Wednesday, June 12, 2013

Why not to use WordPress for you Automotive Blog



In regards to questions on my post about Wordpress blogs. Number one let me make perfectly clear as stated in the post “Wordpress is an impressive software package that allows individuals with minimal understanding of web design to put together a web site rapidly, and for personal use it is unmatched

The second thing I should mention is that just because your wordpress site has not been defaced that does not mean it could not be or has not been hacked. Hackers attack sites and applications for various reasons, weather that be to test their skill set, deface sites with their tags and graphics, site hijacking, scanning databases for personal information, and the list of reasons go on and on. Doing a simple search of wordpress hacked will bring back thousands of results with most of them pointing to information on how to recover from a hacked wordpress site. Trust me all the various security gurus out there would not of taken the time to cover the topic in such great detail if it was not a major issue.

Yes Wordpress is an open source software package. What that means is the easy of developers to tweak code and/or add custom plug-ins is available. What that also means is the hackers don't have to do much work to know the layout of your site's files, the structure of your database, where your site upload pages are, which pages include your database connection information, which pages contain your data queries, etc.. Again running a simple website or blog that is not collection user information, and is updated regularly is not at great risk but it is still at risk.

Recovering from a compromised site can be a costly and time consuming project.

Having worked as an application security & development annalist for over the last 20 years, I can not begin to count the number of people who I have had to help recover from a wordpress hacked site. Sadly most of them were running simple little sites that really had no need for all the bloated code that comes in a premade cms template. All that being said I'm not going to ask anyone to take my word for it each individual should do their own due diligence and research the topic for themselves. Here are some great links to get you started.

OWASP Wordpress Security Checklist Projecthttps://www.owasp.org/index.php/OWASP_Wordpress_Security_Checklist_Project


OWASP vulnerabilities relevant to WordPress
http://security.stackexchange.com/questions/29930/what-vulnerabilities-in-the-owasp-top-10-are-relevant-to-wordpress


WordPress.org information on recovering from database hack
http://wordpress.org/support/topic/post-hack-database-inspection-and-cleanup

WordPress.org Listing of Maintenance and Security updates

http://wordpress.org/news/category/security/
RandomStorm Backtrack cross site scripting information


Tuesday, June 11, 2013

VL Automotive Blogger VS Wordpress





One question I'm commonly asked in regards to blogging platforms is why do I prefer my self rolled VL Automotive Blogging System vs Wordpress or Joomla type of systems. Well its a great question, coming from primarily an application development & security background the number one reason would be because of security concerns.

Wordpress is an impressive software package that allows individuals with minimal understanding of web design to put together a web site rapidly, and for personal use it is unmatched. Nevertheless, for commercial use you will want to question whether it be a good idea to use software which is habitually hacked, delivers slow performance and involves continuous technical attention.

The VL Automotive Blogging System consist of about 20 files containing markup code whereas a Wordpress or Joomla site normally contain over 1,000 files of code and can exceed 6,000 files depending on the plug-ins installed. The amount of code that needs to be managed and updated etc is considerable adding cost and resources to maintain an effective blogging platform.

Since there are countless blogs using WordPress they can be a definite target for computer hackers. When a hacker can locate a vulnerability in a single system chances are this is present on many of the others. Additionally, as robots can determine whether or not a site is made by WordPress or not once a weakness has been discovered it is typically automatically exploited on every similar website the hackers find. Once a blog has been hacked it can be really difficult and expensive to fix.


Any site on-line is in danger of hackers to some degree however, having a VL Automotive Blog would mean that a hacker will need to target your blog specifically. The difference with a WordPress based blog is that the hacker can target a large number of blogs at once, without knowing or considering who they belong to.

Wiredwizrd

Morgan Todd Lewistown, PA

Experienced Information Technology Manager with a strong knowledge of technical guidance, IT best practices, security protocols, team leadership, and analyzing business requirements.
Google