Caution on WP-CONFIG security

Posted in: Newsmag
Post count: 9544

WORDPRESS USERS: okay, this is kind of a big deal; if you’re using WP, be sure to login via FTP and check the wp-config file has permissions of ‘400’ and not ‘644’ which my ftp software or plesk defaulted to when updating it. Just had security bounty hacker (who checks my site couple times a year for me), email me my wordpress dbase name, user name and password (!). Luckily the server only allows “local” connections to the dbase, so even with the info, could not technically connect to do damaage or injections. However, I changed my user password for the dbase, and rechecked the security hardening. Also, if you added a line to your htaccess file to stop people from accessing file directly, give link to friend and ensure they cannot actually access the file at all. Heads up!

Post count: 35449

Hi simchris, thank you for taking your time to share it with us!

Viewing 2 posts - 1 through 2 (of 2 total)
You must be logged in to reply to this topic.