTW, if you install the above plugins you can see how often hackers try to access your blog and it happens CONSTANTLY.  One of the settings I have is I get an email if someone makes 10 bad attempts to sign into my blog.  They are banned and then I get an email saying they were banned.  I get 5-10 of these emails EVERY DAY.  Seriously, it’s scary stuff to see how often bad people will try to access your blog and look for any security hole they can find, so you have to be proactive about protecting yourself.

We’ll have more ideas for keeping your blog secure tonight at #Blogchat, so please check in and let’s learn from each other!  See you at 8pm Central!

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to email a link to a friend (Opens in new window) Email
  • Click to share on Reddit (Opens in new window) Reddit

Like this:

Like Loading...

Related


Discover more from MackCollier.com

Subscribe to get the latest posts sent to your email.

Filed Under: #Blogchat

About Mack Collier

My name is Mack Collier and I am a digital marketing and content strategist located in Alabama. Since 2006 I've helped companies of all sizes from startups to global brands such as Adobe, Dell and Ingersoll-Rand, create customer-centric programs, content and experiences. A long-time internet geek, I've been online since 1988 and began using social networking sites in 1991 when I joined Prodigy. Today, I help companies understand how new technologies like web3, crypto and artificial intelligence can integrate with existing marketing strategies to lead to exceptional customer experiences.

Comments

  1. Linda Bernstein says

    May 5, 2013 at 8:00 pm

    Good info, Mack. Thanks you.

  2. Shawn Wright says

    May 6, 2013 at 6:36 am

    I wrote a post at marketcloud.us about the same thing. I chose Better WP Security and it has served me well. I enjoy receiving notices that someone has been locked out for too many attempts at my various web sites. The most piece important piece of the puzzle for me for me is Backup Buddy. If something does get through it’s a relatively easy fix.

    • Mack Collier says

      May 6, 2013 at 8:40 am

      Hi Shawn, Linda was also evangelizing Backup Buddy last night during #blogchat. She said it was $75 a year. I am going to check into it as well. Thanks to you both!

  3. Joel says

    May 6, 2013 at 12:20 pm

    Yep, keeping your plugins updated is key. Also, the difficult to crack password will help. I use http://random.pw to help generate strong and memorable passwords on the fly. It also has a Javascript-powered password strength checker which can help you discover how weak your password is. Thanks!

  4. Egypt & Jordan Tours says

    May 8, 2013 at 1:28 am

    I make a blog in blogger. but i can’t find any security or protect the content plugins or anything else. but my faith is fully to blogger because it’s google product. if you want to secure your blog..then keep build strong password for it and change it simultaneously.

  5. Madiha Durrani says

    March 4, 2014 at 11:17 am

    Really great post, just started follow your blog/site. Glad I did

Recent Posts

  • Understanding Substack’s Three Growth Stages
  • Blogging Isn’t Dead, it’s Morphed Into Substack
  • The Backstage Pass is Moving to Substack
  • Easter and the Three Eternal Gifts God Gives to Christians
  • Research: 97% of Loyalty Programs Fail Due to This Simple Design Flaw

Categories

Archives

Comment Policy

Be nice, be considerate, be friendly. Any comment that I feel doesn't meet these simple rules can and probably will be deleted.

Top Posts & Pages

  • The Difference Between a Brand Ambassador and a Brand 'Spokesperson'
  • I Do Not Deserve to Suffer Like This...
  • Understanding Substack's Three Growth Stages
  • Case Study: Patagonia’s Brand Ambassador Program Focuses on Product Design and Development Over Sales
  • How Much Money Will You Make From Writing a Book?
  • Let's Take a Closer Look at Patagonia's Worn Wear Road Tour
  • Why Did Jesus Send His Apostles Out With Nothing?
  • The introvert's guide to speaking
  • New research proves that RESPONDING to negative feedback online benefits companies
  • Blogging Isn't Dead, it's Morphed Into Substack

  • Blog
  • Mack’s Bio
  • Work With Mack
  • Buy Think Like a Rock Star
  • Book Mack to Speak

Copyright © 2025 · Executive Pro Theme on Genesis Framework · WordPress · Log in

%d