• Hey guys,
    What are some things I can do to secure my blog from hackers? I have my blog set up so that you must register to comment on any of my pages. Yet, I had a comment from an unregistered person. How could somebody comment on something when I have it set specifically for registered users? Are there any plugins or things I can do to help with the security of my blog?

Viewing 7 replies - 1 through 7 (of 7 total)
  • Moderator t-p

    (@t-p)

    It could also be trackback/pingback.

    you can disable trackback/pingback in the dashboard – settings. Also, where you create/edit posts or pages in admin.

    I find these two plugins pretty effective when it comes to spam:

    http://wordpress.org/plugins/cookies-for-comments/
    http://wordpress.org/plugins/zero-spam/

    Also have a read of this: http://codex.wordpress.org/Hardening_WordPress

    Thread Starter ace2307

    (@ace2307)

    Thanks Tara.

    Moderator t-p

    (@t-p)

    You are welcome 🙂

    Thread Starter ace2307

    (@ace2307)

    Would you recommend disabling trackback/pingback?

    Moderator t-p

    (@t-p)

    yes. I keep them disabled on my blog. They generaly generally contribute to spam.

    Thread Starter ace2307

    (@ace2307)

    Strictly out of curiosity, what would the advantages be keeping them enabled?

    Moderator bcworkz

    (@bcworkz)

    what would the advantages be keeping them enabled?

    That’s actually a good question. Track and Pingbacks would be a cool feature if it were not for spammers. They foster interlinking of related articles, so that anytime anyone references something you write, that reference can automatically become a comment in your post. This enables readers to follow links to related posts and notifies you when someone is talking about your post. It’s all good, until spammers enter the picture.

    The same feature can be used to post spam links to bogus pages pitching all the crap that spammers pitch, completely unrelated to your post and actually not even referencing your post, not that you would want a reference from a spammer anyway. Trackbacks in particular are ridiculously easy to spoof. Pingbacks can also be spoofed, though it takes more work. WordPress actually gives track and pingbacks less scrutiny than normal comments, making them an attractive vehicle for spammers.

    Unless you’re willing to actively stay on top of spam coming in this way, you are better off disabling the feature. Spammers ruin things for everyone.

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Help with security’ is closed to new replies.