LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-17-2017, 01:42 AM   #1
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Rep: Reputation: 30
Vulnerabilty scanner for Apache and Wordpress


Hello,
I have some WordPress installations on Apache and I worry about them. I have no specific reason, only that there is a lot of software made by 3rd parties (plugins, themes etc) and I don't know exactly that it does.

What is a vulnerability scanner you use and recommend? There are a lot.
For the beginning I would like something free.

Thank you
 
Old 05-17-2017, 04:13 AM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
13 years and Zero info.

Wordfence and https://codex.wordpress.org/Hardening_WordPress

How are you vulnerability scanning the non-Turdpress stuff?

Got backups?
clamAV
Maldet
rkhunter

New to this?

Last edited by Habitual; 05-17-2017 at 04:15 AM.
 
Old 05-17-2017, 04:35 AM   #3
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
I've already installed wordfence. I took most of the measures described there.
I have backups.
I am still worried about this maybe because the only security incidents I had with my servers in the last 10 years were related to WordPress.
Thank you
 
Old 05-17-2017, 07:23 AM   #4
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Make sure your addons/plugins are up-to-date.
My Wordpress auto-upgrades on my hosts, but I have to manually upgrade the plugins/addons via the dashboard.

generally,
Files = 644
Directories = 755
few exceptions like .cgi-related stuff.
Watch the inputs including search boxes.

https://www.exploit-db.com/search and search for Wordpress and be amazed.

Also, Google Dork is a valuable skill.
Code:
<addon/plugin> exploit
at any engine worth spit.

I have near 300 rules in my fail2ban, most are for Wordpress abuse.

You get the Wordfence Security Bulletin via email?
https://www.wordfence.com/blog/2017/...te-recommended

Last edited by Habitual; 05-17-2017 at 07:52 AM.
 
Old 05-18-2017, 01:08 PM   #5
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by ddaas View Post
I am still worried about this
and right you are.
wordpress is about as secure as windows XP, and much more widespread. what a glorious attack surface
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: WordPress Updates in CentOS 7 + Apache + SELinux LXer Syndicated Linux News 0 02-03-2017 04:54 AM
Apache HTTP wordpress attack? mkools Linux - Security 5 07-05-2013 05:56 PM
LXer: WPScan: A WordPress Vulnerability Scanner For Ubuntu LXer Syndicated Linux News 0 12-02-2011 02:10 AM
LXer: WordPress 3 Security: Apache Modules LXer Syndicated Linux News 0 06-13-2011 01:41 PM
Vulnerabilty Assestments metallica1973 Linux - Security 3 03-17-2006 04:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration