Ka ilaali oo ka ilaali mareegaha WordPress jabsadayaasha

ka ilaali barta WordPress ee Hackers-ka

Mareegaha WordPress oo sugan

1] Hubi in kombayutarka Windows-(Windows computer) kaagu uu ka xoroobay malware-ka. Ma jiro xad ammaan ah oo ku jira WordPress ama server-kaaga mareegaha wax farqi ah haddii uu jiro keylogger sharci-darro ah oo lagu rakibay kumbuyuutarkaaga.

2] Had iyo jeer iska hubi inaad haysato noocii ugu dambeeyay(latest version) ee WordPress iyo Plugins-kaaga oo lagu rakibay. Adeegahaaga shabakadu sidoo kale waxa uu yeelan karaa nuglaanta. Sidaa darteed, iska hubi in Martigeliyahaaga Shabakadda(Web Host) uu ku shaqaynayo noocyadii ugu dambeeyay, badbaado, xasilloon ee software-ka server-ka. Si ka sii wanaagsan, iska hubi inaad isticmaalayso martigeliyaha la aamini karo oo arrimahan adiga kuu xanaaneeya.

3] Isticmaal magac isticmaale(strong username) oo xooggan iyo furaha sirta ah(strong passwords) ee xooggan . Waxa ugu fiican in la raadiyo ereyada sirta ah ee isku dhafan iyadoo la adeegsanayo xarfaha sare, kuwa hoose, tirooyinka iyo xarfo gaar ah oo dhererkoodu ka sarreeyo 15 xaraf. Ku dhaqan geli(Enforce) isticmaalka furaha sirta ah ee dhammaan qorayaashaada sidoo kale.

4] Ka beddel magaca isticmaalaha maamulaha(Change the Administrator username) ee rakibaada WordPress oo ka beddel maamulka caadiga ah una(admin) beddel wax xooggan oo aan xidhiidh la lahayn magacaaga ama boggaga. Waxaad samayn kartaa koonto maamuleed kale, u gal sidii isticmaale maamule oo cusub oo aad tirtiri kartaa koontada hore ee maamulaha ee caadiga ah. Ama waxaad isticmaali kartaa beddelaha magaca isticmaale ee Admin(Admin username changer) ama plugin renameer kordhinta(Admin renamer extended) ama mid ka mid ah pluginsyada amniga ee hoos ku xusan si aad dib ugu magacawdo isticmaaleha maamulaha caadiga ah.

5] U isticmaal(Use) Captcha ujeeddooyin(Captcha) soo gal.

captcha-3

Qalabka Captcha ee BWS(Captcha plugin from BWS) waa mid wanaagsan oo laga yaabo inaad rabto inaad eegto. Waxay kuu ogolaanaysaa inaad doorato hawlgallada iyo heerarka kakanaanta.

captcha-goobyada

6] Xaddidaadda Isku dayga Soo Gelida(Limit Login Attempts) plugin waxay xaddidi doontaa heerka isku dayga gelitaanka, habka cookies, IP kasta. Waxa ay ogolaan doontaa oo kaliya tirada habaysan ee isku dayo ka dib isticmaaluhu waa la xidhi doonaa. Waxaad u habayn kartaa dhammaan goobaha ay ka kooban tahay sida tirada isku dayga la oggol yahay, muddada xannibaadda, dib-u-isku dayga la oggol yahay iyo wixii la mid ah. Plugin Tani waxay faa'iido u leedahay ka hortagga weerarrada xoogga ah(brute force attacks) .

xaddid-login-isku day-dejinta

Haddii isticmaaluhu isticmaalo magac isticmaale ama erayga sirta ah ee khaldan, isaga ama iyada ayaa arki doona fariintan.

goobta WordPress oo sugan

7] U beddel URL- ka galitaanka Panel Panel ee asalka (Change the WordPress Panel login URL)/wp-admin/ wax kale adoo isticmaalaya Rename wp-login plugin. Plugin-gani wuxuu faa'iido u leeyahay ka hortagga weerarrada xoogga ah sidoo kale.

dib u magacaw-wp-login

 

8] Adeegso plugin Scanner Security(Security Scanner plugin) si aad u sawirto faylalkaaga rakibaadda WordPress wakhti wakhti. (WordPress)Sucuri Security – SiteCheck Malware Scanner(Sucuri Security – SiteCheck Malware Scanner) plugin waxa ay awood kuu siinaysaa in aad iskaan karto boggaga WordPress adiga oo isticmaalaya Sucuri SiteCheck isla saxan dashboardkaaga WordPress . Waxay hubisaa malware, spam, liiska madow, .htaccess redirects, qarsoon eval code, iyo arrimaha kale ee ammaanka.

Intaa waxaa dheer, waxay hubisaa haddii WordPress iyo PHP ay yihiin kuwo casri ah oo ka qarinaya nooca WordPress ee dadweynaha, iwm haddii goobtaada uu ilaaliyo Firewall Web(Web Firewall) . Waxa kale oo ay ilaalisaa Tusahaaga Uploads(Uploads Directory) , waxay xaddidaysaa wp-content iyo wp-waxaa ku jira gelitaanka addoo adkeynaya oggolaanshaha faylka, iyo hubinta daacadnimada faylashaaga WordPress ee asaasiga ah. (WordPress)Waxay la socotaa tiro badan oo ficilo ah, oo ay ku jiraan, Isku dayga Login , Galitaanka Fashilmay(Logins) , Isbedelka Faylka(File Changes) , iyo wixii la mid ah.

sucuri-security-check

Sucuri waxa kale oo ay hubisaa haddii goobtaadu ku jirto liiska madow meel kasta sida Google Safe Browsing , Norton Safe Web , Phish Tank , SiteAdvisor , Eset , Yandex , iwm oo ku wargeliya.

Marka laga reebo Sucuri, Secure WordPress plugin, Scanner Scanner(Exploit Scanner) , WordFence Security , WordPress Sentinel , Quttera , VIP Scanner , iThemes Security (oo hore u ahaa Better WP Security),  BulletProof Security iyo All In One WP Security & Firewall ayaa ka mid ah sawirada kale ee wanaagsan iyo plugins amniga waxaa laga yaabaa inaad rabto inaad eegto. Inta badan plugins-yadan, marka laga reebo in aad goobtaada ka baarto malware, waxay sidoo kale kaa caawin doonaan Oggolaanshaha Faylka(Harden File Permissions) Adag , tirtirida faylasha ReadMe , qarin noocyada WordPress , iyo in ka badan.

Xusuusnow(Remember) inaad kaydiso xogtaada ama goobta buuxda ka hor inta aanad samaynin wax isbedel ah oo la taaban karo oo ku saabsan rakibaadda WordPress maadaama qaar ka mid ah 1-guji hagaajinta laga yaabo inay jebiyaan qaar ka mid ah shaqeynta goobtaada. Markaa fadlan halkan ka taxaddar.

8] Isticmaal shabakada gudbinta macluumaadka bilaashka ah ee Cloudflare si aad u shaandheyso dhammaan taraafikadaada oo ay yarayso halista (Cloudflare)degelkaaga WordPress(WordPress) inuu noqdo bartilmaameed, maadaama ay u shaqeyso sidii wakiil ka dhexeeya booqdayaashaada iyo serverka mareegahaaga lagu martigeliyo. Aasaaska Cloudflare(Cloudflare) waa lacag la'aan, laakiin haddii aad bixiso qaddar magac ah, waxaad sidoo kale ka faa'iidaysan kartaa adeeggeeda Codsiga Webka ee Firewall(Web Application Firewall) . Waxay joojisaa weerarrada waqtiga-dhabta ah sida duritaanka SQL , qoraal-qorista-goobaha, faallaynta spam iyo xadgudubyada kale ee cidhifka shabakadda. Waxaan u isticmaalnaa Sucuri Firewall halkan. Sucuri waxay bixisaa dab-damis weyn, laakiin bilaash maaha. Google Project Shield wuxuu bixiyaa DDoS bilaash ahilaalinta si loo doorto mareegaha.

9] Yaree tirada plugins ee(number of plugins) aad isticmaasho. Dami(Deactivate) ama kaba sii fiican, tirtir kuwa aadan isticmaalin.

10] Sii wad abuurista kaydinta(backups) goobtaada wakhtiyo joogto ah, oo ku dheji qaar ka mid ah adeega Cloud iyo/ama miiskaaga. BackWPUp , VaultPress , BackupBuddy , DropBox for WordPress, BackUpWordPress ayaa ka mid ah plugins Backup -ka wanaagsan ee laga yaabo inaad rabto inaad hubiso.

Inkastoo tani ay ku filnaan karto inta badan bogagga WordPress , haddii aad u baahan tahay inaad sii socoto, waxaad akhrin kartaa qoraalkan WordPress.org .

Akhri: (Read:) Waa maxay sababta loo jabsado mareegaha ?

Qaarkiin ayaa laga yaabaa inay rabaan inay fiiriyaan boostadayda talooyinka waxtarka leh ee bloggers cusub(Useful tips for new bloggers) .(Some of you might want to check out my post on Useful tips for new bloggers.)



About the author

Waxaan ahay injineer software leh in ka badan 10 sano oo waayo-aragnimo ah horumarinta iyo dayactirka Windows 11 ama 10 codsiyada. Waxaan sidoo kale khibrad u leeyahay la shaqeynta Google Docs iyo Microsoft Edge. Xirfadahayga meelahan ayaa iga dhigaya musharax aad u wanaagsan doorarka injineernimada software mustaqbalka.



Related posts