Protecting directories in vBulletin & WordPress

Discussion in 'Security and Legal' started by Nick, May 17, 2009.

  1. Nick

    Nick Regular Member

    Joined:
    Jul 27, 2008
    Messages:
    7,441
    Likes Received:
    218
    What vBulletin directories, other than admincp can be .htaccess protected without disrupting functionality?

    What about in WordPress?
     
  2. Wayne Luke

    Wayne Luke Regular Member

    Joined:
    Apr 2, 2009
    Messages:
    991
    Likes Received:
    276
    In vBulletin you can close off the admincp, modcp, install and includes directory without affecting functionality. It also allows the attachments directory to be stored above the webroot or closed off with .htaccess.

    In wordpress, you should be able to block of wp-admin and wp-includes with .htaccess. However the wp-content directory should be web accessible.

    One thing to do is to turn off directory listing and add a blank .html file in the directory or you could use PHP to direct them to the Site Map of your site. That way unless they know the exact path, they can't explore.
     
  3. Cerberus

    Cerberus Admin Talk Staff

    Joined:
    May 3, 2009
    Messages:
    1,031
    Likes Received:
    500
    You can not close off the modcp without hurting functionality if you have vbseo installed. It will end up as a pain in the rear.I can tell you that from experience.
     
  4. Wayne Luke

    Wayne Luke Regular Member

    Joined:
    Apr 2, 2009
    Messages:
    991
    Likes Received:
    276
    That's a failure within vBSEO then and should be considered a security risk in that addon.

    I was thinking about buying vBSEO but I don't even upload the modcp folder on sites that I administrate so that would be a deal killer if the addon doesn't work properly without it.
     
  5. Nick

    Nick Regular Member

    Joined:
    Jul 27, 2008
    Messages:
    7,441
    Likes Received:
    218
    Were you ever given a reason as to why it doesn't work properly? As Wayne said, this is a huge fall-back but I'm curious to know why it's so vital.
     
  6. Ak Worm

    Ak Worm Grand Master

    Joined:
    May 22, 2009
    Messages:
    979
    Likes Received:
    20
    First Name:
    Corey
    vBulletin, Well I Admin Only On One Site Of vBulletin. Web Access? How Can We Protect?
     
  7. Boss

    Boss Resident Silly Man

    Joined:
    May 23, 2009
    Messages:
    941
    Likes Received:
    23
    Location:
    California
    First Name:
    Alex
    You can always rename your directories. :)
     
  8. Tyler

    Tyler The Badministrator

    Joined:
    Dec 23, 2007
    Messages:
    3,079
    Likes Received:
    63
    Location:
    Long Island, NY
    First Name:
    Tyler
    I'd like to know more about this, too. It seems odd that it would be this way.
     
  9. Soliloquy

    Soliloquy Regular Member

    Joined:
    Jun 3, 2009
    Messages:
    2,402
    Likes Received:
    66
    Location:
    New York City
    Just the Mod CP or the Admin CP as well? I could probably live without the Mod CP...
     
  10. Nick

    Nick Regular Member

    Joined:
    Jul 27, 2008
    Messages:
    7,441
    Likes Received:
    218
    I think he implied just the ModCP. It would be a huge shame if he meant the AdminCP as well, though.
     

Share This Page