{"id":466,"date":"2012-09-16T20:52:44","date_gmt":"2012-09-16T18:52:44","guid":{"rendered":"http:\/\/www.ayhanarda.com\/blog\/?p=466"},"modified":"2012-09-24T23:10:39","modified_gmt":"2012-09-24T21:10:39","slug":"wordpress-guvenlik-onerileri","status":"publish","type":"post","link":"https:\/\/www.ayhanarda.com\/blog\/2012\/09\/wordpress-guvenlik-onerileri\/","title":{"rendered":"WordPress G\u00fcvenlik \u00d6nerileri"},"content":{"rendered":"<p>WordPress g\u00fcvenli\u011fi ile ilgili \u00e7ok fazla soru gelmekte , Tek tek cevap vermek zorla\u015f\u0131nca bir derleme haline getirmeye karar verdim , umar\u0131m faydal\u0131 olur.<\/p>\n<h2><strong>1 &#8211; &#8220;admin&#8221; Y\u00f6netici Ad\u0131n\u0131 Kullanmay\u0131n.<\/strong><\/h2>\n<p>WordPress 3.0 s\u00fcr\u00fcm\u00fcnden sonra bu ismi de\u011fi\u015ftirme opsiyonunu art\u0131k sunmakta , \u00f6ncelikle bunu de\u011fi\u015ftirmenizi \u00f6neriyorum , tahmin edersiniz ki bir sitenin wordpress oldu\u011funu \u00f6\u011frendikten sonra ilk yapt\u0131\u011f\u0131m\u0131z \u015fey &#8220;admin&#8221; kullan\u0131c\u0131s\u0131 i\u00e7in \u015fifre denemektir. Bunu de\u011fi\u015ftirmemiz, bu denemelerin ba\u015far\u0131ya ula\u015fmas\u0131n\u0131 kesmek i\u00e7in etkili bir ba\u015flang\u0131\u00e7 olacakt\u0131r.<\/p>\n<p>E\u011fer WordPress 3.0 dan \u00f6nceki versiyonu kullan\u0131yor iseniz ki ben asla tavsiye etmiyorum , bu durumda muhtemelen hosting kontrol paneliniz \u00fczerinden PhpMyadmin e eri\u015febiliyorsunuz , phpmyadmin \u00fczerinden veritaban\u0131n\u0131zda a\u015fa\u011f\u0131daki sql sorgusunu \u00e7al\u0131\u015ft\u0131rman\u0131z &#8220;admin&#8221; k.ad\u0131n\u0131z\u0131 de\u011fi\u015ftirecektir , phpmyadmin \u00fczerinde bilgili olanlar ise direkt olarak wp_users tablosundan admin ismini bulup editleyebilirler.<\/p>\n<div id=\"wpshdo_1\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_1\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_1\"><\/a><a id=\"wpshat_1\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_1\"  onClick=\"javascript:wpsh_toggleBlock(1)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_1\" onClick=\"javascript:wpsh_code(1)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_1\" onClick=\"javascript:wpsh_print(1)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_1\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"sql\" style=\"font-family:monospace;\"><span class=\"kw1\">UPDATE<\/span> wp_users <span class=\"kw1\">SET<\/span> user_login <span class=\"sy0\">=<\/span> <span class=\"st0\">'yeni_belirleyece\u011finiz_isim'<\/span> <span class=\"kw1\">WHERE<\/span> user_login <span class=\"sy0\">=<\/span> <span class=\"st0\">'admin'<\/span>;<\/pre><\/div><\/div>\n<h2><strong>2- G\u00fc\u00e7l\u00fc \u015eifreler Kullan\u0131n<\/strong><\/h2>\n<p><strong><\/strong>\u00c7o\u011fu kullan\u0131c\u0131 \u00e7ok basit \u015fifreler kullanmakta ve basit bir brute-force tekni\u011fi ile y\u00f6netici panellerine ula\u015f\u0131labilmekte , bu sebeple g\u00fc\u00e7l\u00fc ve komplex \u015fifreler kullanman\u0131z\u0131 \u00f6neriyorum.<\/p>\n<p>G\u00fc\u00e7l\u00fc \u015fifreleri kolayca olu\u015fturmak i\u00e7in a\u015fa\u011f\u0131daki ba\u011flant\u0131y\u0131 kullanabilirsiniz.<\/p>\n<p><a title=\"Password Generator\" href=\"http:\/\/webhostingsitesi.com\/labs\/password_generator.php\" target=\"_blank\">G\u00fc\u00e7l\u00fc \u015eifre Olu\u015fturucu<\/a><\/p>\n<h2><strong>3- Secret Key Kullan\u0131n<\/strong><\/h2>\n<p>WordPress 2.6 dan sonra gelen bir \u00f6zellik , wp-config dosyan\u0131za tan\u0131mlad\u0131\u011f\u0131n\u0131z anahtarlar ile cookilerinizi \u015fifrelemektedir. Burada \u00e7ok uzun bir anahtar girebilirsiniz , ak\u0131lda tutman\u0131za da gerek yoktur. Dilerseniz her refresh te rastgelen atanan keylerin oldu\u011fu <a title=\"Wordpress Secret Key\" href=\"http:\/\/api.wordpress.org\/secret-key\/1.1\/\" target=\"_blank\">http:\/\/api.wordpress.org\/secret-key\/1.1\/<\/a> adresindeki anahtarlar\u0131, oldu\u011fu hali ile wp-config dosyan\u0131zda kullanabilirsiniz.<\/p>\n<p><!--more--><\/p>\n<h2><strong>4- WordPress G\u00fcncellemelerini Ka\u00e7\u0131rmay\u0131n<\/strong><\/h2>\n<p>Her zaman wordpress in son s\u00fcr\u00fcm\u00fc ile \u00e7al\u0131\u015f\u0131n , hem wordpress i , hem kulland\u0131\u011f\u0131n\u0131z eklentileri s\u00fcrekli paneliniz \u00fczerinden g\u00fcncelleyin. WordPress bu konuda \u00e7ok ba\u015far\u0131l\u0131d\u0131r.<strong><\/strong><\/p>\n<h2><strong>5- .htaccess ile wp-config Dosyan\u0131z\u0131 Koruyun<\/strong><\/h2>\n<p>wp-config dosyas\u0131, wordpress i\u00e7in en \u00f6nemli bilgileri saklayan dosyam\u0131zd\u0131r. Bu dosyan\u0131n d\u0131\u015far\u0131dan eri\u015filebilir olmas\u0131n\u0131 istemeyiz , aksi durumda veritaban\u0131 bilgilerimizi k\u00f6t\u00fc niyetli birilerinin eline teslim etmi\u015f olabiliriz.<\/p>\n<p>Bu dosyay\u0131 korumak i\u00e7in .htaccess dosyalar\u0131ndan yararlanabiliriz , K\u00f6k dizininiz i\u00e7in bir <strong>.htaccess<\/strong> dosyas\u0131 olu\u015fturun ve i\u00e7ine a\u015fa\u011f\u0131daki kodu girin , hepsi bu kadar.<\/p>\n<div id=\"wpshdo_2\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_2\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_2\"><\/a><a id=\"wpshat_2\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_2\"  onClick=\"javascript:wpsh_toggleBlock(2)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_2\" onClick=\"javascript:wpsh_code(2)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_2\" onClick=\"javascript:wpsh_print(2)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_2\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"powershell\" style=\"font-family:monospace;\"><span class=\"sy0\">&lt;<\/span>files wp<span class=\"sy0\">-<\/span>config.php<span class=\"sy0\">&gt;<\/span>\norder allow<span class=\"sy0\">,<\/span>deny\ndeny from all\n<span class=\"sy0\">&lt;\/<\/span>files<span class=\"sy0\">&gt;<\/span><\/pre><\/div><\/div>\n<h2><strong>6- WordPress Versiyonunuzu Gizleyin<\/strong><\/h2>\n<p>Bilindi\u011fi \u00fczere wordpress sitelerde , browser da\u00a0 kayna\u011f\u0131 g\u00f6r\u00fcnt\u00fcleme i\u015flemi yapt\u0131m\u0131zda wordpress versiyonumuzu g\u00f6rebiliriz , e\u011fer son s\u00fcr\u00fcm wordpress kullan\u0131yor iseniz bunun \u015fimdilik bir riski bulunmamaktad\u0131r fakat daha eski bir versiyon kullan\u0131yor iseniz bu hackerlar i\u00e7in \u00e7ok b\u00fcy\u00fck bir \u00f6neme sahiptir , hemen bu versiyon ile ilgili a\u00e7\u0131klar\u0131 \u00fczerinizde denerler. Kapatmak i\u00e7in en pratik yol kulland\u0131\u011f\u0131n\u0131z teman\u0131n <strong>functions.php<\/strong> isimli dosyas\u0131nda uygun bir alana a\u015fa\u011f\u0131daki kodu girip browserda testini yap\u0131n\u0131z.<\/p>\n<div id=\"wpshdo_3\" class=\"wp-synhighlighter-outer\"><div id=\"wpshdt_3\" class=\"wp-synhighlighter-expanded\"><table border=\"0\" width=\"100%\"><tr><td align=\"left\" width=\"80%\"><a name=\"#codesyntax_3\"><\/a><a id=\"wpshat_3\" class=\"wp-synhighlighter-title\" href=\"#codesyntax_3\"  onClick=\"javascript:wpsh_toggleBlock(3)\" title=\"Click to show\/hide code block\">Source code<\/a><\/td><td align=\"right\"><a href=\"#codesyntax_3\" onClick=\"javascript:wpsh_code(3)\" title=\"Show code only\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/code.png\" \/><\/a>&nbsp;<a href=\"#codesyntax_3\" onClick=\"javascript:wpsh_print(3)\" title=\"Print code\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/printer.png\" \/><\/a>&nbsp;<a href=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/About.html\" target=\"_blank\" title=\"Show plugin information\"><img decoding=\"async\" border=\"0\" style=\"border: 0 none\" src=\"https:\/\/www.ayhanarda.com\/blog\/wp-content\/plugins\/wp-synhighlight\/themes\/default\/images\/info.gif\" \/><\/a>&nbsp;<\/td><\/tr><\/table><\/div><div id=\"wpshdi_3\" class=\"wp-synhighlighter-inner\" style=\"display: block;\"><pre class=\"php\" style=\"font-family:monospace;\">remove_action<span class=\"br0\">&#40;<\/span><span class=\"st_h\">'wp_head'<\/span><span class=\"sy0\">,<\/span> <span class=\"st_h\">'wp_generator'<\/span><span class=\"br0\">&#41;<\/span><span class=\"sy0\">;<\/span><\/pre><\/div><\/div>\n<p>Devam\u0131 geliyor..<\/p>\n<p><a title=\"Wordpress Hosting\" href=\"http:\/\/www.webhostingsitesi.com\" target=\"_blank\">G\u00fcvenli wordpress hosting<\/a> i\u00e7in bu linkteki <a title=\"WebHosting\" href=\"http:\/\/www.webhostingsitesi.com\" target=\"_blank\">linux hosting<\/a> paketlerini tercih edebilirsiniz.<\/p>\n<p>Ayhan Arda<\/p>\n<div style=\"padding-bottom:20px; padding-top:10px;\" class=\"hupso-share-buttons\"><!-- Hupso Share Buttons - https:\/\/www.hupso.com\/share\/ --><a class=\"hupso_toolbar\" href=\"https:\/\/www.hupso.com\/share\/\"><img decoding=\"async\" src=\"https:\/\/static.hupso.com\/share\/buttons\/lang\/tr\/share-medium.png\" style=\"border:0px; padding-top: 5px; float:left;\" alt=\"Share Button\"\/><\/a><script type=\"text\/javascript\">var hupso_services_t=new Array(\"Twitter\",\"Facebook\",\"Google Plus\",\"Pinterest\",\"Linkedin\");var hupso_background_t=\"#EAF4FF\";var hupso_border_t=\"#66CCFF\";var hupso_toolbar_size_t=\"medium\";var hupso_image_folder_url = \"\";var hupso_twitter_via=\"ayhanarda\";var hupso_url_t=\"\";var hupso_title_t=\"Wordpress%20G%C3%BCvenlik%20%C3%96nerileri\";<\/script><script type=\"text\/javascript\" src=\"https:\/\/static.hupso.com\/share\/js\/share_toolbar.js\"><\/script><!-- Hupso Share Buttons --><\/div>","protected":false},"excerpt":{"rendered":"WordPress g\u00fcvenli\u011fi ile ilgili \u00e7ok fazla soru gelmekte , Tek tek cevap vermek zorla\u015f\u0131nca bir derleme haline getirmeye karar verdim , umar\u0131m faydal\u0131 olur. 1 &#8211; &#8220;admin&#8221; Y\u00f6netici Ad\u0131n\u0131 Kullanmay\u0131n. WordPress 3.0 s\u00fcr\u00fcm\u00fcnden sonra bu ismi de\u011fi\u015ftirme opsiyonunu art\u0131k sunmakta , \u00f6ncelikle bunu de\u011fi\u015ftirmenizi \u00f6neriyorum , tahmin edersiniz ki bir sitenin wordpress oldu\u011funu \u00f6\u011frendikten sonra [&hellip;]","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[113,13,313,3],"tags":[333,330,811,328,332,326,324,327,331,325,329],"class_list":["post-466","post","type-post","status-publish","format-standard","hentry","category-hosting","category-ipucu","category-security","category-wordpress","tag-hacking-wordpress","tag-secure-wp","tag-wordpress","tag-wordpress-guvenlik","tag-wordpress-hack","tag-wordpress-security","tag-wp","tag-wp-guvenligi","tag-wp-hack","tag-wp-security","tag-wp-config-security"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/466","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/comments?post=466"}],"version-history":[{"count":14,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/466\/revisions"}],"predecessor-version":[{"id":478,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/posts\/466\/revisions\/478"}],"wp:attachment":[{"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/media?parent=466"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/categories?post=466"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ayhanarda.com\/blog\/wp-json\/wp\/v2\/tags?post=466"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}