LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-15-2013, 01:22 PM   #1
pingu
Senior Member
 
Registered: Jul 2004
Location: Skuttunge SWEDEN
Distribution: Debian preferably
Posts: 1,350

Rep: Reputation: 127Reputation: 127
Upgrade & secure old wordpress site


This is about a very old site running WP 2.6.
It has not been properly maintained. There are 56000 spam comments as of today.

My job is to take care of this site, remove all spam, upgrade wordpress to newest version and add spam-control.
So I add spam-control, change admin password - and still comments keep coming in as approved!?
The site has only one administrator account, but lots of "user" accounts (it belongs to a webshop). But there are no other accounts with admin privileges, this I have checked in the database/mysql from cli.

My question number 1, to put it simple:
*How can comments be approved without admin approval*???

Question 2:
Am I doing the wrong thing here, just trying to upgrade & secure this site? Is it really possible to make a wp-site this old secure?
Maybe I should just rebuild everything from scratch - but then, the owner doesn't have the money to pay for that...
 
Old 09-15-2013, 01:52 PM   #2
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
Apologies if you've thought about this already, as I've no direct knowledge of Wordpress, but couldn't you back-up the database and files, install the latest Wordpress and restore the backup?
http://codex.wordpress.org/WordPress_Backups
 
Old 09-15-2013, 02:05 PM   #3
pingu
Senior Member
 
Registered: Jul 2004
Location: Skuttunge SWEDEN
Distribution: Debian preferably
Posts: 1,350

Original Poster
Rep: Reputation: 127Reputation: 127
Yes, I could do that. It might be better/safer than just upgrading?
But if somebody succeded in hacking the old site and I just restore the old database to the new site, doesn't that mean he'll still have access?
If that's what happened?
 
Old 09-15-2013, 02:09 PM   #4
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
the benefit of re-installing is that if somebody left a rogue file around you will be removing it. It's a good point about the database though. I'm afraid, as I said, I've no experience with Wordpress but hopefully somebody who has is reading.
 
Old 09-15-2013, 09:24 PM   #5
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,323
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
In your WordPress dashboard, go to Settings-->Discussion.

That's where comment settings reside. The default is to allow comments as long as user provides an email address.

On my own blog, I allow comments, but close them on a post after it is seven days old, and I use Akismet. Closing comments after seven days was a recent decision which has done wonders in reducing the number of spam comments which I receive. I also close comments on all "pages."

Akismet captures almost all spam comments and puts them in a special place where you can review and delete them. Just overnight last night, Akismet quarantined 62 spam comments (If you want to see my blog, the link is in my profile.)

In the years I've used Akismet, it's missed fewer than a dozen spams. It's so reliable that I don't even review the comments it marks as spam any more; I just delete them.

Also check the "Comment Moderation" area in the "Discussion Settings." You can create special conditions (number of links, keywords, etc.) that send comments into the moderation queue.

With judicious use of these rules, I have been able to avoid forcing all comments into moderation at my own blog.

I do not use third-party comment systems, such as Disqus. They are annoying.

Last edited by frankbell; 09-15-2013 at 09:35 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't export wordpress site harry_ord Programming 1 07-12-2013 03:27 PM
LXer: How To Put Your Shields Up To Protect Your WordPress Site LXer Syndicated Linux News 0 04-22-2013 05:32 PM
Publish Wordpress site in Suse Linux RLx86 Linux - Newbie 7 01-07-2010 03:19 AM
no email functionality on self-hosted wordpress site GTBlackwell Linux - Server 0 08-12-2009 09:02 AM
Redirecting Apache2 to Wordpress site by default GTBlackwell Linux - Software 1 09-11-2008 02:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration