{"id":6659012,"date":"2015-10-18T02:14:27","date_gmt":"2015-10-18T02:14:27","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/improve-security\/"},"modified":"2016-08-30T19:14:50","modified_gmt":"2016-08-30T19:14:50","slug":"improve-security","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/improve-security\/","title":{"rendered":"Improve security"},"content":{"rendered":"<p>WordPress installation now automatically create .htaccess file. WordPress should add <code>Options -Indexes<\/code> into the .htaccess, so non-real file\/folder without permission will get 404 error without the need of placing empty index.html\/index.php. This should also eliminate some security notices when user ran security checks on wordpress sites.<\/p>\n<p>After I ran a test against my installation on WordPress 4.3.1 multisites, Detectify gave me following warnings.<\/p>\n<ul>\n<li><strong>Cookie is not set to be HttpOnly &#8211; \/wp-login.php<\/strong> One or more cookies lack the flag HttpOnly-flag. If an attacker discovers an XSS he may use it to steal cookies which haven&#8217;t got the HttpOnly-flag.<\/li>\n<li><strong>WordPress Username Enumeration &#8211; \/?author={id}<\/strong> A flaw in WordPress makes it possible to enumerate which usernames are registered. An attacker can use this information in another step of an attack, for example trying common passwords against the users, spear fishing or social engineering.<\/li>\n<li><strong>Content Sniffing<\/strong> This may open up for XSS attacks as browsers will attempt to guess how to render specific resources without the correct policies.<\/li>\n<li><strong>Empty Document &#8211; \/wp-includes\/Text\/Diff.php<\/strong> Direct access<\/li>\n<li><strong>Empty Document &#8211; \/wp-includes\/admin-bar.php<\/strong> Direct access<\/li>\n<li><strong>Empty Document &#8211; \/wp-includes\/category-template.php<\/strong> Direct access<\/li>\n<\/ul>\n<p>Therefore, I recommend:<\/p>\n<ol>\n<li>Add <code>Options -Indexes<\/code> and <code>Header set X-Content-Type-Options &quot;nosniff&quot;<\/code> in .htaccess<\/li>\n<li>Remove all index.php\/index.html from wordpress directories<\/li>\n<li>Add <code>defined( &#039;ABSPATH&#039; ) or die( &#039;No script kiddies please!&#039; );<\/code> into php file header Ref. https:\/\/codex.wordpress.org\/Writing_a_Plugin#Plugin_Files<\/li>\n<\/ol>\n<p>Thanks!<\/p>\n","protected":false},"template":"","class_list":["post-6659012","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/6659012","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/6659012\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=6659012"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}