4 ms·
Its a suckerpunch.. If there is a way in, they will find it. You have to vet everything. I had a side project compromised through some supplementary php files
by dana321 7y ago
Its a suckerpunch.. If there is a way in, they will find it. You have to vet everything.
I had a side project compromised through some supplementary php files that came with a javascript library. Luckily, i didn't have any users on it.
Keep everything up to date, including your server software, composer, javascript libraries etc.
Make sure you run a clamav on linux, it will catch any intrusion writing scammy files and rename them.
All passwords unique and made using a password generator. That way, if you are compromised it is only one password not the keys to everything.
Don't keep non-user stuff with predictable uri (like /admin/ /phpmyadmin/ etc.)
One-way backups.. Allow your backup server behind a firewall to login to your site and do hourly backups of all the data.
Disallow access to any files beginning with dot in your webserver configuration. I'm pretty sure nginx does this by default.
- ngranja19 7y agoThanks for all the recommendations, so useful!