what does it mean when your back end is open and how is that fixed?
| SitePoint Sponsor |



what does it mean when your back end is open and how is that fixed?
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

It means you've got a security issue on the server side of your site. It could mean any of a number of things:
- Your ftp connection isn't secure
- Your hosts control panels security measures don't measure up
- Your database security is lax/missing/easily circumvented.
- If you're using a COTS product, there might be common problems which haven't been patched on your site.
- Your server side coding is lax in preventing sql injections.
Is this a real situation, or are you looking for general ideas? If general, look at the different forums here (this one, database, whatever language your site is using)) and look there for topics which might meet your needs (the database forum has one dealing specifically with #5 above).
If it's a situation, you might need to provide more details so someone can point you in the direction of where to look to fix your issues.



yes it's a real situation, someone told me the backend was open http://www.sakeenaheducationcentre.com
I know ftp is locked.
My hosting is with poweredbypenguins and I'm guessing they are up to speed with security.
How else can I know?
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

I would guess the issue is more with wordpress than your host.



han,
It's likely that the one telling you that you've been hacked is trying to use social engineering to gain your login details (easier than actually hacking a website). If that's not the case, you'd better be prepared to download your entire website and match it with your local version (WinMergeU and BCompare are both good at making comparisons and noting any differences). If you've been hacked, search here for the checklist of recovery tasks I'd posted some months ago.
Regards,
DK
David K. Lynn - Data Koncepts is a long-time WebHostingBuzz (US/UK)
Client and (unpaid) WHB Ambassador
Updated mod_rewrite Tutorial Article (setup, config, test & write
mod_rewrite regex w/sample code) and Code Generator



I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

Start a blog, they said. People will read it, they said.



I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

Nah, that plugin allows you to clone a post or page, or edit it as a new draft.
To back up your site, basically you need to do two things:
1. Backup your database(s)
2. Backup all of the assets (e.g. images, theme files etc.)
Let's start with point 1.
You can either do this by loging into your hosting company's admin area and using whatever functionality the offer you (probably PHPMyAdmin)
Or, installing a plugin, such as this one, which will do it for you.
You might also want to read: http://codex.wordpress.org/Backing_Up_Your_Database
After that, the easiest way to get to your files, is to connect to your webspace, via FTP, find your root WP folder (it will contain folders such as "wp-admin" and "wp-content"), then just copy this to your local PC.
If you don't have FTP access for whatever reason, there is a plugin that claims to do it for you.
You might also want to read: http://codex.wordpress.org/WordPress_Backups
And that's it.
Personally, I do both of these things by hand, so I can't recommend the plugin as I simply haven't used it.
Anyone else?
Start a blog, they said. People will read it, they said.



oh that sounds easy. I'll wait for a recommendation on that plug. Otherwise where do I go in phpadmin to back up?
To copy my root do I copy the public_html and all inside that?
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

In PHPMyAdmin, select the db, click the tab marked "Export", keep the defaults, but choose "Save as file" (this might be hidden under "Advanced options" or something), and that's it.
It can't hurt to have a backup of everything on the server.
Strictly speaking all you need is the directory titled "wp-content", but I would go one level above that, then you've got a copy of everything related to the WP install.
HTH
Start a blog, they said. People will read it, they said.



easy peezy! I didn't even need to access phpmyadmin as they had a backup button in my control panel so I clicked that and it saved to my pc in a .txt ( hope that's right )
Plus now in the process of transfering all files via ftp...
Thanks I'm now backed up and about to do the same for all my other sites!
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

Yup, it should be a plain text file.
It is probably worth opening it and searching for a string that you know you added to the site recently.
E.g. When I back up my DB after updating my blog, I open the backup file and search for the title of my last blog post. that way you know that you have got the latest version.
Good on you!
Start a blog, they said. People will read it, they said.

Don't forget to password protect your "backend"!!! Use the password your host can generate for you OR use a strong one from strongpasswordgenerator.com.
Regards,
DK
David K. Lynn - Data Koncepts is a long-time WebHostingBuzz (US/UK)
Client and (unpaid) WHB Ambassador
Updated mod_rewrite Tutorial Article (setup, config, test & write
mod_rewrite regex w/sample code) and Code Generator





Your host has nothing to do with the security of your backend; by being open it means it`s vulnerable to attacks, so you should be looking for an upgrade to the CMS you`re using.



I see, will mke sure I keep updating!
@pullo if I want to take this back up I did of the database and files and put it onto a sub directory, how do I do thast? Do you know of a tutorial that I can follow?
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

Not sure I follow you.
Could you elaborate a little on what you are trying to do.
On a separate note, I almost didn't see this question.
If you want to get someone's attention you can mention them by writing an at sign "@" followed by the user name "pullo" a space " " and a semicolon ";"
Like this: @hantaah ;
This will then show up in that person's notifications when they log in.
Start a blog, they said. People will read it, they said.



@Pullo ; I see thanks for that @TechnoBear and thank you also
you helped me make a back up ( above ) so I have a plain text file of the data base and all the files from the public_html. So I now want to take all this and place it on my new url but on a sub directory. I though to do this so that if any of muy clients don't keep their hoting going then I can still link to my work ( fully working )
so for example I'd have my url http://organicwebdesigns.co.uk and then another wordpress site on a sub directory like this http://organicwebdesigns.co.uk/my-first-project and so on. So How do I get this back up above to work on my sub directory. I tried just uploading it into the sub directory but that didn't work.
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

Hi,
Have you installed a second WP instance at http://organicwebdesigns.co.uk/my-first-project?
Start a blog, they said. People will read it, they said.



not yet as not sure of the proper way but if I need to will install. Should I?
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales



I can install wordpress fine on my subdomains but I need to know how to get the backed up files I made for say sakeenaheducation.com onto say organicwebdesigns.co.uk/sakeenah-education
So far I installed wordpress onto a subdomain and via ftp I uploaded the backup files I have from themes folder upwards. nothing and when I log onto the new subdomain admin ( I thought perhaps uploaded theme needs to be activated ) it says the theme is there but there is an error as it needs css files etc but looking in the files all the files css etc are there.
I learnt design from Ben Hunt's Pro Web Design Course
For For Women In Business
For Home School Education in Wales

Sorry for the quick reply, I'm just on my way out.
You also need to reimport the database backup you made of your original site (presuming you want the page structure and content to be available).
If you don't know how let me know and I'll post more later on.
Start a blog, they said. People will read it, they said.
Bookmarks