Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-17-2016, 10:56 AM   #1
lakerslive
Confirmed User
 
Industry Role:
Join Date: Aug 2012
Posts: 929
How to protect WP from XSS or cross site scripting

Should i just remove all plugins and just go with default wp theme and thats it?

(yes, i always update but it still not enough) tnx

ive tried alot of the plugins,ex wordpence = junk

but they are still about to insert these effing files into my wordpress folders with encoded crap and turn my vps into a spam bot. I'm really desperate now.
lakerslive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 11:01 AM   #2
lakerslive
Confirmed User
 
Industry Role:
Join Date: Aug 2012
Posts: 929
Quote:
Originally Posted by lakerslive View Post
Should i just remove all plugins and just go with default wp theme and thats it?

(yes, i always update but it still not enough) tnx

ive tried alot of the plugins,ex wordpence = junk

but they are still about to insert these effing files into my wordpress folders with encoded crap and turn my vps into a spam bot. I'm really desperate now.
Has anyone tried using wordpress without any plugins? how did that turn out for u guys
lakerslive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 11:21 AM   #3
Sarn
Say for inflation - YES!
 
Sarn's Avatar
 
Industry Role:
Join Date: Sep 2015
Location: Russia
Posts: 9,864
noscript plugin + firefox good work for XSS detection.
make backups, read logs, fix problem
Sarn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 11:25 AM   #4
Barry-xlovecam
It's 42
 
Industry Role:
Join Date: Jun 2010
Location: Global
Posts: 18,083
Keep the server's MySQL version patched and up to date. If you cannot do it yourself -- find a shared host that keeps their servers up to date.

That is the first line of defense.
Barry-xlovecam is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 11:26 AM   #5
gnawledge
confirmed loser
 
gnawledge's Avatar
 
Industry Role:
Join Date: Jul 2012
Location: Florida
Posts: 1,092
What are the permissions set on those folders?

I use a lot of WordPress sites and never have those issues. I don't know if your host has permissions set differently. Because I have a server that's SUPHP and one is DSOHANLDER and I have to mess around with permissions to get things working right.

I googled your conundrum... take a look at this. Maybe you saw it maybe not.

https://hackertarget.com/xss-tutorial/
gnawledge is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 11:29 AM   #6
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,368
Quote:
Originally Posted by lakerslive View Post
How to protect WP from XSS or cross site scripting
The only 100% solution is to stop using all the vulnerable plugins. Unfortunately there is no universal solution which will give you a 100% guaranty. Also you can hire a coder who will check your plugins/themes for the XSS vulnerability and fix it if needed.

Quote:
Originally Posted by Sarn View Post
noscript plugin + firefox good work for XSS detection.
make backups, read logs, fix problem
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 11:40 AM   #7
Colmike9
(>^_^)b
 
Colmike9's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 7,224
You could put this in php.ini to stop it (But if the site relies on any of these functions then you'll have to find an alternate or allow individually if necessary)
Code:
allow_url_fopen = off
allow_url_include = off
disable_functions = "apache_child_terminate, apache_setenv, define_syslog_variables, escapeshellarg, escapeshellcmd, eval, exec, fp, fput, ftp_connect, ftp_exec, ftp_get, ftp_login, ftp_nb_fput, ftp_put, ftp_raw, ftp_rawlist, highlight_file, ini_alter, ini_get_all, ini_restore, inject_code, mysql_pconnect, openlog, passthru, php_uname, phpAds_remoteInfo, phpAds_XmlRpc, phpAds_xmlrpcDecode, phpAds_xmlrpcEncode, popen, posix_getpwuid, posix_kill, posix_mkfifo, posix_setpgid, posix_setsid, posix_setuid, posix_setuid, posix_uname, proc_close, proc_get_status, proc_nice, proc_open, proc_terminate, shell_exec, syslog, system, xmlrpc_entity_decode"
Then remove the base64 code that you see, de-encode it if you want to see what it's doing.
Then update things, remove plugins that you don't need or use, set your permissions to a safe level, etc.
__________________
Join the BEST cam affiliate program on the internet!
I've referred over $1.7mil in spending this past year, you should join in.
I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years..
Colmike9 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:02 PM   #8
Sarn
Say for inflation - YES!
 
Sarn's Avatar
 
Industry Role:
Join Date: Sep 2015
Location: Russia
Posts: 9,864
Quote:
Originally Posted by CyberSEO View Post
The only 100% solution is to stop using all the vulnerable plugins. Unfortunately there is no universal solution which will give you a 100% guaranty. Also you can hire a coder who will check your plugins/themes for the XSS vulnerability and fix it if needed.
Что тебе не нравится клоун? ты уже посоветовал не использовать твой плагин и еще фейспалмишь мне?
Sarn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:07 PM   #9
PornDiscounts-V
Confirmed User
 
PornDiscounts-V's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: L.A.
Posts: 5,740
It sounds like your server has dozens of backdoor scripts added to it. Your best bet is to export your posts via export tool, then delete everything. All of it. Then recreate it and import the posts. Then stop using themes from crappy sources and only use plugins you actually need.
__________________
Blog Posts - Contextual Links - Hardlinks on 600+ Blog Network
* Handwritten * 180 C Class IPs * Permanent! * Many Niches! * Bulk Discounts! GFYPosts /at/ J2Media.net
PornDiscounts-V is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:27 PM   #10
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,368
Quote:
Originally Posted by sarn View Post
Что тебе не нравится клоун? ты уже посоветовал не использовать твой плагин и еще фейспалмишь мне?
Клоун это ты. Читай посты людей выше и учи английский уже, дебил блять.

P.s. Или дело не в английском? Ты может вообще ущербный и даже по-русски не понимаешь, что такое "защитить wp сайт от xss"? Так хрена ли ты вообще делаешь на этом форуме?
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:31 PM   #11
lordaRaG0n
Confirmed User
 
Industry Role:
Join Date: Nov 2013
Posts: 93
If you're on an Apache 2 server try using the recommendations from securityheaders.io.
You should be able to implement the following without tweaks:
X-XSS-Protection
X-Frame-Options
X-Content-Type-Options

But for Content-Security-Policy you must whitelist in the headers every host/script that's allowed to use src= queries in your code. This is a bit tricky because you really need to review your code and you'll end up with a very long header if you got code from third parties and not internal, but it's doable.

The basic code without Content-Security-Policy can look like this in your .htaccess:

<IfModule mod_headers.c>
Header set X-XSS-Protection "1; mode=block"
Header set X-Frame-Options SAMEORIGIN
Header set X-Content-Type-Options nosniff
Header set Strict-Transport-Security "max-age=31536000; includeSubdomains"
</IfModule>

Also using mod_rewrite you can set additional restrictions on very specific strings which will help if you don't set a Content-Security-Policy:

RewriteEngine On
RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [OR]
RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
RewriteCond %{QUERY_STRING} (\<|%3C).*iframe.*(\>|%3E) [NC,OR]
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
RewriteRule ^(.*)$ index_error.php [F,L]
RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
RewriteRule .* - [F]

You can replace index_error.php to whatever error page you wish the use.

Hope it helps :D
__________________
lordaRaG0n is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:33 PM   #12
PornDiscounts-V
Confirmed User
 
PornDiscounts-V's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: L.A.
Posts: 5,740
His problem isn't xss. It is that he got hacked and they dropped shells all over his server.
__________________
Blog Posts - Contextual Links - Hardlinks on 600+ Blog Network
* Handwritten * 180 C Class IPs * Permanent! * Many Niches! * Bulk Discounts! GFYPosts /at/ J2Media.net
PornDiscounts-V is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:37 PM   #13
lakerslive
Confirmed User
 
Industry Role:
Join Date: Aug 2012
Posts: 929
not just 1 server, 2 different servers.. they not even linked to each other. I am not a server literate type guy.

I know some whm things... installing wp, customizing it, i knowledge here and there. But i have server knowledge of a 10 year old
lakerslive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:42 PM   #14
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,368
Quote:
Originally Posted by vvvvv View Post
His problem isn't xss. It is that he got hacked and they dropped shells all over his server.
In this case the suggestion is as simply as this: don't download any themes/plugins from the unknown sources. According to the recent reports, over 90% of all that nulled/hacked shit floating online is stuffed with built-in backdoors.
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:42 PM   #15
lakerslive
Confirmed User
 
Industry Role:
Join Date: Aug 2012
Posts: 929
just found out my server software is not upto date since i moved with liquidweb a month ago, when i first started them , there wasnt many xss injections, but a month later, they all started showing up,
lakerslive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:43 PM   #16
lakerslive
Confirmed User
 
Industry Role:
Join Date: Aug 2012
Posts: 929
i only use plugins from wordpress admin.. =(
lakerslive is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 12:46 PM   #17
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,368
Quote:
Originally Posted by lakerslive View Post
i only use plugins from wordpress admin.. =(
From what? You have to download them from wordpress.org (not every plugin is seriously tested even there) and from the trusted 3rd-party sources only.
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 01:06 PM   #18
Sarn
Say for inflation - YES!
 
Sarn's Avatar
 
Industry Role:
Join Date: Sep 2015
Location: Russia
Posts: 9,864
Quote:
Originally Posted by CyberSEO View Post
Клоун это ты. Читай посты людей выше и учи английский уже, дебил блять.

P.s. Или дело не в английском? Ты может вообще ущербный и даже по-русски не понимаешь, что такое "защитить wp сайт от xss"? Так хрена ли ты вообще делаешь на этом форуме?
а ты еще и буйный дурачек И проблема не в языке а в твоей тупости.
что я делаю на форуме тебя вообще не должно ебать, понимаешь?
Любое решение проблем с безопастностью начинается с диагностики и чтения логов, чтобы из за пары идиотов не переделывать работу дважды а то и больше. Поэтому вешаешь плагин носкрипт лазишь по сайту и смотришь откуда у тя xss - далее читаешь логи и смотришь куда что залили. Далее фильтруешь в коде баги.
Sarn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 01:14 PM   #19
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,368
Quote:
Originally Posted by Sarn View Post
что я делаю на форуме тебя вообще не должно ебать, понимаешь?
Да мне насрать. Тут и без тебя дураков хватет. Одним - больше, одним - меньше.

Quote:
Originally Posted by Sarn View Post
Любое решение проблем с безопастностью начинается с диагностики и чтения логов, чтобы из за пары идиотов не переделывать работу дважды а то и больше.
А, ну да, ну да... Стандартный анализ на XSS уязвимость это ж ни о чем, да? ;)

Quote:
Originally Posted by Sarn View Post
вешаешь плагин носкрипт
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 08:16 PM   #20
hdbuilder
Confirmed User
 
hdbuilder's Avatar
 
Industry Role:
Join Date: Jun 2012
Location: Canada
Posts: 1,338
If both of your servers are hacked your home PC is probably the source, run ComboFix on it, then change all servers panel, FTP, root... passwords, then you can clean your servers
__________________

ROBO SCRIPTS | WP CAM PLUGIN - Scripts To Promote Cam Sites - Chaturbate, BongaCams, Streamate, LiveJasmin, Stripchat...

The Cam Site Builder, The Cam Multi Site Builder -> MULTIPLE CAM SITES IN ONE
hdbuilder is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 09:36 PM   #21
Venum
Confirmed User
 
Venum's Avatar
 
Industry Role:
Join Date: Nov 2014
Posts: 181
Serve cached pages. Use nginx as a proxy cache to the front of the web, and keep infra behind proxy.
Venum is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-17-2016, 09:54 PM   #22
The Porn Nerd
Living The Dream
 
The Porn Nerd's Avatar
 
Industry Role:
Join Date: Jun 2009
Location: Inside a Monitor
Posts: 19,304
This thread is filled with nerds. LOL
__________________
My Affiliate Programs:
Porn Nerd Cash | Porn Showcase | Aggressive Gold (Coming Soon)

Over 90 paysites to promote!
Skype: peabodymedia
The Porn Nerd is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2016, 07:26 AM   #23
EvgenUA
Confirmed User
 
Industry Role:
Join Date: Dec 2009
Posts: 109
and russian hackers
EvgenUA is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2016, 08:45 AM   #24
Coup
🚨 PBBC International 🚨
 
Industry Role:
Join Date: Apr 2010
Location: /👁\
Posts: 9,932
OP I would suggest that you search for the names of the plugins and themes that you use here:

https://wpvulndb.com/plugins
https://wpvulndb.com/themes

Remove any that you find listed. You're likely using one or more that is a security vulnerability.
Coup is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2016, 08:59 AM   #25
xXXtesy10
Fakecoin Investor
 
xXXtesy10's Avatar
 
Industry Role:
Join Date: Jul 2012
Location: New Delhi, IN
Posts: 7,128
cyberseo trash garbage junk shit
__________________
WARNING: Stay Away From Marlboroack aka aka Brandon Ackerman
https://gfy.com/21169705-post8.html
Donny Long is Felon, Stalker, Scammer & Coward
http://www.ripoffreport.com/reports/...lon-int-761244
xXXtesy10 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2016, 09:03 AM   #26
just a punk
So fuckin' bored
 
just a punk's Avatar
 
Industry Role:
Join Date: Jun 2003
Posts: 32,368
Quote:
Originally Posted by xXXtesy10 View Post
cyberseo trash garbage junk shit
Put that slogan into your signature and link it to my site. I will give you $10, which is enough to feed up all your village
__________________
Obey the Cowgod
just a punk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-18-2016, 09:47 AM   #27
Sarn
Say for inflation - YES!
 
Sarn's Avatar
 
Industry Role:
Join Date: Sep 2015
Location: Russia
Posts: 9,864
Quote:
Originally Posted by EvgenUA View Post
and russian hackers
white hat. because who has not cracked the can not protect.
but if Putin asked


PS:restrict access to the admin panel wordpress only with your ip, even if you lose all your password all be safe. but it is better to detect and Fix xss in php code

.htaccess
<Files "wp-login.php">
Order deny,allow
Deny from All
Allow from 8.8.8.8
</Files>

8.8.8.8 - you static ip
Sarn is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
theme, default, tnx, update, plugins, xss, protect, cross, site, remove, scripting



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.