Categories
Tutorial, Manual, Tips dan Trik

Move On MPM Prefork ke MPM Event, Sebuah Catatan

Daftar Isi

Perlindungan Aplikasi

|- Amankan upload

  1. WordPress
    • wp-config.php
      Tambahkan baris define( 'DISALLOW_FILE_MODS', true );
    • Jika menggunakan plugin cache, maka folder wp-content (bukan wp-content/*) harus bisa ditulis, maka wp-content harus diabaikan pada saat chattr +i. Pengaman ada di ProxyPassMatch ^(.*((/tmp-php)|(wp-content/uploads/)|(wp-content/cache/)|(wp-content)))(.*\.php(/.*)?)$
  2. Cegah eksekusi skrip
    #Prevent script execution: (1) -ExecCGI, (2) folder temporary php dan folder upload di mount dengan mode=1777 dan noexec
    #Alias ...."/tmp-php"
    <Directory "/tmp-php">
    Options -ExecCGI
    AddHandler cgi-script .php .pl .py .jsp .asp .htm .html
    </Directory>

By basit

Biro Pengembangan Teknologi Dan Sistem Informasi

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.