<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cool WordPress .htaccess Tips to Boost Your WordPress Site&#8217;s Security</title>
	<atom:link href="http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/feed" rel="self" type="application/rss+xml" />
	<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676</link>
	<description>Tech tips, WordPress plugins, WordPress tweaks and Technical tips to build a better blog.</description>
	<lastBuildDate>Wed, 10 Mar 2010 23:52:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: admin</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9387</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 05 Jan 2010 06:49:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9387</guid>
		<description>@Charles, yes you need to replace them with your own domain name. &quot;stealingisbad.gif&quot; is just an image that will be displayed instead of the actual image when someone tries to hotlink. This image can have any message you want.</description>
		<content:encoded><![CDATA[<p>@Charles, yes you need to replace them with your own domain name. &#8220;stealingisbad.gif&#8221; is just an image that will be displayed instead of the actual image when someone tries to hotlink. This image can have any message you want.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9368</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Mon, 04 Jan 2010 14:39:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9368</guid>
		<description>Oh, and what does &quot;stealingisbad.gif&quot; mean in the &#039;disable hotlinking&#039; code?
Is that an image we need to create and upload via FTP in order for disabling of hotlinking to work?

Thanks,
Charles</description>
		<content:encoded><![CDATA[<p>Oh, and what does &#8220;stealingisbad.gif&#8221; mean in the &#8216;disable hotlinking&#8217; code?<br />
Is that an image we need to create and upload via FTP in order for disabling of hotlinking to work?</p>
<p>Thanks,<br />
Charles</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9367</link>
		<dc:creator>Charles</dc:creator>
		<pubDate>Mon, 04 Jan 2010 14:16:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9367</guid>
		<description>Interesting stuff, for a non-coder like me.

In these text snippets, do we replace &quot;?&#039;yourdomain.com&quot; and &quot;!.*yourblog.com.*&quot;
with our own domain names---or do these work as is when dropped into our .htaccess file???

Thank you,
Charles</description>
		<content:encoded><![CDATA[<p>Interesting stuff, for a non-coder like me.</p>
<p>In these text snippets, do we replace &#8220;?&#8217;yourdomain.com&#8221; and &#8220;!.*yourblog.com.*&#8221;<br />
with our own domain names&#8212;or do these work as is when dropped into our .htaccess file???</p>
<p>Thank you,<br />
Charles</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9012</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Wed, 09 Dec 2009 23:37:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9012</guid>
		<description>I use this one: http://alkivia.org/wordpress/capsman/ - it allows me to remove the default admin-account. Will check your suggestion.

The WP -security-scan keeps telling me there is no .htaccess in the WP-Admin dir. - so just ignore it then? Not even some basic code in there?
.-= Jay&#180;s last undefined ..&lt;a href=&quot;0&quot; rel=&quot;nofollow&quot;&gt;If you register your site for free at &lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>I use this one: <a href="http://alkivia.org/wordpress/capsman/" rel="nofollow">http://alkivia.org/wordpress/capsman/</a> &#8211; it allows me to remove the default admin-account. Will check your suggestion.</p>
<p>The WP -security-scan keeps telling me there is no .htaccess in the WP-Admin dir. &#8211; so just ignore it then? Not even some basic code in there?<br />
<span class="cluv"> Jay&#180;s last undefined ..<a href="0" rel="nofollow">If you register your site for free at </a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.tipsandtricks-hq.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9011</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 09 Dec 2009 23:07:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9011</guid>
		<description>If you don&#039;t have static IP then you can&#039;t really restrict by IP so don&#039;t bother putting anything there. Try the login lockdown plugin to add a bit more login protection.</description>
		<content:encoded><![CDATA[<p>If you don&#8217;t have static IP then you can&#8217;t really restrict by IP so don&#8217;t bother putting anything there. Try the login lockdown plugin to add a bit more login protection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9008</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Wed, 09 Dec 2009 12:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9008</guid>
		<description>Sooooooo, not having a static IP Address, not being able to block that address in .htaccess file in Admin folder, what do I put in that file to secure that folder?

I now understand the renaming, but that doesn&#039;t apply to me either, as I don&#039;t have my own server - but yes, good tip, makes sense!
.-= Jay&#180;s last undefined ..&lt;a href=&quot;0&quot; rel=&quot;nofollow&quot;&gt;If you register your site for free at &lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Sooooooo, not having a static IP Address, not being able to block that address in .htaccess file in Admin folder, what do I put in that file to secure that folder?</p>
<p>I now understand the renaming, but that doesn&#8217;t apply to me either, as I don&#8217;t have my own server &#8211; but yes, good tip, makes sense!<br />
<span class="cluv"> Jay&#180;s last undefined ..<a href="0" rel="nofollow">If you register your site for free at </a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.tipsandtricks-hq.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9007</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 09 Dec 2009 12:03:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9007</guid>
		<description>LOL... okay okay I will tell you :)

by default the filename for access control is .htaccess. This is the file that &quot;Apache&quot; will look up to see what restrictions are specified and then it will control the access accordingly when a client makes a request to access your site through the browser.

when you have protection in place the hackers know that it is specified in this file so they will try to attack this file so the protection can be destroyed. You can specify a different name for this access control file in the server configuration file (e.g. httpd.conf, access.conf etc) and &quot;Apache&quot; will look up that file instead. This way anyone from outside has no way of knowing which file to attack because they can&#039;t guess the name of it.

Your server will have other security measures in place so this is not really necessary and in some cases not doable if you don&#039;t have a dedicated server. This is something good to know and do it if you are running your own server from your home PC and you don&#039;t really have a lot of other security measures in place.</description>
		<content:encoded><![CDATA[<p>LOL&#8230; okay okay I will tell you <img src='http://www.tipsandtricks-hq.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>by default the filename for access control is .htaccess. This is the file that &#8220;Apache&#8221; will look up to see what restrictions are specified and then it will control the access accordingly when a client makes a request to access your site through the browser.</p>
<p>when you have protection in place the hackers know that it is specified in this file so they will try to attack this file so the protection can be destroyed. You can specify a different name for this access control file in the server configuration file (e.g. httpd.conf, access.conf etc) and &#8220;Apache&#8221; will look up that file instead. This way anyone from outside has no way of knowing which file to attack because they can&#8217;t guess the name of it.</p>
<p>Your server will have other security measures in place so this is not really necessary and in some cases not doable if you don&#8217;t have a dedicated server. This is something good to know and do it if you are running your own server from your home PC and you don&#8217;t really have a lot of other security measures in place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9006</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Wed, 09 Dec 2009 10:19:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9006</guid>
		<description>Thank you! I don&#039;t have a static IP address, so I need to put something else in the .htaccess in the Admin folder?

Ok, good CHMOD rule.

Renaming: you mention in the last line of your article: 

&quot;Better still, you can rename the .htaccess to any other name you like

# rename htaccess files
AccessFileName ht.access&quot;
.-= Jay&#180;s last undefined ..&lt;a href=&quot;0&quot; rel=&quot;nofollow&quot;&gt;If you register your site for free at &lt;/a&gt; =-.</description>
		<content:encoded><![CDATA[<p>Thank you! I don&#8217;t have a static IP address, so I need to put something else in the .htaccess in the Admin folder?</p>
<p>Ok, good CHMOD rule.</p>
<p>Renaming: you mention in the last line of your article: </p>
<p>&#8220;Better still, you can rename the .htaccess to any other name you like</p>
<p># rename htaccess files<br />
AccessFileName ht.access&#8221;<br />
<span class="cluv"> Jay&#180;s last undefined ..<a href="0" rel="nofollow">If you register your site for free at </a> <span class="heart_tip_box"><img class="heart_tip" alt="My ComLuv Profile" border="0" width="16" height="14" src="http://www.tipsandtricks-hq.com/wp-content/plugins/commentluv/images/littleheart.gif"/></span></span></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-9005</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Wed, 09 Dec 2009 09:49:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-9005</guid>
		<description>Please note that playing around with .htaccess file is dangerous so handle with care.

You can put the content explained in the &quot;Restrict Access to WP Admin directory by IP Address&quot; section in a .htaccess file and put it in the &quot;wp-admin&quot; directory. You will obviously have to modify the a.b.c.d to your IP address (don&#039;t do this if you don&#039;t have static IP address).

Regarding file permission... here is a general rule of thumb... files should have a permission of 644 and directories should have a permission of 755</description>
		<content:encoded><![CDATA[<p>Please note that playing around with .htaccess file is dangerous so handle with care.</p>
<p>You can put the content explained in the &#8220;Restrict Access to WP Admin directory by IP Address&#8221; section in a .htaccess file and put it in the &#8220;wp-admin&#8221; directory. You will obviously have to modify the a.b.c.d to your IP address (don&#8217;t do this if you don&#8217;t have static IP address).</p>
<p>Regarding file permission&#8230; here is a general rule of thumb&#8230; files should have a permission of 644 and directories should have a permission of 755</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://www.tipsandtricks-hq.com/cool-wordpress-htaccess-tips-to-boost-your-wordpress-sites-security-1676/comment-page-1#comment-8991</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Tue, 08 Dec 2009 22:28:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.tipsandtricks-hq.com/?p=1676#comment-8991</guid>
		<description>Nice article - thanks!

Got the following questions:
1 - I use the WP Security Scan plugin (by Semper Fi) - it tells that one thing is incorrect: &quot;The file .htaccess does not exist in wp-admin/. &quot; Now, what do I put in that file? I contacted him last year, I searched all his documentation (which is lacking for this item) and that is how I ended up on your site.
2 - Do I need any other .htaccess files - if yes, where do I put them (root?), what do I put in them and what CHMOD do they get?
3 - As Mugger asked before, how do you apply the renaming? Where do you put what?</description>
		<content:encoded><![CDATA[<p>Nice article &#8211; thanks!</p>
<p>Got the following questions:<br />
1 &#8211; I use the WP Security Scan plugin (by Semper Fi) &#8211; it tells that one thing is incorrect: &#8220;The file .htaccess does not exist in wp-admin/. &#8221; Now, what do I put in that file? I contacted him last year, I searched all his documentation (which is lacking for this item) and that is how I ended up on your site.<br />
2 &#8211; Do I need any other .htaccess files &#8211; if yes, where do I put them (root?), what do I put in them and what CHMOD do they get?<br />
3 &#8211; As Mugger asked before, how do you apply the renaming? Where do you put what?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
