Showing posts with label keamanan. Show all posts
Showing posts with label keamanan. Show all posts

Thursday, May 28, 2015

Plugin Wordpress untuk Scan website yang di hack

Wordfence Security

Wordfence Security is a free enterprise class security and performance plugin that makes your site up to 50 times faster and more secure.
Wordfence starts by checking if your site is already infected. We do a deep server-side scan of your source code comparing it to the Official WordPress repository for core, themes and plugins. Then Wordfence secures your site and makes it up to 50 times faster.
Wordfence Security is 100% free. We also offer a Premium API key that gives you access to our premium support ticketing system at support.wordfence.com along with two factor authentication via SMS, country blocking and the ability to schedule scans for specific times.
You can find our official documentation at docs.wordfence.com and our Frequently Asked Questions on our support portal at support.wordfence.com. We are also active in our community support forums on wordpress.org if you are one of our free users.
This is a brief introductory video for Wordfence:
The following video is an introduction to Falcon Engine, the new caching engine included in Wordfence 5 which will make your site up to 50 times faster than a standard WordPress installation.
Wordfence Security is now Multi-Site compatible and includes Cellphone Sign-in which permanently secures your website from brute force hacks.
Wordfence Security:
  • Includes Falcon Engine, the fastest WordPress caching engine available today. Falcon is faster because it reduces your web server disk and database activity to a minimum.
  • Fully IPv6 compatible including all whois lookup, location, blocking and security functions.
  • Includes support for other major plugins and themes like WooCommerce.
  • Real-time blocking of known attackers. If another site using Wordfence is attacked and blocks the attacker, your site is automatically protected.
  • Sign-in using your password and your cellphone to vastly improve login security. This is called Two Factor Authentication and is used by banks, government agencies and military world-wide for highest security authentication.
  • Includes two-factor authentication, also referred to as cellphone sign-in.
  • Scans for the HeartBleed vulnerability - included in the free scan for all users.
  • Wordfence includes two caching modes for compatability and has cache management features like the ability to clear the cache and monitor cache usage.
  • Enforce strong passwords among your administrators, publishers and users. Improve login security.
  • Scans core files, themes and plugins against WordPress.org repository versions to check their integrity. Verify security of your source.
  • Includes a firewall to block common security threats like fake Googlebots, malicious scans from hackers and botnets.
  • Block entire malicious networks. Includes advanced IP and Domain WHOIS to report malicious IP's or networks and block entire networks using the firewall. Report security threats to network owner.
  • See how files have changed. Optionally repair changed files that are security threats.
  • Scans for signatures of over 44,000 known malware variants that are known security threats.
  • Scans for many known backdoors that create security holes including C99, R57, RootShell, Crystal Shell, Matamu, Cybershell, W4cking, Sniper, Predator, Jackal, Phantasma, GFS, Dive, Dx and many many more.
  • Continuously scans for malware and phishing URL's including all URL's on the Google Safe Browsing List in all your comments, posts and files that are security threats.
  • Scans for heuristics of backdoors, trojans, suspicious code and other security issues.
  • Checks the strength of all user and admin passwords to enhance login security.
  • Monitor your DNS security for unauthorized DNS changes.
  • Rate limit or block security threats like aggressive crawlers, scrapers and bots doing security scans for vulnerabilities in your site.
  • Choose whether you want to block or throttle users and robots who break your security rules.
  • Includes login security to lock out brute force hacks and to stop WordPress from revealing info that will compromise security.
  • See all your traffic in real-time, including robots, humans, 404 errors, logins and logouts and who is consuming most of your content. Enhances your situational awareness of which security threats your site is facing.
  • A real-time view of all traffic including automated bots that often constitute security threats that Javascript analytics packages never show you.
  • Real-time traffic includes reverse DNS and city-level geolocation. Know which geographic area security threats originate from.
  • Monitors disk space which is related to security because many DDoS attacks attempt to consume all disk space to create denial of service.
  • Wordfence Security for multi-site also scans all posts and comments across all blogs from one admin panel.
  • WordPress Multi-Site (or WordPress MU in the older parlance) compatible.
  • Premium users can also block countries and schedule scans for specific times and a higher frequency.
Wordfence Security is full-featured and constantly updated by our team to incorporate the latest security features and to hunt for the newest security threats to your WordPress website.

https://wordpress.org/plugins/wordfence/

Cara memulihkan website berbasis wordpress terkena hack (deface)

Hai kawan, diposting kali ini aku akan membahas mengenai cara mengatasi hack deface pada wordpress. Aktivitas hacking yang dilakukan oleh para cybercrime sangat meresahkan belakangan ini. Beberapa hari yang lalu aku mengalami pengalaman yang tidak mengenakkan ini dimana salah satu web buatanku yang berbasis wordpress (wp) dihack oleh seseorang atau lebih tepatnya deface. Deface adalah salah satu aktivitas hacking yang merubah tampilan halaman (page) website atau blog dan bahkan tampilan wordpress admin (halaman wordpress tempat kita mengatur website kita). Untuk beberapa orang yang mengerti tentang deface dan hacking mungkin tidak akan bermasalah karena mereka bisa memulihkannya kembali, tapi bagi orang yang awam dengan hacking, ini menjadi masalah yang sangat besar. Tapi tenang saja, karenamasalah ini bisa diatasi!
Berikut ini adalah beberapa hal yang bisa kamu lakukan jika web berbasis wordpressmu terkena deface (dihack) :
1.      Jangan panik! Beberapa orang yang awam terhadap deface atau hacking tentu saja akan panik setelah melihat tampilan websitenya yang sempurna berubah menjadi sesuatu yang aneh (biasanya berisi pesan dari hacker dengan background hitam). Seseorang yang panik, kemungkinan besar akan melakukan tindakan yang ceroboh seperti menyalahkan pihak penyedia hosting, meminta pertolongan orang lain yang mungkin Kamu bahkan tidak mengenalnya, atau memutuskan menghapus instalasi wordpress dan memulainya dari awal atau bahkan lapor polisi karena mengira ini adalah tindakan kriminal yang serius. Untuk catatan, tidak semua hacker itu kriminal, mungkin tujuan dari deface ini adalah untuk memperingatkan kamu bahwa keamanan yang ada masih sangat minim J
2.       Coba login wp-mu! Sebagian besar hacker akan merubah username dan password wp, cobalah login ke wpmu untuk mengetahui apakah username dan password masih bisa digunakan atau tidak atau bahkan tampilan wp-login juga terkena deface. Jika tidak bisa dibuka, kamu bisa mengirimkan tiket kepada penyedia hosting untuk merubah username dan password atau mereset ulang password dan username-mu dari cpanel. Caranya login ke cpanel, masuk ke menuphpMyAdmin >> buka instalasi wp-mu >> cari wp_user >> lalu ganti password, e-mail dan username yang ada di kolom option dengan cara menekan edit, setelah itu save perubahannya.
3.       Memulihkan websitemu. Setelah pasword dan username kelar, kembali ke home page cpanel, cari file manager >> Setelah ketemu, klik dan pilih public_html >> cari file bernamaindex.php >> buka dengan menekan menu edit di menubar >> hapus semua isi yang ada di dalam index.php yang dirusak hacker >> perbarui dengan index.php default wp yang bisa kamu download di wordpress.org (di dalam paket wordpress yang didownload dari wordpress.org terdapat index.php, di dalam file ini terdapat script yang harus kamu copy dan pastekan ke index.php yang rusak tadi) setelah itu jangan lupa disave.
4.       Periksa file lain! Selain index.php tadi, periksalah file lain yang kemungkinan telah dirubah oleh hacker. Caranya, kamu harus tahu kapan terakhir kali merubah settingan wp atau kapan deface tersebut terjadi. Jika deface tersebut terjadi hari ini, periksa file manakah yang diubah hari ini dengan melihat last modified. Jika ada yang diubah hacker, segera perbaiki dengan cara mengubah isinya dengan default wp (seperti langkah 3). Jika ada file asing yang mencurigakan atau tidak seharusnya ada di sana (public_html) sebaiknya hapus saja.
5.       Hapus file .htaccess! File tersebut akan ditambahkan lagi secara otomatis ketika kamu login ke wp dan mengedit settingan dasar WordPress lagi (termasuk struktur permalink-nya).
Umumnya 5 cara diatas dapat memulihkan websitemu, tapi beberapa kasus deface yang sangat berat (banyak dile yang diganti) mengharuskan pemilik website untuk merestore backup wp mereka. Untuk melakukan hal ini kamu bisa mengirimkan support tiket kepada penyedia hostingmu.

Untuk mencegah terjadinya hacking pada website kamu, berikut ini adalah beberapa tips yang bisa kamu lakukan :
1.       Selalu update wordpressmu!
2.       Beberapa hacker menggunakan tema sebagai pintu masuk mereka, untuk meinimalisir hal ini, gunakan 1 tema dan hapus yang lain (yang ada di wp-mu).
3.       Gunakan plugin yang terpercaya dan hapus daftar plugin yang tidak kamu pakai.
4.       Gunakan juga plugin security misalnya OSE firewall atau secure wordpress.
5.       Gunakan username dan password yang susah ditebak misalnya W3bS1t3ku atau yang lain (kata2 alay dalam hal ini bisa menjadi sangat berguna karena sulit ditebak :D)
6.       Lakukan backup secara berkala! Untuk mengantisipasi jika wordpress terlanjur disusupi (diinjeksi) file-file jahat dan sulit untuk dicari.

Tips-tips diatas dapat membantu untuk mencegah terjadinya hacking pada wordpress. Semoga posting ini bermanfaat :D

http://my13notes.blogspot.com/2013/04/cara-memulihkan-website-berbasis.html

Meningkatkan keamanan WordPress dengan htaccess

.htaccess adalah sebuah file yang berisi perintah-perintah yang digunakan pada web server apache. Dengan .htaccess, kita dapat memproteksi directory atau file, mengubah asosiasi ekstensi dan handler, redirect halaman, dll. Namun pada artikel ini, saya hanya membahas tentang proteksi saja, khususnya proteksi directory/file pada wordpress.
Sebelumnya, blog ini sudah lumayan seringkena hack atau deface. File yang dirubah oleh hacker tersebut hampir semua sama yaitu file index.php yang terdapat pada folder public_html, dan file-file lain (khususnya file index.php) yang terdapat pada folder wp-admin, wp-include, dan wp-content. Nah dari situlah awalnya saya mencari informasi tentang file .htaccess.
Berikut file .htaccess yang dapat digunakan (sebelum memulai, backup dahulu file htaccess anda):

1. .htaccess untuk wp-admin

Terdapat 2 cara untuk memproteksi foldeer wp-admin yaitu dengan menggunakan ip dan menggunakan password
  1. Dengan Menggunakan IP
    [php]order deny,allow
    allow from xxx.xxx.xxx.xxx
    deny from all[/php]
    Ket : ganti xxx dengan ip anda. Proteksi dengan menggunakan ip bisa digunakan jika ip komputer anda menggunakan ip statis, namun jika ip-nya dinamis gunakan cara yang kedua
  2. Dengan menggunakan password 
    Pada tahap ini, kita harus membuat 2 buah file, yaitu file htpass.txt dan file .htaccess. Pada file htpass.txt isi dengan bantuan genenrator pada htaccesstool. setelah digenerate simpan dengan nama htpass.txt kemudian letakkan pada sembarang directory (JANGAN letakkan di dalam directory public_html)
    Setelah file htpass nya dibuat lalu buat htaccess yang diletakkan di dalam folder wp-admin  dengan isi :[php]ErrorDocument 401 default
    AuthName "Authentication Area"
    AuthUserFile /home/…/…/htpass.txt
    AuthGroupFile /dev/null
    AuthType basic
    require user zzz
    <Files admin-ajax.php>
    Order allow,deny
    Allow from all
    Satisfy any
    </Files>
    [/php]
    Ket : AuthName : isi bebas,  require user : isi dengan nama username anda, AuthUserFile : isi dengan path htpass.txt
    jika berhasil maka ketika ketik yourdomain.com/wp-admin akan muncul :
    auten
Lokai File : Letakkan htaccess-nya di dalam folder wp-admin

2. .htaccess untuk wp-include dan wp-content

[php]Order Allow,Deny
Deny from all
<Files ~ ".(css|jpe?g|png|gif|js)$">
Allow from all
</Files>
[/php]
ket: perintah diatas digunakan untuk membatasi akses pada wp-include dan wp-content kecuali ketika user mengakses file dengan ekstentsi css|jpe?g|png|gif|js. (jikatampilan blog berubah ketika memasang htaccess ini, hapus htaccess pada folder wp-content).
Lokasi File : Letakkan htaccess-nya di dalam folder wp-include dan wp-content

3. .htaccess untuk folder public_html

Untuk selanjutnta, letakkan script htaccess yang akan kita buat nanti di bawah script
[php]# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index.php$ – [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress
[/php]
Script untuk melindungi file wp-config.php
[php]# protect wpconfig.php
<Files wp-config.php>
order allow,deny
deny from all
</Files>
[/php]
Script untuk melindungi file .htaccess itu sendiri
[php]
<Files ~ “^.*.([Hh][Tt][Aa])”>
order allow,deny
deny from all
satisfy all
</Files>
[/php]
Script untuk melindungi file dari script injection
[php]# BEGIN protect WordPress from script injections:
Options +FollowSymLinks
RewriteEngine On
RewriteCond %{QUERY_STRING} (<|%3C).*script.*(>|%3E) [NC,OR]
RewriteCond %{QUERY_STRING} GLOBALS(=|[|%[0-9A-Z]{0,2}) [OR]
RewriteCond %{QUERY_STRING} _REQUEST(=|[|%[0-9A-Z]{0,2})
RewriteRule ^(.*)$ index.php [F,L]
# END[/php]
Lokasi File : Letakkan htaccess-nya di dalam folder root atau public_html
Yak cukup sekian file htaccess yang dibuat, mudah-mudahan blog kita terjaga dari tangan-tangan yang jahil, amiin…

http://risnotes.com/2012/10/meningkatkan-keamanan-wordpress-dengan-htaccess/

Cara Mengatasi dan Memulihkan Blog yang di Hack/Deface

Beberapa hari lalu saya sempat terkejut dengan perubahan yang terjadi pada tampilan blog ini, yang tampil bukanlah halaman yang sebenarnya, tetapi gambar yang bertuliskan bahwa situs ini telah di hack/deface. Sang hacker telah berhasil masuk melalui celah keamanan dan berhasil merubah username dan password serta memasang script-script yang menyebabkan blog ini tidak dapat diakses.
Mengetahui username dan password telah dirubah, saya coba menggunakan fasilitas forgot password. Tetapi setelah memasukkan email yang diminta untuk mendapatkan password dan username kembali, email yang saya masukkan tidak terdaftar yang berarti juga email saya untuk wordpress ini telah dirubah juga oleh sang hacker. Sempat pusing memang, untungnya sang hacker hanyalah merubah tampilan saja dan tidak menghapus konten-konten yang ada, *fiuh untung bukan cracker.
hacker
Akhirnya setelah dicoba bermacam-macam cara, blog ini telah kembali pulih seperti sebelumnya. Berikut merupakan cara-cara yang dilakukan untuk memulihkan blog ini.
1. Dapatkan kembali password dan username anda melalui cpanel atau jika email anda belum dirubah oleh sang hacker, dapat menggunakan fasilitas forgot password. 
2. Perhatikan date modified dari tiap file di dalam folder public_html dan sesuaikan dengan waktu pada saat blog anda kena hack. Jika terdapat kesamaan pada tanggal tersebut, patut dicurigai kalau file tersebut telah dirubah oleh sang hacker
3. cek file-file yang terdapat pada themplate apakah ada file atau script yang mencurigakan dengan cara:
  • Download kembali themplate yang anda gunakan yang berguna sebagai acuan dalam melakukan pengecekan terhadap script-script yang mencurigakan
  •  Setelah didownload cek file index.php dan funtion.php. File inilah biasanya yang paling sering di inject dengan code2 aneh
  • Jika ada code yang mencurigakan atau tidak sama dengan code yang terdapat pada themes yang telah anda download, silahkan dihapus. Biasanya code tersebut berbentuk base64 encode.
  • Kalau anda merasa malas untuk melakukan pengecekan satu persatu, silakan pasang kembali themes yang baru.
4. cek file-file yang terdapat pada wordrpess / public_html(di cpanel)
public_html
  • Download file wordpress di sini (www.wordpress.org). File tersebut akan digunakan sebagai acuan dalam  melakukan pengecekan terhadap script-script yang mencurigakan. Untuk membuka file wordress blog kita yang terletak di public_html bisa melalui cpanel atau filezilla
  • Cek file index.php yang terdapat pada setiap folder wordpress. Jika ada code yang mencurigakan silakan dihapus dan dirubah sesuai dengan file index wordpress yang telah didownload. Biasanya, script yang membuat kita tidak bisa masuk ke halaman dashboard adalah karena file index.php yang terdapat pada folder wp-admin telah dirubah.  jgn lupa untuk mengecek file index di folder wp-content.
  • Selesai
Nah Kalau Blognya sudah kembali seperti semula, alangkan baiknya kalau security di blognya ditingkatkan dengan htaccess. Artikelnya bisa dibaca di Meningkatkan Keamanan WordPress dengan .htaccess dan juga Cara Setting Robot.txt
Yak, itulah cara-cara yang saya lakukan untuk mengembalikkan blog ini. Semoga bermanfaat :)

http://risnotes.com/2012/10/cara-mengatasi-dan-memulihkan-blog-yang-dihackdeface/

Monday, May 25, 2015

SQL Injection - Database Vulnerability

What is it?

SQL injection, is an extremely damaging attack in which hackers will attempt to access information stored in your database, such as customer data or user ID's and passwords. SQL stands for Structured Query Language and is the programming language understood by databases. By inserting commands from this programming language into fields on your website's input forms, hackers can gain access to the database records of vulnerable sites, stealing credit card data, passwords, e-mail addresses and any additional data available in the database.

What is the impact?

The impacts of this type of attack can be devastating. A recent example is the attack carried out on Sony's networks, in which thousands of credit cards were stolen. The company has spent millions to recover. It can also badly damage your company's reputation by exposing your customers' private data to criminals.

How does SiteLock protect me?

SiteLock's patent-pending 360-degree scan technology tests each input box on your website to ensure that they are not vulnerable to this type of attack. We verify the safety of each input box on your website by inserting code in the way hackers would. We do not read or collect any data, however. We use safe test procedures and code and if we discover a vulnerability in our testing, we report it to you immediately. Our Expert Services team can also help you remove these issues from your site.

What can I do about it?

Make sure any applications you use are kept up-to-date and limit the use of third-party plug-in's where possible as they can be a source of many issues and may be updated less frequently or created by unscrupulous publishers. Use a website scanning service that includes SQL injection scans, such as SiteLock Premium or SMB. If you are writing your own code, be sure to validate your input fields for special characters and ensure you are checking for this type of hacking in your database procedures called from the website.
Please read our related article on:

My Account was Hacked!

My Account was Hacked!

HostGator takes security very seriously. Please read the sections below for help with a compromised site.

Steps for Hacked or Compromised Sites

If your site is hacked or compromised, please follow these steps:
  1. Submit a ticket.If you are the victim of a hacker, immediately submit a ticket to report this issue to our Security department. Our administrators will investigate as quickly as possible, both to correct the current issue and to help make sure it does not occur again. If you cannot submit a ticket yourself, please contact us for assistance with this step.
  2. Do not make any changes to the affected site.In the meantime, it is vital that you avoid logging in or making any changes to your account. This lets the necessary time stamps and other forensic data stay in place, which helps your investigation proceed as smoothly as possible.
  3. Watch for updates from our Security admins.Our Security team will notify you via email once the investigation has been completed, or to request additional information if required.
    Note: Only Security Administrators can help you with compromised or hacked sites, and you will be directly contacted via your ticket by the Security agents working your issue. Please submit or reply in your email to your Security ticket for updates.

Free Account Scan

HostGator offers complimentary automated account cleanings when you open a Security ticket for Shared and Reseller accounts with less than 20GB of disk space and below 100k inodes. If you find that something is missed we'll be happy to remove it manually for you.
Note: Cleanings do not include root cause analysis or preventative action, though we will provide you with guidance on basic security precautions. It is the customers responsibility to secure and update their software.
Note: This complimentary service is not available for Dedicated servers, VPS accounts, or Shared and Reseller accounts using more than 20GB or 100k inodes of disk space.
For Shared and Reseller accounts above 20GB or 100k inodes of disk space, customers with Dedicated servers or VPS accounts, or customers wanting a more detailed investigation, we can perform this work manually for a fee.
These cleanings will be quoted for the manual investigation by our Security administrators. Manual investigations will include a full cleaning of the account as well as information regarding the source of account exploitation, provided logs are available and content has not been modified in a way that will interfere with the forensics of the investigation.
Alternatively, you may use a third party cleaning service such as SiteLock for round-the-clock protection of your website.

What to Look For in a Hacked Account

In all cases, we recommend resolution of your issue through some sort of professional service, whether this is done by our Security department or through SiteLock. However, if these options are not available, you may wish to consider removing files or directories which have been recently added and which you do not recognize as part of your site. Things to look for include:
  • Strangely named files or directories (i.e: xf8c3l.php or /home/username/public_html/wellsfargo).
  • PHP files located in image folders.
  • Base64 or other encrypted injections inside of site files which can be removed using file editors.
Again, please do not make changes to your account if it is currently under investigation.
Google Attack Page

If Google's "Reported Attack Site!" page is seen, please refer to the following article for details on how to clean the site and remove the warning:

SQL injection, insertion

SQL injection is an attack where malicious code is passed to an SQL Server for execution. The attack can result in unauthorized access to confidential data, or destruction of critical data.
Before you try to read the methods below, realize that this should only be a concern for PHP developers and the like. If you are using a database driven program (e.g. WordPress, Joomla, OSCommerce), then all you need to do is upgrade your programs to the latest version available.

Methods to prevent SQL injection

Escaping

One way to prevent injections is to escape dangerous characters (i.e. backslash, apostrophe and semicolon). In PHP, it is typical to escape the input using the function mysql_real_escape_string before sending the SQL query. Example:
$Uname = mysql_real_escape_string($Uname);
$Pword = mysql_real_escape_string($Pword);
$query = "SELECT * FROM Users where UserName='$Uname' and Password='$Pword'";
mysql_query($query);

Parameterized statements

A parameterized query uses placeholders for the input, and the parameter values are supplied at execution time.
$params = array($Uname, $Pword);
$sql = 'INSERT INTO Users (UserName, Password) VALUES (?, ?)';
$query = sqlsrv_query($connection, $sql, $params);

Advanced:

In PHP version 5 and above, there are multiple choices for using parameterized statements; the PDO database layer is one of them. There are also vendor-specific methods; for example, MySQL 4.1 + used with the mysqli extension.

Additional Precautions

Scanning for Vulnerabilities

HostGator now offers SiteLock on select hosting plans, which performs forward- and backward-looking scans to make sure current and future visitor/customer data is secure on your website.
For SiteLock subscribers, our patent-pending 360-degree scan technology tests each input box on your website to ensure that they are not vulnerable to this type of attack. We verify the safety of each input box on your website by inserting code in the way hackers would. We do not read or collect any data, however. We use safe test procedures and code and if we discover a vulnerability in our testing, we report it to you immediately. Our Expert Services team can also help you remove these issues from your site.
Find out more here: