• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Pro Blog Service

  • Business Blogging
    • Blogging and Content Marketing for Search Engine Optimization (SEO)
    • Social Media Strategy and Consulting
    • Blogging Services
    • Content Factory
    • Need a Law Blog or Legal Blog?
    • Download Our White Paper: Business Blogging: The Cost of Corporate DIY Blogs vs. Ghost Blogger
    • Pro Blog Service Books
  • Blog
  • Speaking
  • About Pro Blog Service
    • Erik Deckers
    • 4 Simple Rules for Guest Posting on Our Blog
  • Get Ghost Blogging Quote
  • Link Sharing/Contributed Articles

October 24, 2013 By Erik Deckers

5 Ways to Protect Your Blog Against Hackers

Every couple of days, I get an email from my blog alerting me that the zombie hackers are at it again. They’re trying to break into my WordPress blog so they can infect it or steal any financial or personal information they find.

But I’ve taken a few steps to limit their access, and if you’ve got a blog, WordPress or otherwise, you should take these five steps to protect yourself from hackers.

1. Change the Admin Account

The default username on all new blogs is “Admin,” which most people never change. That’s what the hackers attacking my blog seem to go after the most. To protect against that, you can do one of two things:

  1. Delete the Admin account. WAIT!! Don’t go do it yet. First, make sure you set up a new admin-level account under a different name. Use a variation of your name instead. Once you do that, then delete the admin account. The hackers’ automated system will keep trying to break into “admin,” even though it’s no longer there.
  2. Change Admin’s role to subscriber-level. Again, you’ll want to have your own admin account first, but by changing the role to that of a subscriber, even if someone gets in, they won’t have the power to add any code or change anything. The best, most thorough option is deleting the Admin account completely.

“Test” is another name I’m seeing a lot of in my email alerts, so don’t set up an admin account with that name.

2. Change your Password

Hopefully you’re no longer doing things like using “password” or your dog’s name as your password. But even if you’re using variations like “p@ssword” or “#enry,” those won’t work either. The hackers are on to our little tricks of substituting @’s for A’s, and so on.

Instead, pick longer multi-word password phrases like “ILeftMyHeartInSanFrancisco” or “ILikeNewYorkInJuneHowAboutYou.” Even though these don’t use the unique symbols we were told to use a few years ago, they’re almost too long to be easily cracked. Another option is to just mash a bunch of keys at random and then store the password in a password vault on your laptop.

3. Delete Subscribers (WordPress)

One trick you can do to reduce comment spam is to only allow subscribers to leave comments. In order to do that, the spammers will have to subscribe to a blog before they leave a spam-laden comment. And since it’s easy to automate, that’s exactly what they do.

However I don’t require commenters to subscribe (more on that in a moment). I let Akismet catch a lot of the comment spam, and let the real humans leave real comments. Instead, I moderate comments, and check over all the comments Akismet let pass before I publish them, because Akismet is 99% accurate. I just have to monitor the other 1% myself.

But even though I don’t require comments, spammers still subscribe to my blog, and I’ll have a couple thousand every few weeks or so. I go through and delete them whenever I have a few free minutes.

Now, the danger is a real commenter may have actually subscribed, and I will — completely unintentionally and accidentally, because I’m not reviewing every single subscriber first — delete them and their comment. This is why I don’t require commenters to subscribe. Otherwise I’d have no comments at all. (So, if you’re a real person and you want to leave a comment, DON’T SUBSCRIBE!)

Note: If you do this, make sure you click the Subscriber link each time you delete a batch. Otherwise you might actually delete yourself or another admin. Also, set the number of records that show on one page to about 350. That’s about as many as you can delete without causing an error.

4. Install Limit Login Attempts Plugin (WordPress)

Limit Login Attempts (LLA) is a great plugin for any WordPress owner. It limits the number of times an IP address can try to log in unsuccessfully before they’re locked out. It lets you set how many unsuccessful attempts you’ll allow before the IP address is locked out, and how long the lockout lasts. Then, if a specific number of lockouts are reached, the IP address is blocked for a specific amount of time.

For example, I have mine set to 3 unsuccessful attempts lead to a 24 hour lockout. 4 lockouts lead to a 96 hour block. I’ve also set LLA to email me after there are 4 lockouts. Most of these attempts have synced up over the past several months, so I get a new round of emails every 4 days (today was the day, which made me decide to write this post).

5. Install WP-Ban Plugin (WordPress)

If you do find an IP address that’s managed to guess your user name, or see one that continues to try to log in a few dozen times, it may only be a matter of time before they get in. (If nothing else, the one that’s tried a few dozen times is a bot that just keeps knocking on the door, coming back whenever it can to see if they’re unlocked). To fight this, I installed the WP-Ban plugin on my WordPress blog, as well as those of my clients, and I use it to block IP addresses that are most persistent.

Unfortunately, it’s a Sisyphean task, since the IP addresses are constantly changing. I always block the IP addresses that manage to figure out my user name, and I block the ones that have been hit with a 96 hour lockout more than 3 times. I can find that out by looking at the IP addresses that were blocked by the LLA plugin, because it shows the user name they tried and the number of attempts. There are a couple of IP addresses that have seen the Ban message 1,811 and 1,421 times, so it is worth it to ban them.

Blog security is an ongoing issue. For every hack they find, we find a solution. For every solution we find, they find a workaround. This day, these are the five things I rely on to prevent hacking into my blog. What other solutions do you use? Do you have any tricks? What about for non-WordPress blogs? Leave a comment and let me know what works well for you.

(Hat tip to good friend Lorraine Ball and Roundpeg for originally writing about this topic in April.)

Photo credit: Dark Dwarf (Flickr, Creative Commons)

Sorry, no related content found.

Filed Under: Blogging, Tools Tagged With: business blogging

About Erik Deckers

Erik Deckers is the President of Pro Blog Service, a content marketing and social media marketing agency He co-authored four social media books, including No Bullshit Social Media with Jason Falls (2011, Que Biz-Tech), and Branding Yourself with Kyle Lacy (3rd ed., 2017, Que Biz-Tech), and The Owned Media Doctrine (2013, Archway Publishing). Erik has written a weekly newspaper humor column for 10 papers around Indiana since 1995. He was also the Spring 2016 writer-in-residence at the Jack Kerouac House in Orlando, FL.

Reader Interactions

Comments

  1. John Blue says

    October 24, 2013 at 7:50 pm

    And pay for WordPress hosting on a service that adds extra security monitoring, plugins, and backups, like WPEngine.com.

    • Erik Deckers says

      October 24, 2013 at 10:38 pm

      That’s another important step. There are a few places that do that, but do you have any preferences, John?

Primary Sidebar

Subscribe via RSS

Categories

Tags

advice bloggers blogging blog writing books book writing business blogging citizen journalism content marketing copywriting crisis communication digital marketing Ernest Hemingway Facebook freelance writing ghost blogging ghostwriting Google grammar Jason Falls journalism language Linkedin marketing media networking newspapers No Bullshit Social Media personal branding public relations public speaking punctuation ROI SEO Social Media social media experts social media marketing social networking storytelling traditional media Twitter video writers writing writing skills

Archives

Recent Posts

  • 11 Tips for New Digital Nomads
  • 13 Things to Do or Not to Do When Connecting With Me for the First Time
  • Why You Need to Write Your Memoir
  • How to Give a 6-Minute Presentation at 1 Million Cups
  • Conduct Informational Interviews to Land Your Next Job

Footer

BUY ERIK DECKERS’ LATEST BOOK

Erik Deckers' and Kyle Lacy's book - Branding Yourself now available at Amazon

Request a Quote – It’s easy

We write blog posts, manage social media campaigns, write online press releases, write monthly news letters and can write your website content.

Let's figure out the right package for you.

FREE 17 Advanced Secrets to Improve Your Writing ebook

Download our new ebook, 17 Advanced Secrets to Improve Your Writing

Erik recently presented at the Blogging For Business webinar, and shared his presentation "12 Content Marketing Secrets from the Giants of Fiction.

If you attended the event (or even if you didn't!), you can get a free copy of his new ebook on professional-level secrets to make your writing better than the competition.

You can download a copy of free ebook here.

© Copyright 2020 Professional Blog Service, LLC.

All rights reserved. Use of this site indicates your consent to our Privacy Policy and Terms of Use.

1485 Oviedo Mall Boulevard Oviedo, FL 32765
Call us at (317) 674-3745 Contact Us About