View Single Post
Old 05-14-2010, 09:12 AM  
Varius
Confirmed User
 
Industry Role:
Join Date: Jun 2004
Location: New York, NY
Posts: 6,890
Quote:
Originally Posted by pr0 View Post
Everything said in this post is helpful. But just to follow up on it......

But let me stress yet once again........on top of spending thousands of dollars/hours tightening up scripts

When using 3rd party applications, change common file names & "footprints" for the script (search able in the major engines). The less your site can be found by exploit scanners, the less likely you are 2 be hacked. P.S. Renaming the files will result in no real adverse effects in your SE rankings.

For instance, hackers will have a program submit the following to google in several formats....

powered by WordPress
Entries (RSS) and Comments (RSS).

or look for /wp-admin/ directories by ip subnets, well known to be owned by hosting companies......simply changing mundane file structures & footprints will leave you 100x less likely to have your blog (for example) scanned every time a new 0-day exploit hits

so yes...tighten your scripts, consult a security expert, BUT ALSO learn to hide subtle indicators hackers use to find your site in the first place...typically site pwnage/blog spam etc. comes directly from a simple mass google lookup......sometimes simplicity beats over-thinking security

finally if you've been with your host for a few years & you're about to start a new site, ask them if they've obtained a new ip block recently, see if you can get 1 or 2 of the new stock for your newest sites
I agree definitely with the theory but see a problem with that advice; a lot of people here, if they are not experienced programmers, will end up just breaking things.

For example, let's say they rename many common page names. Sometimes, they have to find and replace certain variables in the DB just not grep through the code to replace. Not to mention, if they try and use additional modules or plugins, those may no longer work without modifying that code...and so on.

For those who know what they are doing, or have access to someone who does, it is a great suggestion. For the rest, I think it will end up being a problem for them to achieve
__________________
Skype variuscr - Email varius AT gmail
Varius is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote