PHPIDS - get it!

WPIDS – PHPIDS your WordPress the comfy way

Article written by philipp

Some weeks ago a basic plugin was released which enabled PHPIDS support for your WordPress Blog. Since it has some usability flaws I’ve been planning for some time to make a port of PHPIDS to WordPress together with David Kierznowski, but I had some initial problems with it. So it took up to today to get the first release done.

WPIDwhat?

The WPIDS offers protection for your Blog from malicious code injections. Any Request considered as malicious is logged into a database for later analysis. You can also set up email notification for attacks with very high impact. The back-end pages of the plugin will notify you if new filter rules are available and you can check a list of latest intrusion attempts.

But the most important feature of the WPIDS is that you can block attackers for some time if they are running wild on your blog. The plugin is built on the 0.3.2 core of the PHPIDS – a version shipped with the coming 0.4 milestone will be released soon.

New features coming soon

  • Better design for the ‘Oh-my-god-you-got-blocked’-page
  • Better browsing and analysis features for the attack list
  • Functionality to clean the database from old records
  • … and the feature you’d like have. Drop me a line!

For telling me what needs to be added or changed you can use my WPIDS Forum. If you have any problems with PHPIDS instead or if you discovered a vector which isn’t caught by PHPIDS yet please report to the PHPIDS team – they eat filters for breakfast.

You can download the Software here.

31 Responses to “WPIDS – PHPIDS your WordPress the comfy way”

  1. BlogSecurity » WordPress Hardening Project Update Says:

    [...] Other info: – PHP-IDS Article [...]

  2. SigT Says:

    WPIDS y el WordPress Hardening Project…

    WPIDS es un port de PHPIDS a WordPress, si no me equivoco la traducción vendría a ser Sistema de Detección de Intrusiones para WordPress (WordPress Intrusion Detection System) ya que aunque no aclaran el término, IDS se refiere a esto.

    Según una …

  3. PhSoftware Programming Blog - PSPB Says:

    WPIDS fights SPAM as well…

    I just recognized by checking some parts of WPIDS that it does as well block some Spam entries from getting posted to your Website. As PHPIDS checks for HTML tags, unsanitized ones, within the strings it removes these Requests…The only problem is…

  4. Las páginas blancas de la seguridad Wordpress | aNieto2K Says:

    [...] WPIDS, detecta intrusiones [...]

  5. Ben Says:

    Downloaded wp-ids.zip today to try on WordPress 2.3.1.

    I get this error in the setup page. There is some problem at the end of the page when it is trying to display the legend.

    Filterrules:
    Your WP-IDS runs with the most up to date filter rules.
    Last Blocked Bad Requests:
    ID Name Value Tag Page IP Impact Time
    No Intrusions where logged, you have to be happy!

    Legend:
    Name Values:GET – Bad Value within $_GET Array, POST – Bad Value within $_POST Array,REQUEST – Bad Value within $_REQUEST Array, SERVER RURI – Bad Value in $_SERVER[REQUEST_URI], SERVER AGENT – Bad Value in $_SERVER[HTTP_USER_AGENT], SERVER REF – Bad Value in $_SERVER[HTTP_REFERER]

  6. Ben Says:

    I tried going to the indicated forum. I was unable to post and unable to register.

  7. Philipp Says:

    Hi Ben, Thanks for Using WPIDS. About the Error on the bottom of the Page. It’s no Error, it’s just the description of the given Values…Have you tried to register on my forum over at phsoftware.de? I’ll check it out.

  8. Sin Gamulan » Las páginas blancas de la seguridad Wordpress Says:

    [...] WPIDS, detecta intrusiones [...]

  9. WordPress: 4 suggerimenti per aumentare la sicurezza del vostro blog @ NeuroMemories Says:

    [...] PHPIDS for wordpress (richiesto PHP5) [...]

  10. James Norwood Says:

    How about making use of the WP-Vulnerabilities list at http://blogsecurity.net ?

    When vulnerabilities are checked against the list of installed plugins a vulnerability check can be performed. Is this complementary to the WPIDS ?

  11. Plugin Security Danu.web.id | Danu Belajar nge-Blog Says:

    [...] WPIDS Plugin ini berguna untuk mengamankan file-file wordpress dari proses peng-injekan kode-kode yang berbahaya oleh para hacker. untuk informasi lebih lanjut klik disini [...]

  12. AdMoolah News and Views » Securing Wordpress Installations Says:

    [...] PHPIDS for WordPress. This plugin defends against malicious code injections. This was another recomendation from the [...]

  13. Testbild » Blog Archive » WPIDS - Intrusion Detection System fuer Wordpress Says:

    [...] habe ich nach Security Enhancements fuer mein Blog gesucht. Nun habe ich eins gefunden: WPIDS – ein auf PHPIDS basiertes Plugin fuer WordPress. Ich find das sehr schnuckelig. Leider fehlt noch [...]

  14. Seguridad en Wordpress en Blog personal de InKiLiNo | Wordpress, plugins y algo de SEO. Says:

    [...] WPIDS: Detecta posibles intrusiones. [...]

  15. Plugins para mantener seguro Wordpress | Red de Blogs - Internet y Tecnologia Web Says:

    [...] 9.WPIDS: Detecta posibles intrusiones. [...]

  16. How to Firewall Your WordPress Blog Says:

    [...] This hasn’t been updated in a while and only works with PHP5. I’d nag BlogSec guys for an update before using it. More info here [...]

  17. Wordpress Security - Protecting Against Hackers | John Nasta Says:

    [...] WPIDS – The WPIDS offers protection for your Blog from malicious code injections. Any Request considered as malicious is logged into a database for later analysis. You can also set up email notification for attacks with very high impact. The back-end pages of the plugin will notify you if new filter rules are available and you can check a list of latest intrusion attempts. [...]

  18. Protegendo Wordpress de Atques de Hackers » Gus SOS Brasil Says:

    [...] deste blog e milhares por aí na internet. Acabei até por instalar um novo plugin chamado WPIDS o qual oferece suporte PHPIDS ao WordPress. PHPIDS é um módulo de segurança que protege páginas [...]

  19. WordPress Security Links Says:

    [...] WPIDS (PHPIDS port for WordPress) [...]

  20. WordPress Security? Try Common Sense - SilverPen Publishing Says:

    [...] installed WPIDS because it seemed like a good idea at the time. I uninstalled it for the same reason, because I [...]

  21. Nifty Tools Dificult Tools « Splog Spot Blog Says:

    [...] along with the many WP updates that come and goes as they come out of the grinder. There are some issues to address that may need sone study and implementation may need quite some extensive PHP knowledge. Some other [...]

  22. Securiza tu Wordpress | Enchulatublog Says:

    [...] 9.WPIDS: Detecta posibles intrusiones. [...]

  23. PHP Intrusion Detection System (PHPIDS) – techPortal Says:

    [...] Installing PHPIDS in WordPress, Serendipity, Joomla and Drupal although you might want to use the official WPIDS plugin for WordPress from php-ids.org [...]

  24. 10 tips para blindar a wordpress - El nuevo mundo del techno Says:

    [...] Plugin de deteccion y bloqueo de intrusos | WPIDS es un port de PHPIDS a WordPress. [...]

  25. WPIDS, 来自PHPIDS的WordPress保护插件 - FeelingFly Says:

    [...] 点击前往 OR Download this file [...]

  26. Securiza tu Wordpress | triunfoweb.com Says:

    [...] 9.WPIDS: Detecta posibles intrusiones. [...]

  27. WPIDS – PHPIDS your Wordpress the comfy way - Ei2U Says:

    [...] Click here go to the official website [...]

  28. How to Firewall Your WordPress Blog - SnailVn | SnailVn.Com Says:

    [...] This hasn’t been updated in a while and only works with PHP5. I’d nag BlogSec guys for an update before using it. More info here [...]

  29. I Was Hacked Recently! What I Did To Fight Back. | Blogging Tips Says:

    [...] This plugin works similarly to the WordPress Firewall Plugin. It uses some different technologies but the end goal is the same. Preventing malicious code injections through WordPress. The plugin automatically emails me when there is a potential attack. WPIDS Plugin for WordPress. [...]

  30. Trackback - Free Internation Call >> How to make free international call Says:

    ,[...] php-ids.org is one nice source of tips on this topic,[...]

  31. valeriu.palos.ro » Seven essential WordPress plugins Says:

    [...] repelling e-mail address harvesters, spam bots and all kinds of evil insects.3. WPIDSWebsite: http://php-ids.org/2007/09/12/wpids-phpids-your-wordpress-the-comfy-way/ An excellent alliance between WordPress and the PHPIDS project. It monitors your website for a very [...]

Leave a Reply