4 ms·
This is a great idea. Thanks for sharing.
by _eht 8y ago
This is a great idea. Thanks for sharing.
- Vanderson 8y agoI got the idea from a security company trying to sell me WP security suite that will scan all your files, and automatically replace them if they are bad. Since I wasn't running WP, I couldn't use it. But I liked the idea and I built my own scanner into my CMS (Archetype). But, I found an once of prevention is worth more than a monthly fee for a scanning service. No system files should be writeable by the web server, 98% of the problems solved right there. The other 1% is don't allow any user uploaded files to be executable. The last 1% is don't allow any unknown files to be created in any executable space. Maybe there's a permanent 1% in there that is unsolvable? (social engineering among other unknown threats/bugs, etc...) I am not a security expert, so I have had to learn both the hard way and from a lot of studying.
- greypowerOz 8y agoi second this (but also as a learner not a guru) i admin a server where nothing is writable by the user the webserver runs as except manually modified items/folders where the cms is expecting to upload images or pdfs etc. The hand-changed folders are non-executable by php . I'm sure there is a smarter solution but since implementing this we haven't had a successful malware/deface incident .
- Vanderson 8y agoYep, this is my experience as well. I have accounts get compromised because of a weak password. (maybe 2fa will help) But also, accounts can be locked down to IP address (harder to manage but helps more) But does WP allow php executable on user upload directories by default? I know this is more of a server setting, but it would make sense to test for this in WP admin and alert the user.