- Unduh Pembaruan Definisi untuk melindungi dari ancaman baru.
- Jalankan Pemindaian Lengkap untuk secara otomatis menghapus ancaman keamanan yang diketahui, skrip pintu belakang, dan injeksi database.
- Firewall memblokir SoakSoak dan malware lain agar tidak mengeksploitasi Revolution Slider dan plugin lain dengan kerentanan yang diketahui.
- Lakukan upgrade versi skrip timthumb yang rentan.
Fitur Premium:
- Tambal wp-login dan XMLRPC Anda untuk memblokir serangan Brute-Force dan DDoS.
- Periksa integritas berkas WordPress Core Anda.
- Secara otomatis mengunduh Pembaruan Definisi baru saat menjalankan Pemindaian Lengkap.
Daftarkan plugin ini di GOTMLS.NET dan dapatkan akses ke definisi baru “Ancaman yang Diketahui” dan fitur tambahan seperti Penghapusan Otomatis, ditambah tambalan untuk kerentanan keamanan tertentu seperti timthumb versi lama. File definisi yang diperbarui dapat diunduh secara otomatis di dalam admin setelah Kunci Anda terdaftar. Jika tidak, plugin ini hanya memindai “Ancaman Potensial” dan menyerahkannya kepada Anda untuk mengidentifikasi dan menghapus yang berbahaya.
NOTICE: This plugin make call to GOTMLS.NET to check for updates not unlike what WordPress does when checking your plugins and themes for new versions. Staying up-to-date is an essential part of any security plugin and this plugin can let you know when there are new plugin and definition update available. If you’re allergic to “phone home” scripts then don’t use this plugin (or WordPress at all for that matter).
Terima kasih khusus kepada:
- Clarus Dignus untuk saran desain dan pekerjaan desain grafis pada gambar spanduk.
- Jelena Kovacevic and Andrew Kurtis of for providing the Spanish translation.
- Marcelo Guernieri untuk terjemahan bahasa Portugis Brasil.
- Umut Can Alparslan untuk terjemahan bahasa Turki.
- Micha Cassola for the German translation.
- Robi Erwin Setiawan for the Indonesian translation.
- Unduh dan ekstrak plugin ke direktori plugin WordPress Anda (biasanya
). - Aktifkan plugin melalui menu ‘Plugins’ di Admin WordPress Anda.
- Daftar di dan unduh pembaruan definisi terbaru untuk memindai Ancaman yang Diketahui.
Tanya Jawab
Mengapa saya harus mendaftar?
If you register on GOTMLS.NET you will have access to download definitions of New Threats and added features like automatic removal of “Known Threats” and patches for specific security issues like old versions of timthumb and brute-force attacks on wp-login.php. Otherwise, this plugin only scans for “Potential Threats” on your site, it would then be up to you to identify the good from the bad and remove them accordingly.
How do I patch the Revolution Slider vulnerability?
Mudah, jika Anda telah menginstal dan mengaktifkan plugin Anti-Malware saya ini di situs Anda, maka secara otomatis akan memblokir upaya untuk mengeksploitasi kerentanan Revolution Slider.
How do I patch the wp-login vulnerability?
The WordPress Login page is susceptible to a brute-force attack (just like any other login page). These types of attacks are becoming more prevalent these days and can sometimes cause your server to become slow or unresponsive, even if the attacks do not succeed in gaining access to your site. This plugin can apply a patch that will block access to the WordPress Login page whenever this type of attack is detected. Just click the Install Patch button under Brute-force Protection on the Anti-Malware Setting page. For more information on this subject read my blog.
Mengapa saya tidak dapat secara otomatis menghapus “Potensi Ancaman” pada warna kuning?
Many of these files may use eval and other powerful PHP function for perfectly legitimate reasons and removing that code from the files would likely cripple or even break your site so I have only enabled the Auto remove feature for “Know Threats”.
Bagaimana saya tahu jika ada “Potensi Ancaman” yang berbahaya?
Click on the linked filename to examine it, then click each numbered link above the file content box to highlight the suspicious code. If you cannot tell whether or not the code is malicious just leave it alone or ask someone else to look at it for you. If you find that it is malicious please send me a copy of the file so that I can add it to my definition update as a “Know Threat”, then it can be automatically removed.
Bagaimana jika pemindaian macet di tengah jalan?
First just leave it for a while. If there are a lot of files on your server it could take quite a while and could sometimes appear to not be moving along at all even if it really is working. If it still seems stuck after a while then try running the scan again, be sure you try both the Complete Scan and the Quick scan.
Bagaimana saya bisa diretas sejak awal?
First, don’t take the attack personally. Lots of hackers routinely run automated script that crawl the internet looking for easy targets. Your site probably got hacked because you are unknowingly an easy target. This might be because you are running an older version of WordPress or have installed a Plugin or Theme with a backdoor or known security vulnerability. However, the most common type of infection I see is cross-contamination. This can happen when your site is on a shared server with other exploitable sites that got infected. In most shared hosting environments it’s possible for hackers to use an one infected site to infect other sites on the same server, sometimes even if the sites are on different accounts.
Apa yang dapat saya lakukan untuk mencegahnya terjadi lagi?
Tidak ada cara pasti untuk melindungi situs Anda dari segala jenis upaya peretasan. Meski begitu, jangan jadi sasaran empuk. Beberapa langkah dasar harus mencakup: memperkuat kata sandi Anda, menjaga semua situs Anda tetap mutakhir, dan menjalankan pemindaian biasa dengan perangkat lunak Anti-Malware seperti GOTMLS.NET
Mengapa atau halaman Diagnostik Penjelajahan Aman Google tetap menyatakan bahwa situs saya terinfeksi setelah saya menghapus kode berbahaya?
- caches their scan results and will not refresh the scan until you click the small link near the bottom of the page that says “Force a Re-scan” to clear the cache. Google also caches your infected pages and usually takes some time before crawling your site again, but you can speed up that process by Requesting a Review in the Malware or Security section of Google Webmaster Tools. It is a good idea to have a Webmaster Tools account for your site anyway as it can provide lots of other helpful information about your site.
How can I report security bugs?
You can report security bugs through the Patchstack Vulnerability Disclosure Program. The Patchstack team help validate, triage and handle any security vulnerabilities. Report a security vulnerability.
Kontributor & Pengembang
“Keamanan Anti-Malware dan Firewall Brute-Force” adalah perangkat lunak open source. Berikut ini mereka yang sudah berkontribusi pada plugin ini.
Kontributor“Keamanan Anti-Malware dan Firewall Brute-Force” telah diterjemahkan dalam 15 bahasa. Terima kasih kepada para penerjemah untuk kontribusi-nya.
Terjemahkan “Keamanan Anti-Malware dan Firewall Brute-Force” dalam bahasa Anda.
Tertarik mengembangkan?
Lihat kode, periksa repositori SVN , atau mendaftar ke log pengembangan melalui RSS.
