Menu
iThemes
WordPress Backup, Security & Maintenance
  • Products
    • iThemes Security Pro
    • BackupBuddy
    • Kadence WP
    • Restrict Content Pro
    • iThemes Sync
    • Why buy from iThemes?
  • Bundles
    • Essentials Bundle
    • Plugin Suite
    • WordPress Web Designer’s Toolkit
    • Customer Spotlights
  • Resources
    • Blog
    • WordPress 101 Tutorials
    • WordPress Ebooks
    • Weekly WordPress Vulnerability Report
    • The Ultimate Guide to Starting a Web Design Business
  • Training
    • Upcoming Webinars
    • Free Webinar Library
    • Premium Courses
    • Become a Member
    • Member Login
  • Support
    • Documentation
    • Get Help
    • Product Updates
    • Upgrade Policy
    • Contact
    • Our Mission: Make People’s Lives Awesome
  • Log In
WordPress News and Updates from iThemes
Categories
  • Product Updates
  • WordPress Backup
  • WordPress Block Editor
  • WordPress Ecommerce
  • WordPress for Freelancers
  • WordPress Security
  • WordPress Tutorials
  • WPprosper

[Video] How Anyone Can Hack Your WordPress Site In Less Than 5 Minutes And How To Prevent It

Written by Kristen Wright on February 21, 2013

Last Updated on September 16, 2015

This webinar, hosted by Dre Armeda, covers how anyone can hack your WordPress site in less than 5 minutes (which he actually demos live) … and what you can actually do to prevent it.

Topics Covered

  • Knowing your enemy
  • WordPress-loving Infections
  • Access control
  • Tips for preventing and dealing with hacks
  • Plugins that can help with security
Kristen Wright
Kristen Wright

Kristen has been writing tutorials to help WordPress users since 2011. As marketing director here at iThemes, she’s dedicated to helping you find the best ways to build, manage, and maintain effective WordPress websites. Kristen also enjoys journaling (check out her side project, The Transformation Year!), hiking and camping, step aerobics, cooking, and daily adventures with her family, hoping to live a more present life.

Share via:

  • Facebook
  • Twitter
  • LinkedIn
  • More
Other related posts
wordpress vulnerability report - security
WordPress Vulnerability Report – June 29, 2022
Authentication Bypass Vulnerability
What is an Authentication Bypass Vulnerability? 7 Things to Know
WordPress favicon
What is a WordPress Favicon?
web design trends
5 Web Design Trends for June 2022

Comments

  1. The WordPress Weekend Roundup - WP Daily says:
    February 23, 2013 at 9:23 am

    […] 16. How to Hack a Site in 5 Minutes […]

    Reply
  2. Slackr says:
    February 24, 2013 at 5:28 pm

    Thanks so much for posting this. It was extremely useful and it is nice to have a knowledgable voice and something recent for 2013.

    Reply
  3. Your Blog will pay back Hacked Are You Prepared | McReaSoft Blog says:
    February 27, 2013 at 1:05 pm

    […] [Video] How Anyone can Hack Your WordPress locate In Less Than small cinque … […]

    Reply
  4. jackie says:
    April 19, 2013 at 2:22 am

    this video is really helpful but wpscan is not supported in windows?

    Reply
  5. Riaan says:
    May 8, 2013 at 12:03 pm

    Mmm… How to hack a WordPress website… Isn’t this website a WordPress theme… Hahaha. Awesome Video Guys! I wish I could win a year subscription with securi, NOW THAT WOULD BE AWESOME!

    Reply
  6. Thomson says:
    May 14, 2013 at 7:26 am

    WordPress or Joomla or any other CMS Platform sites are very easy to hack if you’re not aware of the security of your websites. Installing Plugins and Free Themes may cause in many situations. Better to avoid installing Free theme and better to buy any theme from iThemes or from somewhere else.

    Reply
  7. Amila says:
    May 29, 2013 at 8:57 pm

    Once I had my wp site hacked due to non regularly updates (it was version 2.xx) since then I use only HTML + CSS sites, so no more hassels, no more updates & not using any php files except for the contact page, Do I still need to worry about those hack attempts explained above in the video ??
    —
    Concerning the demonstration wp hack, What if the “wp-admin” folder protected against the IP ? simply by adding .htaccess ip allow deny rule (so that way only I can access to the admin panel even with the pw )

    Any thoughts ?
    thanks, cordially Amila

    Reply
  8. John says:
    June 5, 2013 at 3:35 am

    This information is really helpful. I found another articles which talks about fixing the worpdress hacking issue.

    http://wordpressapi.com/2013/05/22/if-wordpress-site-is-hacked-then-how-to-fix-issue/

    Reply
  9. Best Wordpress Security in 3 Easy Steps [Video Link] - Robert Collins says:
    June 7, 2013 at 2:17 pm

    […] 2. Restrict login attempts using the Limit Login Attempts plugin for WordPress.  Most sites are compromised using a “brute force” attack where an automated system discovers your admin account user name then tries a list of passwords against it.  By limiting the number of login attempts, the bot can only try a few times and then has to wait an hour or so try again, this makes it impossible for them to go through their password list.  Want to see how it works?  Here’s @dremeda hacking a WordPress site in 5 minutes [Video]. […]

    Reply
  10. Piyush says:
    June 16, 2013 at 3:55 am

    The video is really too big to view it at once. Need to download it

    Reply
  11. Jessie says:
    June 23, 2013 at 10:43 am

    OMG- My website got hacked last year, and it was such a mess. I had 2 other websites hosted on my same FTP server, and they were all being redirected to some weird website selling pharmaceuticals or something. I worked on it for probably 2 days before I gave in and started looking for professional help. I found a website called eSecurityPros.com and worked with their technicians. They had my sites completely fixed, up and running in a day. The whole thing costs about $200, but definitely worth it. I’d recommend them to anyone.

    Reply
  12. Mishka says:
    July 7, 2013 at 10:30 pm

    @Robert Collins
    Reducing login attempts against a 90,000 strong botnet is a useless tactic on its own. Login attempts are based on IP address. With that many addresses and that much badwidth, the brute force would be insanely fast. About as fast as the server could handle. Which is why it bogs you down. It’s using all is resources processing the information and bandwidth from the botnet.
    Login attempt isn’t a bad idea, but definitely add in the other security measures.

    Reply
  13. Nitin says:
    August 29, 2013 at 11:09 pm

    Thanks a lot for this amazing wordpress hack thing. I am impleting this method on my site now so that i don’t get hacked.
    Keep sharing info related to wordpress like this one.

    Reply
  14. Jess Canadian says:
    January 4, 2014 at 4:17 pm

    I think this just happened to me.
    I see product sold via “free” method.

    Reply

Respond

Click here to cancel reply.

Get updates on new themes & plugins plus special discounts

About iThemes

  • The Team
  • Contact Us
  • Website Accessibility Statement
  • Sitemap

Resources

  • Blog
  • Documentation
  • WordPress Tutorials
  • Free WordPress Ebooks
  • Free Webinar Library
  • Free Upcoming Webinars
  • iThemes Training
  • Affiliates

Customers

  • Member Panel Login
  • Support
  • FAQs
  • Upgrade Policy
  • Licensing
  • Terms and Conditions
  • Refund Policy

Top Products

  • BackupBuddy
  • iThemes Security Pro
  • iThemes Sync
  • Restrict Content Pro
  • WPComplete
  • WordPress Hosting
  • WordPress Plugins
  • Content Upgrades
  • WordPress Landing Page Plugin
  • BackupBuddy Stash

iThemes Media LLC Copyright © 2022 All rights reserved | Privacy Policy

© 2022 All Rights Reserved.

Share via
Facebook
Twitter
LinkedIn
Mix
Email
Print
Copy Link
Powered by Social Snap
Copy link
CopyCopied
Powered by Social Snap