Greenguy's Board


Go Back   Greenguy's Board > Blogs and Blogging
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2008-04-07, 10:29 PM   #26
ronnie
Wheither you think you can or you think you can't, Your right.
 
Join Date: Jun 2004
Location: midwest
Posts: 2,274
Send a message via ICQ to ronnie
Am I missing something here, I just realized, seemed the whole deal with setting the htaccess file to 777 was so Wordpress could write the new htaccess file for you? It's always been like that.

Then again, when you set up permalinks, WP gives you the htaccess code, you just copy and paste it into your htaccess file and upload it.

Not much need to have a security hole so that WP can write the file instead of just doing it yourself.

Just like when I see people changing the file permissions on their theme files, so they can edit them in WP, when it's just as easy to do it with a web page editor.

Perfect example, some one hacked one of my blogs this am (partly my fault, left less then secure WP pass as it was), if all my files where editable (777), they could have done much more. They could have done little things that I might not even notice.

This was no 2.5 bug or error.

Or I missed something?
ronnie is offline   Reply With Quote
Old 2008-04-07, 11:26 PM   #27
Maj. Stress
Progress rarely comes in buckets, it normally comes in teaspoons
 
Maj. Stress's Avatar
 
Join Date: Jun 2005
Location: Dark Side Of Naboo
Posts: 1,289
My copy of 2.5 did not give me any code to put in htaccess (and did not come with a htaccess file). I remember 1.5 did.
Maj. Stress is offline   Reply With Quote
Old 2008-04-08, 02:12 AM   #28
walrus
Oh no, I'm sweating like Roger Ebert
 
walrus's Avatar
 
Join Date: May 2005
Location: Los Angeles
Posts: 1,773
Send a message via ICQ to walrus Send a message via Yahoo to walrus
Quote:
Originally Posted by Maj. Stress View Post
My copy of 2.5 did not give me any code to put in htaccess (and did not come with a htaccess file). I remember 1.5 did.
WP hasn't come with a htaccess file for awhile now. I can't remember a 2.x file that did.

I haven't upgraded to 2.5 yet but to my knowledge all WP versions will give you the htaccess code in permalinks when you try to set it if it can not write to the file.

I agree with ronnie why set anything writable if you don't absolutely have to
__________________
Naked Girlfriend Porn TGP
free partner account
walrus is offline   Reply With Quote
Old 2008-04-08, 02:51 AM   #29
Maj. Stress
Progress rarely comes in buckets, it normally comes in teaspoons
 
Maj. Stress's Avatar
 
Join Date: Jun 2005
Location: Dark Side Of Naboo
Posts: 1,289
Quote:
Originally Posted by walrus View Post
WP hasn't come with a htaccess file for awhile now. I can't remember a 2.x file that did.

I haven't upgraded to 2.5 yet but to my knowledge all WP versions will give you the htaccess code in permalinks when you try to set it if it can not write to the file.

I agree with ronnie why set anything writable if you don't absolutely have to
The copy of 2.5 that I installed gave me a warning without any code to put in htaccess. It said something about making my htaccess writeable.

I haven't installed wordpress in almost 2 years so this was all new to me.
Maj. Stress is offline   Reply With Quote
Old 2008-04-08, 08:18 AM   #30
Simon
That which does not kill us, will try, try again.
 
Simon's Avatar
 
Join Date: Aug 2003
Location: Conch Republic
Posts: 5,150
Send a message via ICQ to Simon Send a message via AIM to Simon Send a message via Yahoo to Simon
Since a lot of people seem to be upgrading older (sometimes very old) WordPress installations, here are a couple of links that will help with securing your sites.

Three Tips to Protect Your WordPress Installation - Matt Cutts

Hardening WordPress - codex

And yes, make sure you change your htaccess permissions back to 644 as soon as possible if you ever need to make it world-writable by setting them to 777 temporarily. And really, if you leave any of your theme files writable by WordPress, or leave the standard 'admin' user with full admin rights, you can count on getting hacked at some point.

Also it's a good idea not to run more than one WP installation from one MySQL database. Sure, you can change prefixes for each install and run several from one database, but if you do get hacked at some point you're making it easy to take down all your blogs with one click.

Lots of good tips in the comments to Matt's article too, don't miss reading those.

HTH
__________________
"If you're happy and you know it, think again." -- Guru Pitka
Simon is offline   Reply With Quote
Old 2008-04-08, 03:53 PM   #31
Maj. Stress
Progress rarely comes in buckets, it normally comes in teaspoons
 
Maj. Stress's Avatar
 
Join Date: Jun 2005
Location: Dark Side Of Naboo
Posts: 1,289
Excellent info Simon. Thanks for passing that along.
Maj. Stress is offline   Reply With Quote
Old 2008-04-08, 05:10 PM   #32
ronnie
Wheither you think you can or you think you can't, Your right.
 
Join Date: Jun 2004
Location: midwest
Posts: 2,274
Send a message via ICQ to ronnie
Ya, that is true, they don't come with a htaccess file, i was thinking it still gives you the code to write to your htaccess file. My bad.
ronnie is offline   Reply With Quote
Old 2008-04-08, 10:23 PM   #33
walrus
Oh no, I'm sweating like Roger Ebert
 
walrus's Avatar
 
Join Date: May 2005
Location: Los Angeles
Posts: 1,773
Send a message via ICQ to walrus Send a message via Yahoo to walrus
Quote:
Originally Posted by ronnie View Post
Ya, that is true, they don't come with a htaccess file, i was thinking it still gives you the code to write to your htaccess file. My bad.
It still does...at least 2.5. When you hit save changes, on the top of your screen it says you should update your htaccess file now but if you scroll to the very bottom it shows the code to update your file with.

Not very obvious
__________________
Naked Girlfriend Porn TGP
free partner account
walrus is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 07:28 AM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc