htaccess question | General Questions and Support | Forum Archive

The free forums are no longer in use. It remains available as read-only archive.

Avatar
Lost password?
Advanced Search
Forum Scope


Match



Forum Options



Minimum search word length is 3 characters - maximum search word length is 84 characters
The forums are currently locked and only available for read only access
sp_TopicIcon
htaccess question
March 28, 2011
9:07 pm
Avatar
spadilla
Member
Members
Forum Posts: 12
Member Since:
September 30, 2010
sp_UserOfflineSmall Offline

I use xCloner in multiple envirnoments (Joomla/Wordpress and other open source scripts) and want to make sure my backups and configs are secure as possible. I was going to add an htaccess file to the directory, but wasn't sure if this would cause problems. I did a search for the topic and found that there was mention of this in the old FAQ. Is there anyplace to read about security best practices and what I can safely put in an htaccess file in the xcloner directory without breaking abything - while still keeping everyting secure by blocking hackers?

Thanks again 🙂

March 29, 2011
6:12 am
Avatar
Ovidiu Liuta
Admin
Forum Posts: 2484
Member Since:
September 26, 2010
sp_UserOfflineSmall Offline

You could try and use this online utility http://tools.dynamic.....sword/ to generate a htpasswd rule and use that to protect your xcloner folder as well as the backups directory.

 

This might help also /tutorials/how-to-further-secure-directories-on-your-site/

 

Hope it helps! Ovidiu

March 29, 2011
5:52 pm
Avatar
spadilla
Member
Members
Forum Posts: 12
Member Since:
September 30, 2010
sp_UserOfflineSmall Offline

So are you saying it would be best to password protect the actual worpress plugin folder? I believe that might cause issues right?

 

I have my backups outside of the root, I am mainly concerned about the xcloner config which has the DB information in it. I will add the htaccess to the folder though 🙂

 

Edited to ask: Do you think it would be possible to include an htaccess file with:

<Directory />

Order Deny,Allow
Deny from All

</Directory>

in the plugin/component install? As I see it, it will get over written on each update if I manually add it.

March 29, 2011
6:20 pm
Avatar
Ovidiu Liuta
Admin
Forum Posts: 2484
Member Since:
September 26, 2010
sp_UserOfflineSmall Offline

I was not referring to the actual wp-content/plugins folder, but the wp-contents/plugins/xcloner-backup-and-restore folder, you can protect that without issues.

 

Ovidiu

March 29, 2011
6:51 pm
Avatar
spadilla
Member
Members
Forum Posts: 12
Member Since:
September 30, 2010
sp_UserOfflineSmall Offline

Password protecting wp-contents/plugins/xcloner-backup-and-restore gave a 404 error in the admin area of Wordpress. I added an htaccess with the above referenced content, but am afraid it will jsut be overwritten on the next update.

March 29, 2011
7:26 pm
Avatar
Ovidiu Liuta
Admin
Forum Posts: 2484
Member Since:
September 26, 2010
sp_UserOfflineSmall Offline

You could add the changes inside your main .htaccess file by using either the RewriteCond to match the subfolder you want to protect as indicated here http://www.hacksar.c.....ed/  for instance, this might be a little overly complicated however. You could also add ip banning if you like, so for that folder, only your ip has access.

 

As you know, XCloner runs in standalone mode, so you could also simply rename the wp-contents/plugins/xcloner-backup-and-restore  folder to something else, it will make it harder to target.

 

Anyway, if somebody does get access to your site, the main mysql details are also stored in the wp-config.php file, so best protection is to keep backups, and always try to keep the site code updated, as well as the server software. 

 

Ovidiu

Forum Timezone: America/Chicago
Most Users Ever Online: 867
Currently Online:
Guest(s) 1
Currently Browsing this Page:
1 Guest(s)
Top Posters:
mlguru: 30
Django29: 29
Andy: 21
D: 21
Marcus: 20
Jamie F: 19
Member Stats:
Guest Posters: 738
Members: 10030
Moderators: 2
Admins: 3
Forum Stats:
Groups: 3
Forums: 7
Topics: 2397
Posts: 8236
Newest Members:
Omar Vera
Moderators: TriP: 0, Steve Burge: 0
Administrators: Ovidiu Liuta: 2484, Victor Drover: 1, Valentin Barbu: 0