Would be possible to create a specialized security topic in order to try to improve the security for all the members it would be win win for you and for all the customers . I am pretty sure that it would have a beneficial effect for all of us.
Hello @Borislav.VD,
Thanks for writing in!
I think that’s a good idea to have a thread on security. I will pass on your message to our leadership team for consideration wherein our lead developers can also chimin to contribute their own views on website security.
For now if you would like to get started, I suggest you to take a look at following articles:
Thanks.
I am going to create a special detail tutorial about brute attacks . But I am unabled to give any advices for sql injections,neither
RCE – Remote Code Execution
SQLi – SQL Injection
XSS – Cross Site Scripting attacks
CSRF – Cross Site Request Forgery
PHP Object Injection
RFI – Remote file inclusion
Authentication Bypass
XXE – External Entity Expansion (an XML based attack)
Please provide us with some information and details and plugins even you can create a specialized plugin I am quiet sure that it would be a best seller and the price would not be a problem at all
Hi there,
Thank you for your reply. We already informed our leadership team regarding this and they will act upon this if see fit.
Regarding the questions, I can give you some resources which will help around but the best source will be the google search for sure:
SQLi: https://wordpress.org/plugins/tags/sql-injection/
XSS: https://wordpress.org/plugins/search/xss/
CSRF: https://codex.wordpress.org/WordPress_Nonces
PHPoi: https://www.owasp.org/index.php/PHP_Object_Injection
RFI: https://blogvault.net/common-attacks-on-wordpress-sites-101-file-inclusion-arbitrary-code-execution/
XXE: https://www.acunetix.com/blog/articles/xml-external-entity-xxe-vulnerabilities/
Thank you.
This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.