<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Scobleizer - Latest Comments in I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.disqus.com/</link><description>Tech enthusiast, video blogger, media innovator, fanatical about startups at Rackspace, home of fanatical support for Internet entrepreneurs.</description><atom:link href="https://scobleizer.disqus.com/i_don8217t_feel_safe_with_wordpress_hackers_broke_in_and_took_things/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Sun, 18 Oct 2009 05:52:07 -0000</lastBuildDate><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-20309579</link><description>&lt;p&gt;I agree with  spidersilk  on that too. It is a rich environment with several points of failure and wordpress is only one of them. I've had application hacks, malicious stuff installed and even a rootkit attack on my servers. It was even worse when I used managed servers since I had to depend on others to fix it which took more time.&lt;/p&gt;&lt;p&gt;Backing your data is always a good step of achieving an acceptable peace of mind level with web endeavors.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ipotpal Laptopov</dc:creator><pubDate>Sun, 18 Oct 2009 05:52:07 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-17637046</link><description>&lt;p&gt;Sorry for the very late reply Viki and thanks for the heads up on it working on the latest version. ;)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">ScottW</dc:creator><pubDate>Sun, 27 Sep 2009 11:14:47 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16870568</link><description>&lt;p&gt;is moving to posterus, which is indeed a great service, but is none the less a hosted provider on a service that you don't control, more secure?&lt;/p&gt;&lt;p&gt;I think we could hash through the dynamics of this security problem (e.g. posterous, running your own server, etc) at some length, but I'm not sure if that discussion would be particularly useful... &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">tychoish</dc:creator><pubDate>Fri, 18 Sep 2009 09:20:27 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16773430</link><description>&lt;p&gt;Mitch,&lt;/p&gt;&lt;p&gt;Thanks for sharing that plugin. I have a ton of clients who use Wordpress,  and one had her site hacked as well. The host did restore the backup, but I know of other folks who have more of a DIY setup like Robert had.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">orange_county_seo</dc:creator><pubDate>Wed, 16 Sep 2009 17:23:59 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16505234</link><description>&lt;p&gt;Oh, Hackers! They are very terrible.  Fortunately you wrote this post.  So amateur wordpress users like me learned this event. I will backup my blog. Very thank you.&lt;/p&gt;&lt;p&gt;Do you know any blog site better than wordpress?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">While1</dc:creator><pubDate>Sat, 12 Sep 2009 14:07:09 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16436158</link><description>&lt;p&gt;It's really sad to hear that happened to you Robert. Make sure that you always keep a backup of WordPress. I suggest use WP-DB plugin and set a 24 hour daily backup emailed to you.&lt;/p&gt;&lt;p&gt;Also look at this article for further ways to securing your WP-Admin&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.wpbeginner.com/wp-tutorials/11-vital-tips-and-hacks-to-protect-your-wordpress-admin-area/" rel="nofollow noopener" target="_blank" title="http://www.wpbeginner.com/wp-tutorials/11-vital-tips-and-hacks-to-protect-your-wordpress-admin-area/"&gt;http://www.wpbeginner.com/w...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Syed Balkhi</dc:creator><pubDate>Fri, 11 Sep 2009 15:07:12 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16421536</link><description>&lt;p&gt;This is exactly the sort of reason why I prefer &lt;a href="http://asp.net" rel="nofollow noopener" target="_blank" title="asp.net"&gt;asp.net&lt;/a&gt; applications such as BlogEngine.Net. PHP seems to get hacked a *lot* more than &lt;a href="http://asp.net" rel="nofollow noopener" target="_blank" title="asp.net"&gt;asp.net&lt;/a&gt; applications. Don't get me wrong I like FOSS, but refuse to use PHP as a web server platform.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Allen Harkleroad</dc:creator><pubDate>Fri, 11 Sep 2009 10:32:02 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16315559</link><description>&lt;p&gt;As a Wordpress blogger who can't upgrade (my dashboard doesn't have that facility for whatever reason), I must say I am pleasantly surprised to find Matt's comment at the very top here. I wrote to Wordpress several months ago with exactly the same complaint and I still haven't had the luxury of a response. It was very disappointing, but we live and we learn.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Krishna Prasad</dc:creator><pubDate>Thu, 10 Sep 2009 14:05:50 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16299596</link><description>&lt;p&gt;@Robert: Hopefully your ignorance when it comes to website security will hep lots of other people.&lt;/p&gt;&lt;p&gt;You run a hi-profile site, attractive to hack, with no security and then  you get caught with your pants down and embarrassed. Twice.&lt;/p&gt;&lt;p&gt;Now the word goes around; dont do as Robert, be smart, do the basics and keep up to date, and lots of ignorant people understand why they have to take some responsibility to avoid problems.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;So, once this happens, how do you feel safe again?&lt;/blockquote&gt;&lt;p&gt;&lt;br&gt;By investing one hour in checking your install/server security and by upgrading as you know you should do.&lt;/p&gt;&lt;p&gt;btw: Why did you not upgrade from 2.7.1 and what did you do prior to the hacking to secure your blog ? &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Myrstad</dc:creator><pubDate>Thu, 10 Sep 2009 08:32:25 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16278258</link><description>&lt;p&gt;Thanks.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">daveevans</dc:creator><pubDate>Wed, 09 Sep 2009 19:23:26 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16277436</link><description>&lt;p&gt;I'm cheap and lazy so I use &lt;a href="http://instantssl.com" rel="nofollow noopener" target="_blank" title="instantssl.com"&gt;instantssl.com&lt;/a&gt; but there are a bunch that will work for you.  Since the WP-Admin section is just to encrypt my password data and whatnot I opted for the lowest end cert as I don't need any badges, etc.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">bencredible</dc:creator><pubDate>Wed, 09 Sep 2009 18:59:46 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16261692</link><description>&lt;p&gt;What SSL cert vendor should I look at, such a range of pricing, need a cheat sheet.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">daveevans</dc:creator><pubDate>Wed, 09 Sep 2009 12:56:49 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16257035</link><description>&lt;p&gt;Well, so nice post, haah! Your mind helps me so much! I'm not sure if you mind the thing I'll do here. Im an online seller for the &lt;a href="http://www.purelife-shoes.com/" rel="nofollow noopener" target="_blank" title="http://www.purelife-shoes.com/"&gt;Timberland shoes, Gucci shoes, Prada shoes &lt;/a&gt; and &lt;a href="http://www.purelife-bags.com/" rel="nofollow noopener" target="_blank" title="http://www.purelife-bags.com/"&gt;Gucci bags, Coach bags, Prada bags&lt;/a&gt;, they are the most hot items on my sites, are u interest in them?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">BillPalm</dc:creator><pubDate>Wed, 09 Sep 2009 11:21:03 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16204535</link><description>&lt;p&gt;Oh yes btw,&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Wordpress Rocks.&lt;/strong&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">GodMode</dc:creator><pubDate>Tue, 08 Sep 2009 14:17:50 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16204254</link><description>&lt;p&gt;There are a lot of ways to make your wordpress blog safe and secure. I think you should first look for these and then blame wordpress... else u'll b the one who'll look lame.&lt;/p&gt;&lt;p&gt;Do make sure that all of the loop holes are filled up and that your blog a great one.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">GodMode</dc:creator><pubDate>Tue, 08 Sep 2009 14:11:06 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16199609</link><description>&lt;p&gt;I use wordpress to. But there is a diffrence between you and me. I get off my lazy ass and update my wordpress once in a while.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">jonfr</dc:creator><pubDate>Tue, 08 Sep 2009 13:02:50 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16176188</link><description>&lt;p&gt;Agree with you here man, especially with the nature of the web!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ahad Bokhari</dc:creator><pubDate>Tue, 08 Sep 2009 05:13:14 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16176175</link><description>&lt;p&gt;Amiable of you Robert, I know you want to play the role (and thats great!) but if it eases your mind you should have someone monitor your blog and back it up for you periodically.   Peace of mind is what matters most - besides you got other fish to catch and great posts to write.&lt;/p&gt;&lt;p&gt;Sure we are all techies at the end of the day, and i dont blame you for scratching that itch :-)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ahad Bokhari</dc:creator><pubDate>Tue, 08 Sep 2009 05:12:33 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16176105</link><description>&lt;p&gt;Good points Erica..&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ahad Bokhari</dc:creator><pubDate>Tue, 08 Sep 2009 05:04:54 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16176074</link><description>&lt;p&gt;Its open source at the end of the day Mr. Scoble.  Last versions of wordpress had an export to RSS WXR feature and the newer versions do as well.&lt;/p&gt;&lt;p&gt;Lots of other ways to back up but the above is the easiest.  Interesting to see the structure in the exported file...&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ahad Bokhari</dc:creator><pubDate>Tue, 08 Sep 2009 05:02:36 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16166609</link><description>&lt;p&gt;I have a diffierent point to make here.  Why do you need the plugins?  I have been reading you for years, and your blog design is not relevant.  Content and comments are important.  Then when you added things like that annoying Google Friend Connect visiting the site became less enjoyable.  Anyhow thats why I am happy I am sticking with &lt;a href="http://wp.com" rel="nofollow noopener" target="_blank" title="wp.com"&gt;wp.com&lt;/a&gt;.  Cloud hosting is no different than having your own server in that it takes tender love and constant care and 24 hour monitoring.   Thats not what blogging is.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">$51740</dc:creator><pubDate>Mon, 07 Sep 2009 23:30:49 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16165815</link><description>&lt;p&gt;I hope this entry shows up in this years Darwin awards...&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mark</dc:creator><pubDate>Mon, 07 Sep 2009 23:03:55 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16144413</link><description>&lt;p&gt;PostRank has a fairly extensive archive of your blog:&lt;br&gt;&lt;a href="http://www.postrank.com/feed/65b2b7c99c37d4c0276f237002dc8476" rel="nofollow noopener" target="_blank" title="http://www.postrank.com/feed/65b2b7c99c37d4c0276f237002dc8476"&gt;http://www.postrank.com/fee...&lt;/a&gt;&lt;/p&gt;&lt;p&gt;We have a full content archive as well - just the descriptions, titles dats are on the postrank app itself.&lt;/p&gt;&lt;p&gt;Lemme know if you'd like us to extract some posts - or even the entire archive and you can select the missing ones?&lt;/p&gt;&lt;p&gt;Ready a willing if you think it would help.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jim Murphy</dc:creator><pubDate>Mon, 07 Sep 2009 22:04:01 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16124282</link><description>&lt;p&gt;Robert,&lt;/p&gt;&lt;p&gt;Someone said it a few tweets down, but there's a really easy plugin down below that will automatically back up your blog to a server or email address, and you can schedule it to backup things once a week.&lt;/p&gt;&lt;p&gt;It's called WP-DB-Backup (&lt;a href="http://wordpress.org/extend/plugins/wp-db-backup/)" rel="nofollow noopener" target="_blank" title="http://wordpress.org/extend/plugins/wp-db-backup/)"&gt;http://wordpress.org/extend...&lt;/a&gt;.  I'm running it on Jeremiah Owyang's blog, and it allows me to have a weekly backup of what's going on in case his site goes down.  You guys are putting out so much great content that you really don't' have any other option but to make sure it goes somewhere safe.&lt;/p&gt;&lt;p&gt;I'll even help you set it up if you would rather it.&lt;/p&gt;&lt;p&gt;There are other measures you can take to make sure your site doesn't get hacked / make it harder to hack.&lt;/p&gt;&lt;p&gt;1).  Set your permissions to disallow public writing (it makes your themes uneditable in the editor, but if you have FTP access go in and enable one at a time until you're done, then re-disable it).&lt;/p&gt;&lt;p&gt;2) Move your WordPress directory somewhere else.  There are tutorials (like this one: &lt;a href="http://codex.wordpress.org/Giving_WordPress_Its_Own_Directory)" rel="nofollow noopener" target="_blank" title="http://codex.wordpress.org/Giving_WordPress_Its_Own_Directory)"&gt;http://codex.wordpress.org/...&lt;/a&gt; that show you how to set WordPress up to live in a subfolder, which you can name whatever you want, but have it live in the root directory (keep the root folders clean too)&lt;/p&gt;&lt;p&gt;3) Create a username that's not the default admin username, and delete the admin user.  That's the first place they check because it's the default.&lt;/p&gt;&lt;p&gt;Simple stuff, takes minutes to do, but a stitch in time saves nine, I guess.  Good luck in the recovery process, and if you need some advice let me know.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">studionashvegas</dc:creator><pubDate>Mon, 07 Sep 2009 21:01:24 -0000</pubDate></item><item><title>Re: I don&amp;#8217;t feel safe with WordPress, hackers broke in and took things</title><link>http://scobleizer.com/2009/09/05/i-dont-feel-safe-with-wordpress-hackers-broke-in-and-took-things/#comment-16112663</link><description>&lt;p&gt;unless there is some 0 day exploit they get hit with, it's not going to happen soon.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt McInvale</dc:creator><pubDate>Mon, 07 Sep 2009 17:04:12 -0000</pubDate></item></channel></rss>