no1nose
Forum Replies Created
-
You should read what LiteSpeed warns about when noabort is used the way Wordfence suggests:
https://docs.litespeedtech.com/lsws/cp/cpanel/long-run-script/#easiest-solution
https://www.litespeedtech.com/support/forum/threads/wordfence-for-wordpress-expands-litespeeds-noabort-exception-site-wide-because-its-own-architecture-cannot-isolate-the-requests-that-need-it.24173/You should read what LiteSpeed warns about when
noabortis used the way Wordfence suggests:https://docs.litespeedtech.com/lsws/cp/cpanel/long-run-script/#easiest-solution
https://www.litespeedtech.com/support/forum/threads/wordfence-for-wordpress-expands-litespeeds-noabort-exception-site-wide-because-its-own-architecture-cannot-isolate-the-requests-that-need-it.24173/You should read what LiteSpeed says about using the WF “fix”.
Danger
We know it is tempting to simply add noabort for all requests (.*), but we strongly suggest you do not do this.
Adding noabort for all requests to .htaccess is not standard practice and may cause unintended consequences. For example, a site running in a Cloudlinux Lightweight Virtual Environment (LVE) that is hitting resource limits can become completely tied up. This is because LSWS is not able to abort any external app requests.
We suggest you add noabort selectively, and only when absolutely necessary. Apply it to a specific script URL instead of .*. The narrower the scope, the less likely you will run into an issue.
This is not a LiteSpeed request-level-temination, but a native PHP termination controlled by max_execution_timeout limit. LiteSpeed allows to override this limit by noabort directive, but the way how Wordfence suggests it is a high security risk! Wordfence knows about this risk since a degade, but doesn’t fix it!
Wordfence for WordPress on LiteSpeed may weaken PHP process protection site-wide – and Wordfence has known about it for at least a decade
byu/Good_Flight6250 inWordPress