Welcome Guest. Please Login or Register  


You are here: Index > Softaculous Auto Installer > Suggestions > Topic : WordPress installer creates security risk



Normal Mode | Print  

 WordPress installer creates security risk, Installer leaves out critical WP security measures (3 Replies, Read 3465 times)
erclerico
Group: Member
Post Group: Newbie
Posts: 2
Status:
Take a look at the wp-config.php when this install is complete - it leaves several key phrases used to secure encrypting to their default settings - for example:

define('AUTH_KEY', 'put your unique phrase here');

Here is a code snippet from a bash script I developed for installing WP that installs secure pass phrases:

Code

curl http://api.wordpress.org/secret-key/1.1/ -o "secret_key.txt"
TIC="'"

sed -e 's/define('"${TIC}"'DB_NAME'"${TIC}"', '"${TIC}"'[[:alnum:]]*'"${TIC}"')/define('"${TIC}"'DB_NAME'"${TIC}"', '"${TIC
}${DB_NAME}${TIC}"')/g
s/define('"${TIC}"'DB_USER'"${TIC}"', '"${TIC}"'[[:alnum:]]*'"${TIC}"')/define('"${TIC}"'DB_USER'"${TIC}"', '"${TIC}${DB_US
ER}${TIC}"')/g
s/define('"${TIC}"'DB_PASSWORD'"${TIC}"', '"${TIC}"'[[:alnum:]]*'"${TIC}"')/define('"${TIC}"'DB_PASSWORD'"${TIC}"', '"${TIC
}${DB_PASSWORD}${TIC}"')/g
s/define('"${TIC}"'DB_HOST'"${TIC}"', '"${TIC}"'[[:alnum:]]*'"${TIC}"')/define('"${TIC}"'DB_HOST'"${TIC}"', '"${TIC}${DB_HO
ST}${TIC}"')/g
s/'"$(printf '\015')"'$//g
s/$table_prefix  = '"${TIC}"'wp_'"${TIC}"'/$table_prefix  = '"${TIC}${TNAME}${TIC}"'/g
/define('"${TIC}"'AUTH_KEY'"${TIC}"', '"${TIC}"'.*'"${TIC}"');/ d
/define('"${TIC}"'SECURE_AUTH_KEY'"${TIC}"', '"${TIC}"'.*'"${TIC}"');/ d
/define('"${TIC}"'LOGGED_IN_KEY'"${TIC}"', '"${TIC}"'.*'"${TIC}"');/ d
s/define('"${TIC}"'NONCE_KEY'"${TIC}"', '"${TIC}"'.*'"${TIC}"');/WORDPRESS_KEYS/g
/WORDPRESS_KEYS/{
        r secret_key.txt
        d
}' "public_html/wp-config-sample.php" > "public_html/wp-config.php"
rm -f secret_key.txt


I think you guys use perl - so I don't know how much this helps.

Thank you.

-Erin
IP: --   


Threads
 erclerico   WordPress installer creates security risk, Installer leaves out critical WP security measures (3 Replies, Read 3465 times)
    |--  alons   Hi, We have...   on October 20, 2009, 6:12 am
    |--  erclerico   Wow you guys...   on October 20, 2009, 7:56 am
    |--  alons   Hi, No thank...   on October 20, 2009, 5:09 pm

« Previous    Next »

Normal Mode | Print  



Users viewing this topic
1 guests, 0 users.


All times are GMT. The time now is September 26, 2024, 3:40 am.

  Powered By AEF 1.0.8 © 2007-2008 Electron Inc.Queries: 10  |  Page Created In:0.028