Plugins: Got a Scare for Ya Today, People

Jan 21, 2008

Did you know that your blog can be hacked via your plugins folder? I had no idea. I write, not hack.

But here’s a cool post from  Deep Jive Interests, where they say:

If you’re running Wordpress, unless you’ve already locked down your Wp-content folder with some .htaccess fixes, you may not notice that your Wp-content/plugins folder is naked and bare to the world.  That is, navigate to http://www.yourblogname.com/wp-content/plugins and you may find a directory listing of your plugins folder, files and all.  How do you fix it?  Easy.  Just upload an empty index.html into the wp-content/plugins folder and its all fixed.

Well, thank you, Deep Jive! Really hard to do, eh? I don’t want my plugins folder or anything else about me naked in public.

Get ‘er done!

No TweetBacks yet. (Be the first to Tweet this post)

Share with others

No Responses so far | Have Your Say!

Leave a Feedback

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Switch to our mobile site