![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,595
|
![]() Hi there!
How big of a security risk is running Wordpress on older versions of PHP? And when considering an upgrade one should move to 7.4 or the latest stable of 8.x? (I usually have only 2-3 plugins, so I guess the upgrade shouldn't cause much of a trouble) I wasn't thinking about updating it, but one of the blogs is using AIOSEO and it says the support for 7.3.3 will be discontinued this year. Thanks.
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Nov 2005
Posts: 2,166
|
Your problem won't be the php version, but wordpress itself.
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,595
|
You mean security wise? Fortunately I didn't had any issues (hacks etc) in the last year (or I just dont know about it which is always a possibility).
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Your issue won't be with PHP, it will be with wordpress itself if it's an older version + whatever million plugins you have installed for it. You don't even get the common courtesy of a human being hacking you anymore, it's just bots doing it at this point. If you are running PHP 5 or PHP 8 it won't make a difference if your code has exploits.
The PHP version is largely irrelevant - I know alot of people are all worried about EOL on PHP 7 and so forth but the concern with these older PHP versions isn't that your site will get hacked - anything exploit that comes out for older PHP is very likely to be something that requires local access to the server to begin with rather then something that can be done remotely. There's still sites running PHP 5.2 out there and not getting hacked.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Confirmed User
Join Date: Nov 2005
Posts: 2,166
|
Yes, was talking security wise. As Konrad up there mentioned also, i know plenty of sites on php 5. Nothing wrong with them. They might have some upgrading issues like you're facing etc, but other then that, it works, it won't stop working cause of eol.
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#6 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
It depend on several factors , like:
- How big is your site. If your site receives only few hits daily mostly like nobody knows about it therefore wont be interesting to "get in" even if you leave open door - what kind of plugins you have installed - is it WordPress version up to date - do you have installed script firewall of any kind (mod security, CSF, your own rules) - do you have installed security patches for old PHP version |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Quote:
Like I said though bigger issue is old wordpress and plugins and not PHP or Apache itself.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 |
Living inside your head.
Industry Role:
Join Date: Dec 2002
Location: In your AirBNB
Posts: 20,434
|
Best thing you can do is get rid of "Generated by wordpress" and all other wordpress identifiers out of your source code. There are plugins to help do that.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
That will make no difference. There are other markers that something is wordpress like shit in the html source with directories like wp-content and so forth.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Living inside your head.
Industry Role:
Join Date: Dec 2002
Location: In your AirBNB
Posts: 20,434
|
It isn't foolproof, but it helps. Not all bots are searching for every marker. Most are searching for the most obvious.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
The bots are searching for known exploits, so they'll attack specific files and paths for specific plugins. They aren't just looking for wordpress installations in general.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
I base that on behavior on two remain sites which i have - first one , which was my flagship site and had 65k daily traffic and tons of backlinks at one point but now almost nothing, it is still hammered on daily bases by various bots trying get into wordpress and other common security holes. But the second site which had only 3k daily in it's best day and which is even older site, from year 1998, but it's not hammered by any bot compared to first site.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 |
Confirmed User
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,595
|
Thanks for the answers
__________________
![]() Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 |
GFY'S #1 retard
Industry Role:
Join Date: Feb 2003
Location: Kelowna
Posts: 10,478
|
Good thing about Wordpress is even if someone hacked my shit and destroyed my entire site I could have my backup running again in 10 minutes.
__________________
I make my money from people jerking off |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
No one really destroys sites now unless they hate you specifically. What they do instead is they make redirects to some affiliate offers to make money off your traffic. Sometimes it takes weeks or months before people realize they were even hacked because it only redirects for certain geos for instance.
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
GFY'S #1 retard
Industry Role:
Join Date: Feb 2003
Location: Kelowna
Posts: 10,478
|
Quote:
Well I make $0 off my site right now so does it even fucking matter? I have the most innovative, most advanced website for media display... $0 per month Meanwhile if you run a shit tube you can be loaded with 0 innovation Such is life in 2023
__________________
I make my money from people jerking off |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#17 | |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
Quote:
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#18 | |
Confirmed User
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
|
Quote:
![]()
__________________
Mechanical Bunny Media Mechbunny Tube Script | Mechbunny Webcam Aggregator Script | Custom Web Development |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#19 | |
(>^_^)b
Industry Role:
Join Date: Dec 2011
Posts: 7,224
|
Quote:
![]()
__________________
![]() I've referred over $1.7mil in spending this past year, you should join in. ![]() ![]() I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years.. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#20 |
Confirmed User
Industry Role:
Join Date: Mar 2003
Location: Miami, FL
Posts: 2,089
|
Leaving your default folder structure is a big security issue. I can't tell you how many times I check for wp-admin and shake my head that a login pops up.
__________________
GetSCORECash.com | In the Biz Since 1991
Big Tits | Granny & MILFs | Amateurs | Big Booty | Foot Fetish | BBW | Teens Hosted Embeds | MP4s | RSS Feeds | FHGs | Model Directory |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#21 |
Icq: 14420613
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
|
Old plugins is where you will get fucked
__________________
Need WebHosting ? Email me for some great deals [email protected] |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#22 |
(>^_^)b
Industry Role:
Join Date: Dec 2011
Posts: 7,224
|
Just use Joomla, no one hacks that unless it's a targeted brute force to get login info or something not worth the effort like that.
![]()
__________________
![]() I've referred over $1.7mil in spending this past year, you should join in. ![]() ![]() I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years.. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#23 |
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
|
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#24 |
GFY'S #1 retard
Industry Role:
Join Date: Feb 2003
Location: Kelowna
Posts: 10,478
|
Wordpress is actually pretty awesome... so much shit you can do with it, mostly for free!
__________________
I make my money from people jerking off |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#25 | |
Confirmed User
Join Date: Nov 2005
Posts: 2,166
|
Quote:
![]() Furthermore, your admin login is irrelevant. You can identify wordpress just through certain source code things. Check wpscan. it has a hash for each wordpress version, so not only are you going to get identified, you're also going to be identified which version of wordpress you're running just from looking at your index source code and how it's layed out. Then it's free game, every plugin you have will get identified, and then the fun starts.
__________________
agentGFY *at* gmail.com |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#26 |
(>^_^)b
Industry Role:
Join Date: Dec 2011
Posts: 7,224
|
Honestly, no one's going to bother with hacking a WP porn site, except for rare targeted cases.
All I ever did were things like doing an injection when WP was more vulnerable with sites using pagination and not setting it up to use slugs, then adding in a funny pic somewhere. Or getting into workers' computers, turning up the volume, then making Appletalk scare them.. Or in school, making the teacher's CD drive constantly open
__________________
![]() I've referred over $1.7mil in spending this past year, you should join in. ![]() ![]() I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years.. ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#27 |
Too lazy to set a custom title
Industry Role:
Join Date: Aug 2002
Posts: 55,229
|
too many hosts have servers with outdated php. for wp minimum is 7.4, but 8.0 or 8.1 (this is what i use)
7.4 is the more "safe" version as some peoples code may be incompatible with 8.1 etc. i noticed while doing dev work for a few clients on vacares, they are shipping 7.3 on their servers wish they could upgrade the defaults for that, its a pain when doing work and want to use updated code.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence. ![]() WP Stuff |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#28 |
Confirmed User
Join Date: Nov 2005
Posts: 2,166
|
Yea, the way you describe things, it's rather clear you didnt do anything.
__________________
agentGFY *at* gmail.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#29 | |
(>^_^)b
Industry Role:
Join Date: Dec 2011
Posts: 7,224
|
Quote:
![]()
__________________
![]() I've referred over $1.7mil in spending this past year, you should join in. ![]() ![]() I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years.. ![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#30 | |
👏 REVOLUTIONARY 👏
Industry Role:
Join Date: Jan 2016
Posts: 1,440
|
Quote:
But hey, when you're back here in a month complaining don't act surprised when people point at your neglect here as the reason why.
__________________
![]() |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#31 |
Confirmed User
Industry Role:
Join Date: Apr 2019
Posts: 125
|
you can mitigate a lot of potential wordpress attacks on cloudflare with filters, if you know a bit about wordpress and bots and attackers metrics . i use a couple of older wp versions and also older php versions and they havent been hacked yet. just close everything that lets people from outside try to comment, mail, post etc. the easiest way is to use cloudflares waf > xmlrpc.php, wp-login.php, wp-comments.php, wp-admin, wp-mail, rest api, throw and block everyone out who is trying to access those from outside,+ it also takes load from your own server , its also good to do this on newer versions
|
![]() |
![]() ![]() ![]() ![]() ![]() |