Sunday, August 13, 2017

Manage back-ups wisely and securely

What exactly needs to be secured? WordPress basically consists of (program) files, an upload directory and a database. There is a fundamental difference between the data and files on the webspace and the MySQL database.


Back up in the cloud


The files are easy to reach with an FTP client and can be copied arbitrarily back and forth. The WordPress content, on the other hand, is stored in a database. For security reasons, the providers usually run these databases on separate servers. Therefore, a back-up of the database as well as a back-up of the FTP files must be set up, as long as an intelligent plug-in does not take this work.


Are the back-ups checked?


At what intervals must be secured? This question is aimed at the update interval of the data. As a rule, backing up the database with all its regularly updated text contributions and the diligent comments of a lively community should be the most common. The backup of the WordPress data and the upload directory often takes some longer back-up cycles. Above all, the loss of user comments weighs heavily. If you can still reload photos or files from the local hard disk, it looks zappenduster in user-generated content.


Create Back-ups with BackWPup


If the WordPress website does not change at all - or only very rarely, as in the case of a business card in the network, for example, one can make the back-up settings accordingly generously. However, it is recommended to automate the back-up completely, it is sometimes sufficient to check the logs and to test the back-ups for error-freeness.


The job settings at a glance


Social media tools at a glance


Which media is secured? Some plug-ins ensure a timed backup of the files and the database. That is great. However, care should be taken where the data is being saved. If you have selected a folder of your WordPress installation for the back-up treasure chest, you should consider that a hard disk defect or attack on the page can also affect back-up subdirectories. Better is a backup in separate places.


Backup via FTP: Many plug-ins and solutions allow an FTP connection to play back-ups via FTP directly to another server. At this point, it would be worth considering whether you would not want to take a few more euros in the hand to rent a physically separate webspace in addition. This would be predestined as a back-up webspace. The prices for pure webspace without frills are manageable to ridiculous.


You do not need scripting languages ​​or a database. The pure webspace is enough, of course, should be large enough. Perhaps you even have a computer or NAS at home that could act as a file store (assuming it is switched on at the time of the back-ups and accessible from the outside).


Back-ups can be played at night. Thus, one has a back-up of their own data conveniently on the domestic hard drive. If you have the choice between a traditional FTP and an SFTP connection, an encrypted SFTP connection is always preferable. Thanks to this encrypted connection, data is not transferred to the server in plain text and can not be read and used by third parties. As a variant of the FTP backup some plug-ins send a compressed version of the database also to a set e-mail address. One saves thus additionally required Webspace.


Dropbox, Google Drive, Skydrive, Amazon S3, Cloudsafe. The Cloud. Nowadays, you can store memory at low prices. Since you have already secured his 10,000 pieces and his countless number of photos in the cloud anyway, one might have the idea to save his website there as well. Commercial sites should, however, be aware that most or the most popular cloud services are based in the US and are transferred to the US, purely from a data point of view. In the case of sensitive company data, this is not a cheap option.


It could be from a James Bond film, but it is true: the American government is allowed to see and evaluate all the data stored on American web servers - and it also makes a lot of use of it. So before back-ups are secured in the cloud, you should take a closer look which provider is eligible. In addition to the popular US services, there are also American providers who take it more closely with data protection and privacy.


Use CC licenses correctly


If you still want to dropbox on the place, there is still the possibility to encrypt the files before they are stored in the dropbox account. So you can also be sure - with the best encryption possible - that no foreign eyes see your own content.


Clear naming of each back-up order


This point is neglected by most. Usually, our good old friend Murphy hits the light-hearted WordPress user a snippet and - as the chance once again wants - the back-up file with the database is of course exactly useless when you just need it bitter. Many make back-ups easy to imagine. If you do not manually create back-ups, you usually blindly familiarize yourself with an added-practical tool that automates the task. Nevertheless, you do not get around samples. This is the only way to be sure that you have a complete and working backup.


To create back-ups, you can choose the conventional path and go through a database administration interface like PHPmyAdmin and copy the data from FTP to A via FTP. It is more practical - once again - with a corresponding plug-in. BackWPup is a very powerful back-up tool, and once set up it performs reliably in the background of its work. The plug-in itself is available in a free and cost-effective Pro version. For most purposes, the free version is more than adequate. You can find a comparison between the two versions on the manufacturer's website.


Backup to folder


What should the ideal back-up plug-in master?


After installing and activating BackWPup, we can set up back-up orders. To do this, click the new BackWPup menu item in your left navigation bar. However, before you get access to the various settings, you are greeted with a Welcome screen to make you more compact and visually appealing to the features of the plug-in. In addition, the advantages of the Pro version are explained again below. Simply click BackWPup on the left side again. Now you are also directed directly to the BackWPup dashboard.


Quick & Dirty: The one-click database back-up: If you want to quickly create a back-up of your database and do not want to create a large hand, you can launch a one-click back-up in a windscrew. To do this, simply press the "Download database backup" button on the right. A database backup is then created and offered for download. It can not get any faster.


Backup via e-mail


Backup in the Dropbox


Back-ups restore


To create a significantly finer configured back-up order, click on "New order" in the left navigation bar under BackWPup. Alternatively, you can also use the "Create a job" link in the "Getting Started" dashboard. You will now be presented with an overview page divided into various tabs in order to tailor and set up your back-up order according to your requirements. The riders themselves appear and disappear, depending on the choice you make in the "General" tab under Order details. If you tick the box next to all possible options, all tabs are visible. So you do not lose track of the overview, you should set up several smaller jobs and only enable the necessary options for the individual orders to be viewed.


That is a lot - what options are really relevant to me? In the normal case, file and database backup is compulsory. It is therefore sufficient to set and activate a check mark next to the first two options "Database Backup" and "Files Backup". This also increases the overview immediately.


The best podcasts for Webworker


A list of installed plug-ins that are stowed in a safe place is enough to reinstall the plug-ins. Plug-ins is therefore usually not necessary. In addition, it is cleaner to install plug-ins, something should happen. Most of your content comes from the database and the file system. The optimization and, above all, the testing of the database should also be carried out at regular intervals. But there are also plug-ins like WP Optimize, which is presented in a further chapter in more detail.


In order to be well versed, it is recommended to give clear names for the newly created orders. "Backup1" is, of course, much less meaningful than "weekly back-up of files and database". The order name can be assigned directly in the first tab "General". Make use of this to directly use the title in the order overview under orders to open up later, which tasks the back-up does exactly. Where to use the backup?


In the "General" tab, you can also define where the backup is to be stored. Here, the plug-in is very versatile, and you can back up the finished back-up via different cloud services, send it via e-mail, or have the freshly created back-up transferred via FTP to your own server >



It is interesting that you do not have to specify a variant and can combine as desired. So it is quite possible that a back-up via FTP can be carried out and at the same time a back-up with a cloud provider secures. Allowing a back-up via e-mail is often critical because of the expected file size, and should only be used with partial back-ups. As a rule, e-mail mailboxes are limited as far as file size is concerned. However, a database should be easily transferred. In general, keep in mind that an e-mail is not a secure route.


While the database usually does not include any plaintext passwords, it looks very different in the case of files. The wp-config.php file contains all passwords in the plaintext. Do not transfer such sensitive data by e-mail, even if it would work from the transfer volume.


This long list of locations should not be misled. Looking at the different storage locations in detail, only the first three variants are different in principle. All other noted storage locations are all different cloud providers, which are also very suitable. To configure a selection, just click on the corresponding point. Then a new matching tab appears in the bar.


A backup of data in a folder is only conditionally meaningful and only complementary. This back-up version only helps with accidentally deleted files. Because the back-up is available ad hoc on its own webspace, data can of course be restored quickly.


If you leave it at the default, the plug-in will create a new directory in the Upload folder of your WordPress installation to back future backups to that folder. This directory and the back-ups it contains can be accessed via FTP: / wp-content / uploads /.


If, despite all restrictions, you have decided to send a back-up by e-mail, a new tab "To: E-Mail" appears. If you enter a valid email address in the field provided, the back-up is sent by e-mail. In order to save your mailbox, you can also set a maximum file size in the settings provided for it.


Back-up to FTP: The most interesting and comprehensive setting interface is the "Backup to FTP" section. As mentioned earlier in the chapter, it is a worthwhile investment to invest in a physically separate FTP back-up webspace. In the various fields, you must now enter the connection data to the FTP server. These are provided by your hosting provider. To find the folder for files, which can be noted separately, one should connect via FTP to its webspace. Now you have to click through one or two folders to get to your files.


These folders are to be noted here. This path is important for the back-up files to be stored correctly. Often, this is httpdocs / or htdocs / to get to the top level of your files. By specifying a "maximum number of files in the FTP folder" under file deletion, you can control the number of back-ups to be kept. If you enter 0 here, there is no limit. If you enter 7, and the backup is executed daily, the back-ups are kept a week.


The oldest is then deleted when the next backup is performed. If you put a check mark next to the setting SSL-FTP connection, an encrypted SFTP connection is used (Secure FTP). If your hosting provider supports this variant, this should be preferred in any case to the unsecured FTP connection. This will encrypt the passwords and not transfer them in the plaintext.


Try it out. If you can not connect via FTPS, deactivate this option again. In a last option you have the option to use FTP Passive mode with "Use FTP Passive Mode". In order to save you unnecessary technical explanations from the depths of the FTP protocol, I recommend testing both options. The passive FTP mode is usually used when the classic active FTP mode does not work.


Create websites for disabled people


Testing the FTP connection and checking back-ups: Unfortunately, there is no way to check the connection to the FTP server immediately after entering the information and information. So you do not know whether the data can now be used correctly. In this case, try also to study, and after a first back-up you should check the result via FTP for completeness.


For the purpose of testing, you could create your own back-up order, which will be executed only a few minutes in the future. A result is obtained immediately. If the backup was successfully uploaded via FTP, this back-up request can be removed and the clean data can be used for further back-up orders.


For the various cloud providers, let's look at the Dropbox. If you want to use this cloud service, but you do not yet have access to it, you can click on "Create account" next to the red warning "Unauthenticated!" Directly to the Dropbox website. If you already have an account, a shortcut is quite quick.


Provided you are already logged in to Dropbox, you click on Authentication (Sandbox) and is promptly requested to allow the necessary Dropbox app from BackWPup to access the Dropbox account. After clicking on "Allow", you automatically return to your back-up order. One thing, however, has changed. If the connection was successful, the plug-in acknowledges this with a green highlighted success message: "Authenticated!"


Also in the case of a backup via Dropbox you should of course check the result accordingly, and here, too, there is the possibility to limit the number of backups - just like in the case of a back-up via FTP.


The reasons to have a back-up re-imported can be varied. Perhaps your website was attacked or a plug-in installation failed, and all rescue efforts failed.


Restore files via FTP: If you have backed up your entire file on a regular basis, this step is probably the simplest. Whether partial or complete. If your website was hacked, you should immediately change all your passwords after you have backed up the data. Restore Database: In principle, restoring the database is somewhat more difficult. Unfortunately, in the current version of the BackWPup plug-in, the restore function has been eliminated.


Apparently the developers work under high pressure on the new development of this feature. With this feature it was possible to perform a restore in a few steps: Reinstall WordPress, install the BackWPup plug-in and restore the database using the plugin.


Afterwards, all plug-ins, contents and settings were available again. It is quite possible that the book printing feature has already been implemented again. However, up to the current time a back-up must be imported via an external tool such as phpMyAdmin.

No comments:

Post a Comment