Compare commits

..
2 Commits
Author SHA1 Message Date
moritz 4b81322e4f harden htaccess 2026-04-28 01:21:29 +02:00
moritz 563c691172 selfmanaged wordpress 2026-04-28 01:17:17 +02:00
7 changed files with 19 additions and 39 deletions
+7 -7
View File
@@ -1,8 +1,8 @@
export PHP_UPLOADS_CONF_VERSION=v4
export ENTRYPOINT_CONF_VERSION=v8
export ENTRYPOINT_CONF_VERSION=v7
export ENTRYPOINT_MAILRELAY_CONF_VERSION=v2
export MSMTP_CONF_VERSION=v4
export HTACCESS_CONF_VERSION=v4
export HTACCESS_CONF_VERSION=v3
export USERS_CONF_VERSION=v1
wp() {
@@ -42,11 +42,11 @@ core_install(){
}
enable_auto_updates(){
wp "plugin deactivate disable-update-notifications --allow-root"
wp "plugin uninstall disable-update-notifications --allow-root"
wp "option delete disable_notification_setting --allow-root"
wp "plugin auto-updates enable --all --allow-root"
wp "theme auto-updates enable --all --allow-root"
wp plugin deactivate disable-update-notifications --allow-root
wp plugin uninstall disable-update-notifications --allow-root
wp option delete disable_notification_setting --allow-root
wp plugin auto-updates enable --all --allow-root
wp theme auto-updates enable --all --allow-root
}
disable_auto_updates(){
+4 -3
View File
@@ -3,6 +3,7 @@ version: "3.8"
services:
app:
image: "wordpress:latest"
volumes:
- "wordpress:/var/www/html/"
environment:
@@ -12,9 +13,9 @@ services:
define( 'FS_METHOD', 'direct' );
${WORDPRESS_CONFIG_EXTRA}
#ftp:
# volumes:
# - "wordpress:/home/ftp_user/"
ftp:
volumes:
- "wordpress:/home/ftp_user/"
volumes:
wordpress:
+1 -1
View File
@@ -62,7 +62,7 @@ services:
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.replacement=https://${DOMAIN}/$${2}"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectregex.permanent=true"
- "coop-cloud.${STACK_NAME}.timeout=${TIMEOUT}"
- "coop-cloud.${STACK_NAME}.version=2.19.4+6.9.4"
- "coop-cloud.${STACK_NAME}.version=2.19.1+6.9.4"
db:
image: "mariadb:12.2"
-13
View File
@@ -42,19 +42,6 @@ define('FORCE_SSL_ADMIN', true );
define('COOKIE_DOMAIN', \$_SERVER['HTTP_HOST']);"
{{ end }}
UPLOADS_HTACCESS=/var/www/html/wp-content/uploads/.htaccess
if [ ! -f "$UPLOADS_HTACCESS" ]; then
mkdir -p /var/www/html/wp-content/uploads
cat > "$UPLOADS_HTACCESS" <<'EOF'
# Prevent PHP execution in uploads directory
<FilesMatch "\.(?i:php|phtml|phar)$">
Require all denied
</FilesMatch>
EOF
chown www-data:www-data "$UPLOADS_HTACCESS"
fi
if [ -n "$@" ]; then
"$@"
fi
+7 -13
View File
@@ -3,18 +3,12 @@
Require all denied
</FilesMatch>
# Block XML-RPC
<Files xmlrpc.php>
Require all denied
</Files>
# Block wp2shell CVE-2026-63030
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{QUERY_STRING} rest_route=.*/batch/v1 [NC]
RewriteRule .* - [F,L]
RewriteRule ^wp-json/batch/v1 - [F,L]
</IfModule>
# Prevent PHP execution in uploads directory
<Directory /var/www/html/wp-content/uploads>
<FilesMatch "\.(?i:php|phtml|phar)$">
Require all denied
</FilesMatch>
</Directory>
{{ if eq (env "MULTISITE") "" -}}
# BEGIN WordPress
@@ -72,4 +66,4 @@ RewriteRule ^(.*\.php)$ $1 [L]
RewriteRule . index.php [L]
# END WordPress Multisite
{{- end }}
{{- end }}
-1
View File
@@ -1 +0,0 @@
patch to block XML-RPC via htaccess
-1
View File
@@ -1 +0,0 @@
temporarily block rest api against wp2shell CVE