This post was put together in collaboration with one of our Support Engineers, Bruno Borges. Be sure to take a minute and say thanks for the info, he loves twitter (when its up). It seems every day we’re combating malicious redirections. Often, they are simple, but everyday they are evolving, and in some instances become [...]
Website Malware Removal – WordPress Tips & Tricks
We often write posts that give you advice and recommendations around how to harden your websites, and have only recently begun to give advice on ways to navigate your backend and remove infections via terminal. But what about all the basics? That’s what I want to cover in this post. All those things that you should know [...]
Website Malware Removal – Blackhole Exploit
Here is a quick little write up on how to to deal with one, of many variations, of the Blackhole Exploit. The Infection If you scan your site using Sucuri SiteCheck and find yourself with a result that looks like this: Then you are dealing with an infection that is facilitated through the use of [...]
Google Blacklist Warning: Something’s Not Right Here!
Google recently put out a post talking to the past 5 years offering the Safe Browsing program and summarized in a post titled: Google Safe Browsing Program 5 Years Old – Been Blacklisted Lately? This got us thinking about the number of Google warnings end-users see every day, and naturally we couldn’t help but take [...]
How To: Lock Your Site by Enabling a Second Layer of Authentication
I put together a post this weekend about my personal experience installing a WordPress site on a clean Server. In the process of hardening the administration panel I found myself doing something that I don’t see discussed much – enabling Basic Access Authentication. That got me thinking about a putting together this post which will [...]
Understanding Conditional Malware – IP Centric Variation
In today’s web malware landscape you can’t help but take a minute to familiarize yourself with a concept known as conditional malware. As implied in the name, it’s malware that only works when specific rules are met. Those rules can range from specific IP ranges to time of day. They are very tricky and as [...]
How To: Lock Down WordPress Admin Panel With a Dynamic IP
There is often a lot of discussion around locking down access to WP-ADMIN and WP-Login.php, specially around restricting it by IP. The issues and retort that often comes up is, “but what if I have a dynamic IP?” Right away the response from folks is, “oh, well then this won’t work for me.” It didn’t [...]
The Sucuri Learn Blog
We have long known that the time was approaching in which we would need to improve our level of engagement with the community and start providing more substantial contributions around managing and securing your websites. We hope to use this blog, Learn Blog, to focus specifically on this challenge, educating our audience, such that through [...]