3 ms·
I always give the webserver read only access to the file system, except the uploads directory, and then prevent the webserver from being able to execute php ins
by waingake 12y ago
I always give the webserver read only access to the file system, except the uploads directory, and then prevent the webserver from being able to execute php inside the uploads directory.
You can't update plugins via the admin with this setup, that is instead done with a deployment script.
I've deployed many WP sites with this setup and have never been hacked.
Oh fail2ban monitoring wp-login is also essential.
- lmz 12y agoThis should be a more common configuration and it would be nice if web apps themselves promoted using different OS identities for sensitive parts. W^X and privilege separation are widely used in daemons, why not in web apps?
- Rapzid 12y agohttp://codex.wordpress.org/Hardening_WordPress#File_Permissions http://codex.wordpress.org/Hardening_WordPress#File_Permissi... People just don't RTFM. It has been mentioned in Wordpress's hardening information for years and years aoubt having the web server process running as a separate user than the file owners along with the proper permissions.