<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Sidewalk Cafe Design</title>
	<atom:link href="http://www.sidewalkcafedesign.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sidewalkcafedesign.com</link>
	<description>Just another WordPress site</description>
	<lastBuildDate>Sun, 13 Nov 2011 01:17:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>Comment on Is WordPress secure? by Eliana</title>
		<link>http://www.sidewalkcafedesign.com/is-wordpress-secure/#comment-12</link>
		<dc:creator>Eliana</dc:creator>
		<pubDate>Sun, 13 Nov 2011 01:17:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.sidewalkcafedesign.com/?p=951#comment-12</guid>
		<description>I use a plugin called WordPress Prefix Table Rename, by seo eggheads (http://www.seoegghead.com/software/wordpress-table-rename.seo). And you&#039;re correct, hackers will look for the default table prefix, which is wp_. Here&#039;s what seo eggheads says about why you need to rename your table prefixes.

&quot;Well, it turns out that the majority of exploits we&#039;ve seen against WordPress-based web sites (this one and those for clients) have a very simple signature — they attempt SQL injection attacks with the assumption that the table prefix is set to &quot;wp_.&quot; So why not just change the prefix?&quot;

And here&#039;s what their plugin does. 

1. Creates a duplicate set of tables with the same structure/schema.
1a. Copies a coherent version of the old tables to the new tables.
1b. Makes a few changes to the data in the new tables with regard to the new table names.
(all the while showing all executed queries to keep you informed).

2. Swaps to the newly-created set of tables.

I do have one complaint about the plugin. It&#039;s not in the WordPress repository, so you have to download it from their site, and then ftp it to your site.</description>
		<content:encoded><![CDATA[<p>I use a plugin called WordPress Prefix Table Rename, by seo eggheads (<a href="http://www.seoegghead.com/software/wordpress-table-rename.seo" rel="nofollow">http://www.seoegghead.com/software/wordpress-table-rename.seo</a>). And you&#8217;re correct, hackers will look for the default table prefix, which is wp_. Here&#8217;s what seo eggheads says about why you need to rename your table prefixes.</p>
<p>&#8220;Well, it turns out that the majority of exploits we&#8217;ve seen against WordPress-based web sites (this one and those for clients) have a very simple signature — they attempt SQL injection attacks with the assumption that the table prefix is set to &#8220;wp_.&#8221; So why not just change the prefix?&#8221;</p>
<p>And here&#8217;s what their plugin does. </p>
<p>1. Creates a duplicate set of tables with the same structure/schema.<br />
1a. Copies a coherent version of the old tables to the new tables.<br />
1b. Makes a few changes to the data in the new tables with regard to the new table names.<br />
(all the while showing all executed queries to keep you informed).</p>
<p>2. Swaps to the newly-created set of tables.</p>
<p>I do have one complaint about the plugin. It&#8217;s not in the WordPress repository, so you have to download it from their site, and then ftp it to your site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is WordPress secure? by Thomas</title>
		<link>http://www.sidewalkcafedesign.com/is-wordpress-secure/#comment-11</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Sat, 12 Nov 2011 17:15:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.sidewalkcafedesign.com/?p=951#comment-11</guid>
		<description>You mention, &quot;Rename the tables in the database...&quot; Is that because hackers will look for the default name used in automated WP installations?

And, if so, does renaming the databases require you to update WP&#039;s default scripts, so it can &#039;find&#039; the newly-renamed DB?

Thanks for a very informative post!</description>
		<content:encoded><![CDATA[<p>You mention, &#8220;Rename the tables in the database&#8230;&#8221; Is that because hackers will look for the default name used in automated WP installations?</p>
<p>And, if so, does renaming the databases require you to update WP&#8217;s default scripts, so it can &#8216;find&#8217; the newly-renamed DB?</p>
<p>Thanks for a very informative post!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Is WordPress secure? by Nancy Sloane</title>
		<link>http://www.sidewalkcafedesign.com/is-wordpress-secure/#comment-7</link>
		<dc:creator>Nancy Sloane</dc:creator>
		<pubDate>Thu, 10 Nov 2011 14:34:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.sidewalkcafedesign.com/?p=951#comment-7</guid>
		<description>Thanks Eliana for helping to clear up the confusion!</description>
		<content:encoded><![CDATA[<p>Thanks Eliana for helping to clear up the confusion!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced

Served from: www.sidewalkcafedesign.com @ 2012-02-22 17:48:20 -->
