<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Three tips to protect your WordPress installation</title>
	<atom:link href="http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/</link>
	<description>neat fun stuff</description>
	<lastBuildDate>Thu, 18 Mar 2010 06:22:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jon</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-483611</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Tue, 02 Mar 2010 00:55:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-483611</guid>
		<description>Hi, me again. I use Wordpress a lot, but am not a techy at all. I am very paranoid about things going wrong. I see that you keep the &quot;meta&quot; widget on your sidebar. Now, I try to remove every sign that my site is running on Wordpress for fear of those pesky hackers doing naughty things, like killing my site and business! I am guess that as wordpress blogs go, yours must be one of the most popular in terms of traffic, and also get a lot of unwanted attention. Do you ever have any problems with people trying to hack it? Is it much more secure than it used to be? Do you have any other little security tips that you have not had time to publish yet?</description>
		<content:encoded><![CDATA[<p>Hi, me again. I use Wordpress a lot, but am not a techy at all. I am very paranoid about things going wrong. I see that you keep the &#8220;meta&#8221; widget on your sidebar. Now, I try to remove every sign that my site is running on Wordpress for fear of those pesky hackers doing naughty things, like killing my site and business! I am guess that as wordpress blogs go, yours must be one of the most popular in terms of traffic, and also get a lot of unwanted attention. Do you ever have any problems with people trying to hack it? Is it much more secure than it used to be? Do you have any other little security tips that you have not had time to publish yet?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-468769</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Sun, 14 Feb 2010 02:24:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-468769</guid>
		<description>There&#039;s a couple of pretty handy plugins that help protect WP:
Secure Wordpress - http://wordpress.org/extend/plugins/secure-wordpress/
Wordpress firewall - http://www.seoegghead.com/software/wordpress-firewall.seo

I use them both. The firewall throws out some &quot;false positives&quot; sometimes (I had problems with Google Ad Manager, but you can whitelist stuff).</description>
		<content:encoded><![CDATA[<p>There&#8217;s a couple of pretty handy plugins that help protect WP:<br />
Secure Wordpress &#8211; <a href="http://wordpress.org/extend/plugins/secure-wordpress/" rel="nofollow">http://wordpress.org/extend/plugins/secure-wordpress/</a><br />
Wordpress firewall &#8211; <a href="http://www.seoegghead.com/software/wordpress-firewall.seo" rel="nofollow">http://www.seoegghead.com/software/wordpress-firewall.seo</a></p>
<p>I use them both. The firewall throws out some &#8220;false positives&#8221; sometimes (I had problems with Google Ad Manager, but you can whitelist stuff).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iglow</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-455261</link>
		<dc:creator>iglow</dc:creator>
		<pubDate>Tue, 19 Jan 2010 13:22:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-455261</guid>
		<description>yeah this days a lot of blogs gets hacked, using chmod properly can help much also</description>
		<content:encoded><![CDATA[<p>yeah this days a lot of blogs gets hacked, using chmod properly can help much also</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RAY</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-430587</link>
		<dc:creator>RAY</dc:creator>
		<pubDate>Wed, 02 Dec 2009 08:27:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-430587</guid>
		<description>Q about feedburner feeds that do not validate?

hmmm. wondering why feedburner shows the wp version in its coding if it&#039;s such a security risk and now considered a no-no?

from the feedburner feed code  --&gt; http://wordpress.org/?v=abc 

but also mainly wondering why feedburner feeds don&#039;t validate (using http://feedvalidator.org/check.cgi?url=hxxp://domain-name.com ) ....  it shows lots of yellow highlighted errors such as:

language must be an ISO-639 language code: ...
Ensure description precedes content:encoded 
Unregistered link relationship: hub
Non-html tag: hs  .... &lt;img src=&quot;http://feeds.feedburner.com/~r ....
Column 0: Invalid HTML: malformed start tag,
column 0: style attribute contains potentially dangerous content: word-wrap   ..... 

As a newbie i would have thought feedburner had all the formatting protocols taken care of for validation since it refers one to validate a feed there at that site if FB cannot find the feed?

I&#039;m confused about this. Really appreciate any clarification and feedback or solutions on how to fix / validate feedburner feeds properly since I am working on setting up a WP-based site w/ a friend and it&#039;s really like a new language -- on alot of this but trying to learn for sure.
 thank.s</description>
		<content:encoded><![CDATA[<p>Q about feedburner feeds that do not validate?</p>
<p>hmmm. wondering why feedburner shows the wp version in its coding if it&#8217;s such a security risk and now considered a no-no?</p>
<p>from the feedburner feed code  &#8211;&gt; <a href="http://wordpress.org/?v=abc" rel="nofollow">http://wordpress.org/?v=abc</a> </p>
<p>but also mainly wondering why feedburner feeds don&#8217;t validate (using <a href="http://feedvalidator.org/check.cgi?url=hxxp://domain-name.com" rel="nofollow">http://feedvalidator.org/check.cgi?url=hxxp://domain-name.com</a> ) &#8230;.  it shows lots of yellow highlighted errors such as:</p>
<p>language must be an ISO-639 language code: &#8230;<br />
Ensure description precedes content:encoded<br />
Unregistered link relationship: hub<br />
Non-html tag: hs  &#8230;. &lt;img src=&quot;http://feeds.feedburner.com/~r &#8230;.<br />
Column 0: Invalid HTML: malformed start tag,<br />
column 0: style attribute contains potentially dangerous content: word-wrap   &#8230;.. </p>
<p>As a newbie i would have thought feedburner had all the formatting protocols taken care of for validation since it refers one to validate a feed there at that site if FB cannot find the feed?</p>
<p>I&#8217;m confused about this. Really appreciate any clarification and feedback or solutions on how to fix / validate feedburner feeds properly since I am working on setting up a WP-based site w/ a friend and it&#8217;s really like a new language &#8212; on alot of this but trying to learn for sure.<br />
 thank.s</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Bury</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-425377</link>
		<dc:creator>Robert Bury</dc:creator>
		<pubDate>Tue, 24 Nov 2009 04:41:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-425377</guid>
		<description>Thanks for the great resource!!!
To possibly help others...

Step 1) I could only use:
order deny,allow
deny from all
# whitelist home IP address
allow from 64.233.169.99
(anything else crashed and I couldn&#039;t access anything)

Step 2) 
I already had a file (maybe an update) and it said:


Bonus Step) 
I really had to search for it and ultimately found it in the wp-includes\general-template.php
file.

Thanks so much Matt!!!
~ Robert Bury</description>
		<content:encoded><![CDATA[<p>Thanks for the great resource!!!<br />
To possibly help others&#8230;</p>
<p>Step 1) I could only use:<br />
order deny,allow<br />
deny from all<br />
# whitelist home IP address<br />
allow from 64.233.169.99<br />
(anything else crashed and I couldn&#8217;t access anything)</p>
<p>Step 2)<br />
I already had a file (maybe an update) and it said:</p>
<p>Bonus Step)<br />
I really had to search for it and ultimately found it in the wp-includes\general-template.php<br />
file.</p>
<p>Thanks so much Matt!!!<br />
~ Robert Bury</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kat Young</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-399885</link>
		<dc:creator>Kat Young</dc:creator>
		<pubDate>Mon, 05 Oct 2009 02:55:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-399885</guid>
		<description>I have had my blog hacked over and over. I will try to edit my .htaccess file thanks =)</description>
		<content:encoded><![CDATA[<p>I have had my blog hacked over and over. I will try to edit my .htaccess file thanks =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Russell</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-385971</link>
		<dc:creator>Russell</dc:creator>
		<pubDate>Tue, 01 Sep 2009 13:43:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-385971</guid>
		<description>Hi Matt
Hope you doing great!
Our blog has been hacked. Im getting all these wierd backlinks to my blog on other blogs but they hidden.  My blog developer says &quot;What the script does, apparently, is create those URL&#039;s on their site (that are linking back to you).&quot;

Thought it would interest you. We are working with Godaddy to fix the problem..

Best</description>
		<content:encoded><![CDATA[<p>Hi Matt<br />
Hope you doing great!<br />
Our blog has been hacked. Im getting all these wierd backlinks to my blog on other blogs but they hidden.  My blog developer says &#8220;What the script does, apparently, is create those URL&#8217;s on their site (that are linking back to you).&#8221;</p>
<p>Thought it would interest you. We are working with Godaddy to fix the problem..</p>
<p>Best</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: doruman</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-384361</link>
		<dc:creator>doruman</dc:creator>
		<pubDate>Sat, 29 Aug 2009 17:26:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-384361</guid>
		<description>Even if this post has more than a year old, here are very useful informations for any WP blogger. Thank you very much Matt for all that you offer as free informations, not only as Google employer.

 Kind regards,
Doru</description>
		<content:encoded><![CDATA[<p>Even if this post has more than a year old, here are very useful informations for any WP blogger. Thank you very much Matt for all that you offer as free informations, not only as Google employer.</p>
<p> Kind regards,<br />
Doru</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Redbrickstock</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-379343</link>
		<dc:creator>Redbrickstock</dc:creator>
		<pubDate>Fri, 21 Aug 2009 00:37:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-379343</guid>
		<description>Will the .htaccess thing work for a class B address. eg. allow from 64.233.169. ?</description>
		<content:encoded><![CDATA[<p>Will the .htaccess thing work for a class B address. eg. allow from 64.233.169. ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rory Siems</title>
		<link>http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-364971</link>
		<dc:creator>Rory Siems</dc:creator>
		<pubDate>Fri, 24 Jul 2009 02:45:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.mattcutts.com/blog/three-tips-to-protect-your-wordpress-installation/#comment-364971</guid>
		<description>Hi Matt,

we just spent the day fixing my friend&#039;s wordpress site that apparently had some passthru exploit from a site on a Chinese domain routed through a Russian IP.

We upgraded Wordpress to the latest version, we upgraded all of the plugins to the latest version. The web developer who set up the website claimed that the malicious code installed on the site was not from a Wordpress vulnerability, but rather from a brute force attack on the web host.

I still am not 100% sure that a dictionary attack or brute force attack guessed the password as it was pretty obscure. To be safe I did subscribe to the wordpress development feed. I like the idea of obscuring plugins from snoops too.</description>
		<content:encoded><![CDATA[<p>Hi Matt,</p>
<p>we just spent the day fixing my friend&#8217;s wordpress site that apparently had some passthru exploit from a site on a Chinese domain routed through a Russian IP.</p>
<p>We upgraded Wordpress to the latest version, we upgraded all of the plugins to the latest version. The web developer who set up the website claimed that the malicious code installed on the site was not from a Wordpress vulnerability, but rather from a brute force attack on the web host.</p>
<p>I still am not 100% sure that a dictionary attack or brute force attack guessed the password as it was pretty obscure. To be safe I did subscribe to the wordpress development feed. I like the idea of obscuring plugins from snoops too.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
