<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WordPress Pro - WordPress How To Plugins, Themes Usability &#187; Security</title>
	<atom:link href="http://crunchpress.com/category/wordpress/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://crunchpress.com</link>
	<description>Learn How To Use WordPress Like A Pro - WordPress Pro Articles</description>
	<lastBuildDate>Wed, 05 May 2010 16:19:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>How to Protect Your WordPress Blog Content</title>
		<link>http://crunchpress.com/how-to-protect-your-wordpress-blog-content/</link>
		<comments>http://crunchpress.com/how-to-protect-your-wordpress-blog-content/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 11:57:00 +0000</pubDate>
		<dc:creator>Nasir Hayat</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Themes]]></category>
		<category><![CDATA[Blog Protector]]></category>
		<category><![CDATA[Blog Protector Plugin]]></category>
		<category><![CDATA[Protect your content form getting copied]]></category>
		<category><![CDATA[Wp content protection]]></category>

		<guid isPermaLink="false">http://crunchpress.com/?p=526</guid>
		<description><![CDATA[Blog Protector is WordPress plugin, It can protect your valuable blog content as well as images from getting copied. How it does Works: Disable right click on your blog Disable selection of text on your blog Disable dragging of images on your blog so that images can’t be saved using. Disable Microsoft Image Toolbar to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcrunchpress.com%2Fhow-to-protect-your-wordpress-blog-content%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcrunchpress.com%2Fhow-to-protect-your-wordpress-blog-content%2F&amp;source=crunchpress&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="aligncenter size-full wp-image-527" title="web_security1" src="http://crunchpress.com/wp-content/uploads/2010/01/web_security1.jpg" alt="Protect Blog Content, " width="342" height="317" /></p>
<p><strong>Blog Protector</strong> is WordPress plugin, It can protect your valuable blog content as well as images from getting copied.</p>
<h4>How it does Works:</h4>
<ul>
<li><strong>Disable right click</strong> on your blog</li>
<li><strong>Disable selection of text</strong> on your blog</li>
<li><strong>Disable dragging of images</strong> on your blog so that images can’t be saved using.</li>
<li><strong>Disable Microsoft Image Toolbar</strong> to protect images from your blog.</li>
</ul>
<p>Installation:</p>
<p>You must enable the features from options page to protect your blog.</p>
<p>Activated Blog Protector,But Disable Text Selection is not workin.</p>
<p>1) Got To Design Section of your WordPress Admin Panel</p>
<p>2) Click on Theme Editor &amp; Then Select File Footer.php</p>
<p>3) Now insert code  <code>&lt;?php wp_footer();?&gt;</code> exactly before the body ending tag.ie. <code>&lt;/body&gt;</code> tag. &amp; now your blog is Protected.</p>
<p>You can get <strong>Blog Protector plugin</strong> from <a rel="nofollow" href="http://wordpress.org/extend/plugins/blog-protector/" target="_blank">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://crunchpress.com/how-to-protect-your-wordpress-blog-content/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enhance Security of WordPress Blog-5 Best Plugins</title>
		<link>http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/</link>
		<comments>http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 07:17:10 +0000</pubDate>
		<dc:creator>Nasir Hayat</dc:creator>
				<category><![CDATA[Plugins]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[Chap Secure Login]]></category>
		<category><![CDATA[Enhance Security of WordPress]]></category>
		<category><![CDATA[Secure Wordpress]]></category>
		<category><![CDATA[WordPress Protection]]></category>
		<category><![CDATA[WordPress Security]]></category>
		<category><![CDATA[WordPress Security Plugins]]></category>

		<guid isPermaLink="false">http://crunchpress.com/?p=443</guid>
		<description><![CDATA[In order to eliminate hackers attacks, here are some of the best WordPress security plugins which will help you enhance security of WordPress blog. 1. WP Security Scan: WP Security Scan will automatically check some of the major items on our checklist, to enhance security of WordPress blog. but while it reports the issues, it [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcrunchpress.com%2Fenhance-security-of-wordpress-blog-5-best-plugins%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcrunchpress.com%2Fenhance-security-of-wordpress-blog-5-best-plugins%2F&amp;source=crunchpress&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>In order to eliminate hackers attacks, here are some of the <strong>best WordPress security plugins</strong> which will help you enhance security of WordPress blog.</p>
<p><strong>1. WP Security Scan:</strong></p>
<p>WP Security Scan will automatically check some of the major items on our checklist, to enhance security of WordPress blog. but while it reports the issues, it doesn’t give you the ability to make the necessary changes from your WordPress admin. It does have a section for attempting to change the prefix of your wordpress tables,</p>
<p style="text-align: left;"><a rel="attachment wp-att-444" href="http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/wp-security-scan-permissions/"><img class="aligncenter size-full wp-image-444" title="wp-security-scan-permissions" src="http://crunchpress.com/wp-content/uploads/2010/01/wp-security-scan-permissions.jpg" alt="wp-security-scan" width="450" height="246" /></a></p>
<p style="text-align: left;">You can get <strong>WP Security Scan</strong> form <a rel="nofollow" href="http://wordpress.org/extend/plugins/wp-security-scan/" target="_blank">here</a></p>
<p><strong>2. WordPress Exploit Scanner:<span id="more-443"></span></strong></p>
<p>WordPress Exploit Scanner. It basically scans your database entries and site files looking for suspicious lines of codes. On top of that it also looks for suspicious plugins, posts, pages, users and WordPress settings.</p>
<p><a rel="attachment wp-att-445" href="http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/wordpress-exploit-scanner-plugin/"><img class="aligncenter size-medium wp-image-445" title="wordpress-exploit-scanner-plugin" src="http://crunchpress.com/wp-content/uploads/2010/01/wordpress-exploit-scanner-plugin-450x240.jpg" alt="exploit-scanner" width="450" height="240" /></a></p>
<p>You can get <strong>WordPress Exploit Scanner</strong> form <a rel="nofollow" href="http://wordpress.org/extend/plugins/exploit-scanner/" target="_blank">here</a></p>
<p><strong>3. WP Antivirus:</strong></p>
<p>Once installed it will automatically scan your wordpress theme files to make sure they haven’t been hacked or compromised by a virus. It doesn’t do anything else, but it DOES send the admin an email if a “virus” is found in your theme files. You can also run a manual check to check your theme files if you don’t want to enable email notification:</p>
<p><a rel="attachment wp-att-446" href="http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/wp-antivirus/"><img class="aligncenter size-medium wp-image-446" title="wp-antivirus" src="http://crunchpress.com/wp-content/uploads/2010/01/wp-antivirus-450x355.jpg" alt="" width="450" height="355" /></a></p>
<p>You can get <strong>WP Antivirus</strong> form <a rel="nofollow" href="http://wpantivirus.com/" target="_blank">here</a></p>
<p><strong>4. Secure WordPress:</strong></p>
<p>Secure WordPress plugin allow to its user  to enhance security of WordPress blog. It is easy to configure. Secure WordPress actually takes care of some of them by setting options in plugin admin in your dashboard. <a rel="attachment wp-att-447" href="http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/secure-wordpress-plugin/"><img class="aligncenter size-medium wp-image-447" title="secure-wordpress-plugin" src="http://crunchpress.com/wp-content/uploads/2010/01/secure-wordpress-plugin-450x278.jpg" alt="" width="450" height="278" /></a></p>
<p>You can get <strong>Secure WordPress</strong> from <a href="http://wordpress.org/extend/plugins/secure-wordpress/" target="_blank">here</a></p>
<p><strong>5. Chap Secure Login:</strong></p>
<p>Whenever you try to login into your website, you can use this plugin to trasmit your password encrypted. The encryption process is done by the Chap protocol; this is particularly useful when you can&#8217;t use ssl or other kinds of secure protocols. By activating the ChapSecureLogin plugin, the only information transmitted unencrypted is the username; password is hided with a random number (nonce) generated by the session.</p>
<p><a rel="attachment wp-att-448" href="http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/securelogindiagram/"><img class="aligncenter size-medium wp-image-448" title="securelogindiagram" src="http://crunchpress.com/wp-content/uploads/2010/01/securelogindiagram-450x366.gif" alt="" width="450" height="366" /></a></p>
<p>You can get <strong>Chap Secure Login</strong> form <a rel="nofollow" href="http://wordpress.org/extend/plugins/chap-secure-login/" target="_blank">here</a></p>
]]></content:encoded>
			<wfw:commentRss>http://crunchpress.com/enhance-security-of-wordpress-blog-5-best-plugins/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WordPress Security &#8211; Hide Login Error</title>
		<link>http://crunchpress.com/wordpress-security-hide-login-error/</link>
		<comments>http://crunchpress.com/wordpress-security-hide-login-error/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 16:53:05 +0000</pubDate>
		<dc:creator>Nasir Hayat</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tweaks]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[Hide Login Error]]></category>
		<category><![CDATA[WordPress hide login error]]></category>
		<category><![CDATA[WordPress Security]]></category>

		<guid isPermaLink="false">http://crunchpress.com/?p=212</guid>
		<description><![CDATA[Security issue of WordPrss is most important. There is a lot of discussion going about WordPress Security. Is your WordPress secured? Here is a tip that you can apply on your blog. If someone is trying to login into you WordPress blog, but fails, WordPress display a message to let you know what happened. Sure, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcrunchpress.com%2Fwordpress-security-hide-login-error%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcrunchpress.com%2Fwordpress-security-hide-login-error%2F&amp;source=crunchpress&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: left;"><img class="aligncenter size-medium wp-image-213" title="WordPress Security - Hide Login Error " src="http://crunchpress.com/wp-content/uploads/2009/12/security-tips3-450x260.png" alt="WordPress Security - Hide Login Error " width="450" height="260" /><br />
Security issue of WordPrss is most important. There is a lot of discussion going about WordPress Security. Is your WordPress secured? Here is a tip that you can apply on your blog. If someone is trying to login into you WordPress blog, but fails, WordPress display a message to let you know what happened. Sure, it may be useful to you, but it is for sure also useful to potential blog hackers.<br />
To remove theses messages, simply open your theme folder and find functions.php file and paste the following code.</p>
<p style="text-align: center;"><textarea cols="60" rows="2" name="Link To Blog" readonly="readonly">add_filter(&#8216;login_errors&#8217;,create_function(&#8216;$a&#8217;, &#8220;return null;&#8221;)); </textarea></p>
<p>If your are enjoying our posts, Let us know by leaving your comments</p>
]]></content:encoded>
			<wfw:commentRss>http://crunchpress.com/wordpress-security-hide-login-error/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beware! New WordPress Distributed Admin Account Cracker</title>
		<link>http://crunchpress.com/beware-new-wordpress-distributed-admin-account-cracker/</link>
		<comments>http://crunchpress.com/beware-new-wordpress-distributed-admin-account-cracker/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 13:58:05 +0000</pubDate>
		<dc:creator>Aqeel Syed</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[WordPress Attack]]></category>
		<category><![CDATA[WordPress Hacking]]></category>
		<category><![CDATA[WordPress Security]]></category>

		<guid isPermaLink="false">http://crunchpress.com/?p=97</guid>
		<description><![CDATA[ISC aka Internet Storm Center has reported a new &#8216;distributed WordPress admin account cracker&#8216;. This is a very smart and major attempt to crack admin passwords of WordPress blogs. This script is written in PHP and performs brute force cracking attempts to WordPress admin accounts. The wp_brute_attempt() function takes 3 parameters, $ch which is cURL&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fcrunchpress.com%2Fbeware-new-wordpress-distributed-admin-account-cracker%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fcrunchpress.com%2Fbeware-new-wordpress-distributed-admin-account-cracker%2F&amp;source=crunchpress&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://crunchpress.com/wp-content/uploads/2009/12/wp-bruteforce1.png"><img class="alignnone size-full wp-image-98" title="WordPress distributed admin account cracking" src="http://crunchpress.com/wp-content/uploads/2009/12/wp-bruteforce1.png" alt="WordPress distributed admin account cracking" width="530" height="317" /></a></p>
<p>ISC aka <a rel="nofollow" href="http://isc.sans.org" target="_blank">Internet Storm Center</a> has reported a new &#8216;<strong>distributed WordPress admin account cracker</strong>&#8216;. This is a very smart and major attempt to crack admin passwords of WordPress blogs.</p>
<p>This script is written in PHP and performs brute force cracking attempts to WordPress admin accounts.</p>
<blockquote><p>The wp_brute_attempt() function takes 3 parameters, $ch which is cURL&#8217;s structure (cURL is a command line tools that can be used to perform HTTP requests). The other two parameters define the site and the password that will be tried. If the script logged in successfully, the page that gets returned by the server will contain the phrase &#8220;Log Out&#8221;, and the function will return a true value.</p></blockquote>
<p>In layman&#8217;s words that script allows distributed cracking. It uses a MySql database to save information and script distributed (installed) over a large number of machines actually connects to main database. This allows the attacker to run many simultaneous scripts, each of them can take 200 URLs.</p>
<p>The script then takes every password from a password script and tries it on each site. The script can even be stopped and when executed next time will continue where it stopped.</p>
<p>While this particular version is relatively simple, the power behind the script and the MySQL database allows the attacker to distribute the attacks not only by sites, but also by passwords tried as well.</p>
<p>What can you do to protect your blog?</p>
<p>Cool question! If you are using WordPress, your blog security is at risk. You can protect your blog by taking following steps.</p>
<ol>
<li>Change you admin username, name it to something other then &#8216;admin&#8217;</li>
<li>Use a strong password &#8211; other then some simple word, use alpha-numeric password and also use some special characters like #$%^&amp;*</li>
<li>You can use WordPress security plugins like &#8216;<a href="http://www.bad-neighborhood.com/login-lockdown.html" target="_blank">Login Lockdown</a>&#8216; to protect your WordPress signup page.</li>
<li>Use &#8216;<a rel="nofollow" href="http://www.bad-behavior.ioerror.us/download/" target="_blank">Bad Behavior</a>&#8216; plugin for WordPress, &#8216;Bad Behavior&#8217; is <a rel="nofollow" href="http://www.bad-behavior.ioerror.us/2009/12/02/bad-behavior-stops-distributed-wordpress-account-cracker/" target="_blank">tested against this script</a> and it can block its access attempts to your blog.</li>
</ol>
<p>Have any questions? Feel free to ask through comments section.</p>
]]></content:encoded>
			<wfw:commentRss>http://crunchpress.com/beware-new-wordpress-distributed-admin-account-cracker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
