1. Halo Guest, pastikan Anda selalu menaati peraturan forum sebelum mengirimkan post atau thread baru.

[warning] pengguna wordpress harap masuk untuk securit

Discussion in 'Wordpress' started by chikmonk, May 28, 2011.

Tags:
  1. chikmonk

    chikmonk Super Hero

    Joined:
    Jun 10, 2009
    Messages:
    1,919
    Likes Received:
    172
    Location:
    di kolong jembatan
    temen2, cuma mw ngingetin ternyata sampai saat ini cms wordpress masih jadi buruan utama orang2 yang jail buat nyoba2 ( arti lain hacker )

    daripada kepanjangan mending cek masing2 blog yg pake wp, beberapa tips aja
    untuk membership kalo bisa ga usah di aktifin, ataupun klo di aktifin mending langsung default New User Default Role nya subcriber jangan lebih

    jangan lupa sering2 browsing masalah keamanan wordpress, beberapa tread yg mngkin bisa di baca
    trik menyembunyikan wp login
    plugin security wp
    keamanan lewat htaccess
    jangan lupa juga gabung di group security wordpress disini

    bagaimana cara hacker mencari celah di wp ?
    dulu jga pernah ada yang bahas masalah ini dari mastah hacker disini ( pasti uda pada tau smua )

    cara lainnya yaitu menggunakan fasilitas dari mbah google yang kita cintai :hmm:
    yg biasa di sebut google dork
    ini beberapa dork yang digunakan buat nyari celah di wp
    index/wp-content/plugins/Enigma2.php?boarddir=
    mygallery/myfunctions/mygallerybrowser.php?myPath=
    plugins/wp-table/js/wptable-button.phpp?wpPATH=
    plugins/wordtube/wordtube-button.php?wpPATH=
    plugins/myflash/myflash-button.php?wpPATH...=
    plugins/BackUp/Archive.php?bkpwp_plugin_path=
    plugins/BackUp/Archive/Predicate.php?bkpwp_plugin_path=
    plugins/BackUp/Archive/Writer.php?bkpwp_plugin_path=
    plugins/BackUp/Archive/Reader.php?bkpwp_plugin_path=
    plugins/sniplets/modules/syntax_highlight.php?libpath=

    monggo di lanjutkan sendiri
    ga enak kalo ga da contoh hasilnya
    dan yang paling sederhana aja mungkin uda pada tau nama domainnya
    hxxp://www.garudaone.com/wp-content/uploads/2011/05/ads.html kalo ada admin dari domainnya disini sowry cuma ngetes doang ko :sttt:
    contoh lainnya yg lebih parah
    tanya ke mbah google aja ya soalna takut.. :cilukba:

    buat para mastah2 hacker disini yang baik hati tolong kalo ada yang salah di koreksi demi keamanan kita bersama.
     
    mawarkuning, andygrey, heripu and 3 others like this.
  2. TransBlogger

    TransBlogger Super Hero

    Joined:
    Apr 27, 2008
    Messages:
    1,151
    Likes Received:
    92
    Wow... mr Hacker is in the house! Ngeri om!
     
  3. nodali

    nodali Ads.id Fan

    Joined:
    Jan 13, 2010
    Messages:
    230
    Likes Received:
    22
    Gan, boleh ga kau minta tolong? kira-kira, apa yang harus diamankan di blog saya: wewewe.negerihijau[.]com

    Thanks
     
  4. JhezeR

    JhezeR Super Hero

    Joined:
    Dec 14, 2009
    Messages:
    1,356
    Likes Received:
    59
    Location:
    Universe
    Hiii ngeri jg euy..
    Ayo perkuat security skrg.
     
  5. einlanzer

    einlanzer Hero

    Joined:
    May 2, 2011
    Messages:
    581
    Likes Received:
    3
    Mantap gan..
    thx banget.
    Web ane sempat di defaced beberapa mminggu yang lalu.. :(

    Like!
     
  6. chikmonk

    chikmonk Super Hero

    Joined:
    Jun 10, 2009
    Messages:
    1,919
    Likes Received:
    172
    Location:
    di kolong jembatan
    wew ga ngerti gan ane masalah gituan... tadi cuma iseng2 ga ada kerjaan
    sing penting jangan banyak plugin sembarangan...


    halah mastah ngerendah aja nih :D
     
  7. ahmadsoe

    ahmadsoe Ads.id Pro

    Joined:
    Apr 28, 2010
    Messages:
    499
    Likes Received:
    92
    Location:
    Bandung ~ Jakarta
    Selengkapnya ttg vuln di wordpress ada disini :
    Code:
    http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=wordpress&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=6&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=
     
  8. hebohmania

    hebohmania Super Hero

    Joined:
    Feb 10, 2010
    Messages:
    3,193
    Likes Received:
    221
    to TS

    sob ente install plugin firewall sebelumnya enggak?
    so far blog gw yang pakai firewall adem ayem meskipun tiap hari/minggu ada saja SQL INJECTION atau REVERSE ATTACK ...
     
  9. adexaja

    adexaja :3

    Joined:
    Oct 21, 2010
    Messages:
    3,305
    Likes Received:
    623
    Location:
    Musholla
    Wahh,, bisa diinjeck backdoor tuh blog ,, :hmm2: nanti dicoba dulu baru ane tutupi blognya .
     
  10. Schwarzkophf

    Schwarzkophf Super Hero

    Joined:
    Nov 13, 2008
    Messages:
    2,318
    Likes Received:
    71
    Location:
    Depok
    wah serem juga ya ..
    makin banyak aja celahnya :hmm:
     
  11. chikmonk

    chikmonk Super Hero

    Joined:
    Jun 10, 2009
    Messages:
    1,919
    Likes Received:
    172
    Location:
    di kolong jembatan
    ane ga pernah pake firewall seh gan...
    mskipun kadang ada yg iseng2 ke blog tpi alhamdulillah slama ini blum sampai kena :D

    ---------- Post added 05-30-2011 at 09:36 AM ---------- Previous post was 05-29-2011 at 11:20 AM ----------

    mw tanya disini ada yg ngerasa punya nama domain
    pakde.com ga ???
     
  12. moh.taqiem

    moh.taqiem Ads.id Fan

    Joined:
    Mar 23, 2011
    Messages:
    148
    Likes Received:
    5
    Location:
    Kamar Gelap
    iye perlu waspada, lagi marak2nya gan banyak temen ane kena.. /:)
     
  13. auranda

    auranda Super Hero

    Joined:
    Aug 7, 2008
    Messages:
    806
    Likes Received:
    11
    Location:
    duduk dikursi depan monitor
    plugin firewall na free or premium bos?
     
  14. hebohmania

    hebohmania Super Hero

    Joined:
    Feb 10, 2010
    Messages:
    3,193
    Likes Received:
    221
    free di add new plugins saja
    - firewall ver 2
    - bulletproof juga

    * tidak menolak di kasih cendol nya
     
  15. adityabct

    adityabct Hero

    Joined:
    May 5, 2011
    Messages:
    702
    Likes Received:
    12
    Location:
    local
    wah... rawan nih...
     
  16. boijos1

    boijos1 Ads.id Fan

    Joined:
    Jan 10, 2011
    Messages:
    110
    Likes Received:
    5
    trus gimana gan cara atasi wp yang sudah kena hack , udah jasi korban nih 2 domain kena semua [-(
     
  17. poetri

    poetri Super Hero

    Joined:
    May 11, 2011
    Messages:
    1,452
    Likes Received:
    265
    Untung pake blogcepot
     
  18. masrimanas

    masrimanas Super Hero

    Joined:
    Oct 18, 2010
    Messages:
    1,612
    Likes Received:
    106
    Location:
    Kampar, Riau
    hemm, untung sekarang blog ane masih aman2 aja mskipun gak pake pengaman. .
     
  19. ricario

    ricario Newbie

    Joined:
    Jul 24, 2010
    Messages:
    33
    Likes Received:
    0
    ok.. sip gan, diantisipasi nih :)
     
  20. k0z3y

    k0z3y Ads.id Fan

    Joined:
    Feb 17, 2010
    Messages:
    228
    Likes Received:
    37
    Location:
    https://www.ciusan.com/
    semakin tinggi pohon, semakin kenceng angin yang niup... Kayaknya pas tuh... Jadi musti gimana dong ??????
     

Share This Page