
WordPress 보안은 중요합니다!
🇺🇸 A massive supply chain attack just hit over 1.2 million WordPress websites, and the lessons are loud and clear: even deactivated plugins can leave you wide open. If you run a site (or host them for clients), this is your wake-up call to tighten up security before the next breach.
🔥 The attack targeted three popular marketing plugins — OptinMonster, TrustPulse, and PushEngage. Hackers didn’t hit the plugins directly. They compromised external scripts these plugins loaded. When an admin logged in, the malicious code got full administrator access.
🛡️ Attackers weren’t just messing around — they installed hidden backdoors for long-term control:
- 부적절한 관리자 계정(developer_api1 또는 wpsecurebot 등)
- 대시보드에 숨겨진 악성코드
- SEO 스팸, 가짜 브라우저 업데이트, 심지어 암호화폐 채굴자까지
핵심 내용: 플러그인을 삭제하거나 비활성화하는 것만으로는 충분하지 않습니다. 설치된 적이 있는 경우 철저하게 검사하십시오.
WordPress 사이트를 확인하고 정리하는 방법
- 관리자 계정 검토 — 사용자 페이지만 신뢰하지 마십시오. 알 수 없는 관리자가 있는지 wp_users 데이터베이스 테이블을 확인하세요(또는 WP-CLI를 사용하세요).
- 플러그인 폴더 검사 — wp-content/plugins/ 및 wp-content/mu-plugins/에서 의심스러운 것이 있는지 살펴보세요.
- 모든 것을 변경하세요 — 모든 관리자 비밀번호를 재설정하고, 솔트를 재생성하고, 데이터베이스 비밀번호를 업데이트하고, API 키를 교체하세요.
앞으로의 스마트 보안 관행
- 사용하지 않는 플러그인 및 테마를 완전히 삭제하세요. 비활성화됨 ≠ 안전합니다.
- 변경 사항을 모니터링하려면 견고한 활동 로그 플러그인(예: WP Activity Log)을 사용하세요.
- 이중 인증 및 무차별 대입 보호를 추가합니다.
- 모든 것을 최신 상태로 유지하고 정기적인 맬웨어 검사를 실행하세요.
🇺🇸 America-first take: In a digital world full of threats, real security comes from ownership and vigilance — not trusting third-party scripts or “set it and forget it” plugins. Self-hosted WordPress on reliable hosting (with server-level protections) gives you the control you need to protect your business and data.
HostRite와 같은 호스팅 제공업체는 추가 계층(감옥 호스트 격리, 일일 백업, 서버 수준 차단)을 추가하지만 사이트 소유자는 여전히 자신의 역할을 수행해야 합니다.
다들 어떻게 생각하세요? 이와 같은 상황에 직면했거나 WordPress 사용자를 위한 강력한 보안 팁을 얻으셨나요? 아래에서 공유하세요!
