3 ms·
I saw the virus on your site earlier. It appears to be gone now and I couldn't find any XSS or SQL vulnerabilities on your site. Here's some other stuff to cons
by pinksoda 16y ago
I saw the virus on your site earlier. It appears to be gone now and I couldn't find any XSS or SQL vulnerabilities on your site. Here's some other stuff to consider:
- Possibly vulnerable to mod_rewrite off-by-one buffer overflow (Apache 2.0.54). Upgrade Apache.
- Possibly vulnerable to header injection (Apache 2.0.54). Upgrade Apache.
- Possibly vulnerable to session fixation attack. Set session.use_only_cookies = 1 in php.ini
- Install mod_security if you haven't already. It's a great extra layer of security and can save your butt when someone forgets to sanitize input (which WordPress and 3rd party plugins frequently do).
- jasonlbaptiste 16y agoMany thanks for the insight. Lot of it detailed here too: http://news.ycombinator.com/item?id=1551868 http://news.ycombinator.com/item?id=1551868 Sadly, my blog is on mediatemple, so I can't change a lot of the good Apache stuff. I may switch to the semi advanced setup I have running for Cloudomatic (rackspace cloud).