
Summary: A web horde had a crappy server pattern which authorised people on a same box to review any others’ pattern files, as well as a little members of a “security” press have attempted to spin this in to a “WordPress vulnerability” story.
WordPress, similar to all other web applications, contingency store database tie info in transparent text. Encrypting certification doesn’t make a difference since a keys have to be stored where a web server can review them in sequence to decrypt a data. If a antagonistic user has entrance to a record complement — similar to they appeared to have in this box — it is pardonable to acquire a keys as well as decrypt a information. When we leave a keys to a doorway in a lock, does it assistance to close a door?
A scrupulously configured web server will not concede users to entrance a files of an additional user, in any case of record permissions. The web server is a shortcoming of a hosting provider. The methods for we do this (suexec, et al) have been around for 5+ years.
I’m not even starting to couple any of a articles since they have so most inaccuracies we spin stupider by celebration of a mass them.
If you’re a web horde as well as we spin a bad record permissions story in to a WordPress story, you’re we do something wrong.
P.S. Network Solutions, it’s “WordPress” not “Word Press.”
See a strange post:
Secure File Permissions Matter