A shout out to all WordPressers!
A recent bout of hacking attempts, successful attempts at that on WordPress accounts has highlighted a security weakness on WordPress blogs.
In retrospect its pretty obvious really and this, from the BBC is worth reading. BBC on recent WordPress hacks.
The issue is that when you create your WordPress account, the account name defaults to “ADMIN” and that’s pretty much what most people use as the account name. This effectively gives hackers a head start in that they already know half of your security details.
Here’s a few steps that anyone can take to protect themselves against this –
- Log in to WordPress with your Admin account and set up a new user.
- Make sure the new user has “Administrator” access.
- Log out and log back in again using the new account.
- Go back into the “Users” menu and delete the Admin account and when it says re-associate the posts make sure that you assign them to the new account.
Taking these simple actions will make your WordPress blog a whole lot more secure.
If you don’t use the Admin account and use another administrator level account to create posts and so on, it’s still worth deleting the Admin account.
And…if you don’t have an Admin account at all, then it’s worth changing the password on the account that you do use.
Hope that helps fellow bloggers.
Knife Box Digital are a digital marketing consultancy based in Norwich and London – we are here to help businesses large and small, local or global with their digital marketing. Gives us a call or drop us an email.
