‘Security’ Videos

  • John Lu: WordPress 基本安全性檢測與防範方式 / WordPress Security Check and How to Prevent Them

    WordCamp Taipei 2019Speaker: John Lu

    June 16, 2020 — 本主題將針對使用 VPS 自架站的人提出一些基本的網站安全性檢測與防範,包含 WordPress 資訊隱藏、目錄權限設定、Security Header 檢測與設定、.htaccess 安全性設定、簡易的自動化備份流程等等,希望在自架站的同時,也能對於基本的資安知識有所瞭解。 接著也會介紹網站被駭之後的處理方式,包含網站復原、重新提交網頁漏洞檢測報告(Sucuri、McAfee),避免被防毒軟體當作惡意網站阻擋。

    Presentation Slides »

  • Alfonso Frachelle: No voy a hablar de seguridad

    WordCamp Montevideo 2018Speaker: Alfonso Frachelle

    May 29, 2020 — ¿Por qué y cómo debo asegurar mi WordPress? Alfonso Frachelle nos muestra las mejores práctica para que tu sitio web hecho en WordPress no tenga brechas de seguridad.

  • Fast alles zum Thema WordPress Sicherheit

    WordPress Meetup PotsdamSpeaker: Bernhard Kau

    May 14, 2020 — Bernhard erklärt in seiner Session zum Thema “(Fast) Alles zum Thema Sicherheit” worauf es ankommt. Die drei wichtigsten Aspekte: Updates, Backups und ein starkes Passwort.
    Weitere Sicherheitsaspekte die möglich sind, beschreibt Bernhard als optional oder gar unnötig.

    Presentation Slides »

  • Nigel Pentland: Security testing – outside looking in

    WordCamp Glasgow 2020Speaker: Nigel Pentland

    April 22, 2020 — I’ll start by trying to convince folks why they should be considering the subject of security testing in relation to their WordPress sites. Assuming I’ve managed to convince you why, then I’ll move onto showing you just how anyone can use Kali (don’t worry, I’ll explain what Kali is!) as a tool for doing some basic security testing with a minimal learning curve to get started. This is being aimed at the novice level in terms of ‘security people’ but very inclusive in terms of anyone who is part of the WordPress community.

  • Georg Knabl: Ein Drittel des Internets hacken? WordPress-Sicherheit aus der Sicht eines Hackers

    WordCamp Vienna 2020Speaker: Georg Knabl

    April 18, 2020 — Die große Verbreitung von WordPress macht es zu einem interessanten Ziel für Angreifer. Dieser Talk zeigt das beliebteste CMS aus Sicht eines Angreifers: Welche Sicherheitsmechanismen bringt WordPress mit? Wo sind generelle Schwachstellen? Wie laufen typische Angriffe ab? Darüber hinaus werden konkrete Angriffe exemplarisch erläutert.
    Die vorgestellten Schwachstellen bieten Entwicklern und Betreibern einer WordPress-Installation die Basis für folgende Absicherungsmaßnahmen.

    Presentation Slides »

  • Chathu Vishwajith: Hardening WordPress and Driving a Vehicle

    WordCamp Utrecht 2018Speaker: Chathu Vishwajith

    February 25, 2020 — I would like to talk about recent serious security incidents had with WordPress installations and Start with the general points that anybody who is going to use or currently using WordPress needs to put their attention compared with driving a vehicle. Then I will suggest few plugins and services that I use and will request the audience to engage and let their suggestions too.I have mastered Art of hardening WordPress installation more than 30+ in Sri Lanka and other clients abroad.

  • Mikey Veenstra: 3 Security Mistakes You Didn’t Realize You Made

    WordCamp Portland 2018Speaker: Mikey Veenstra

    December 31, 2019 — We all take shortcuts sometimes. Whether you were swamped with client work and a corner had to be cut, or you’re stretched so thinly trying to wear every hat that something fell through the cracks, we’ve all encountered mistakes we made ourselves. While they’re mostly all forgivable, it becomes a bit of a different issue when a mistake leads to a security concern. In this talk we’ll look at three common security mistakes made by WordPress site owners every day, why they get made in the first place, and how to resolve them.

    Presentation Slides »

  • Vladimir Smitka: WordPress through the bad guys’ glassed

    WordCamp Europe 2019Speaker: Vladimír Smitka

    December 30, 2019 — Vladimír will give a 10-minute preview of common but not often-mentioned mistakes he saw during security scans of WordPress sites, specifically: Username and email leaking, full path disclosures, accessible backups, open .git repositories and DoS capable endpoints. He will also provide tips on how to reduce risks, where it is worth restricting access, how to enable Bcrypt password hashing and 2FA, and what configuration directives you need to check.

  • Todd Dow: WordPress Security 101

    WordCamp Niagara 2019Speaker: Todd Dow

    December 30, 2019 — Security is hard. And scary. And oh so confusing. But it doesn’t have to be that way. With WordPress, the basics are built in and you’re a simple checklist away from hardening your WordPress site like a pro. In this session, Todd will use plain english, entertaining stories and an all encompassing top 10 list to take you from newbie to knowledgeable in less than an hour.

  • Mikey Veenstra: What The Hack? Fortifying Your Security by Understanding Your Adversary

    WordCamp Seattle 2018Speaker: Mikey Veenstra

    December 19, 2019 — Malicious activity is an unfortunate reality when maintaining a web presence today. Most people involved in the web industry know someone who encountered the aftermath of a disruptive attack–if they haven’t themselves. Because of this, awareness of security best practices is at an all-time high. To many, though, it may not be clear exactly why these measures are important.

    To remedy that, we’ll be taking a practical look at what’s actually happening when a website gets attacked, as well as discussing the hows and whys along the way. From understanding why small sites still get hacked, to why password reuse is really as bad as everyone says, we’ll explore the rationale behind the security principles you’re always being told to follow.

    Presentation Slides »