Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Blogging Forum


You are currently viewing our Blogging Forum as a guest. Please register to participate.
Login



Reply
Wordpress Security Tips..
Old 05-13-2009, 02:40 AM Wordpress Security Tips..
Skilled Talker

Posts: 68
Name: Melvin Dichoso
Trades: 0
its very alarming but yesterday i was visiting some blogs (blogs w/less than 100,000 alexa rank) and 7/10 of them have their wordpress subfolders browsable w/c means anyone can view the url 'blogname.com/wp-content/plugins' or 'blogname.com/wp-content/themes' This is bad because hackers can pretty much exploit it and then hack your blog, or people could easily get your themes and stuffs inside your folders.

The simplest solution is to put "options - indexes" in your .htaccess file...
__________________
MelvinBlog.Com -
Please login or register to view this content. Registration is FREE

Must Read Articles -
Please login or register to view this content. Registration is FREE

Importance of
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
| My
Please login or register to view this content. Registration is FREE
countolaf is offline
Reply With Quote
View Public Profile Visit countolaf's homepage!
 
 
Register now for full access!
Old 05-13-2009, 03:18 AM Re: Wordpress Security Tips..
NullPointer's Avatar
Will Code for Food

Posts: 2,784
Name: Matt
Location: Irvine, CA
Trades: 0
That's a good point. Just to clarify, your .htaccess should like something like this:

Code:
options -indexes
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>

# END WordPress
Provided your .htaccess hasn't been modified by you or a plugin.

URLs like domain.com/wp-content/plugins/ should not give you a 404.
__________________

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
NullPointer is online now
Reply With Quote
View Public Profile Visit NullPointer's homepage!
 
Old 05-21-2009, 01:43 PM Re: Wordpress Security Tips..
Skilled Talker

Posts: 60
Name: otpas
Trades: 0
Thanks for sharing.I will try it.
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE
pithu_7 is offline
Reply With Quote
View Public Profile Visit pithu_7's homepage!
 
Old 05-25-2009, 06:40 AM Re: Wordpress Security Tips..
SunstarShop's Avatar
Skilled Talker

Posts: 74
Name: liny
Location: Shenzhen China
Trades: 0
Terrible thing, thanks!
__________________
My own chinese language site:
Please login or register to view this content. Registration is FREE

My business site:
Please login or register to view this content. Registration is FREE
SunstarShop is offline
Reply With Quote
View Public Profile Visit SunstarShop's homepage!
 
Old 05-27-2009, 03:35 AM Re: Wordpress Security Tips..
Skilled Talker

Posts: 68
Name: Melvin Dichoso
Trades: 0
hey guys thanks for the great response..
__________________
MelvinBlog.Com -
Please login or register to view this content. Registration is FREE

Must Read Articles -
Please login or register to view this content. Registration is FREE

Importance of
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
| My
Please login or register to view this content. Registration is FREE
countolaf is offline
Reply With Quote
View Public Profile Visit countolaf's homepage!
 
Old 05-27-2009, 03:57 PM Re: Wordpress Security Tips..
Junior Talker

Posts: 3
Name: Ray Mulen
Location: Southern California
Trades: 0
Thanks for the tip. The template I use for my WP blog is secure. But when I set up a new one with a free template (I paid for my theme) then I'll need to look out for this.
__________________
- Ray

Please login or register to view this content. Registration is FREE
pplsearch is offline
Reply With Quote
View Public Profile Visit pplsearch's homepage!
 
Reply     « Reply to Wordpress Security Tips..
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.22583 seconds with 12 queries