Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 09-03-2023, 12:55 AM   #1
Paul&John
Confirmed User
 
Paul&John's Avatar
 
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,595
Running Wordpress on PHP7.2/7.3

Hi there!

How big of a security risk is running Wordpress on older versions of PHP? And when considering an upgrade one should move to 7.4 or the latest stable of 8.x? (I usually have only 2-3 plugins, so I guess the upgrade shouldn't cause much of a trouble)

I wasn't thinking about updating it, but one of the blogs is using AIOSEO and it says the support for 7.3.3 will be discontinued this year.

Thanks.
__________________
Use coupon 'pauljohn' for a $1 discount at already super cheap NameSilo!
Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here
Paul&John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-03-2023, 08:00 AM   #2
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,166
Your problem won't be the php version, but wordpress itself.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 01:39 AM   #3
Paul&John
Confirmed User
 
Paul&John's Avatar
 
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,595
You mean security wise? Fortunately I didn't had any issues (hacks etc) in the last year (or I just dont know about it which is always a possibility).
__________________
Use coupon 'pauljohn' for a $1 discount at already super cheap NameSilo!
Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here
Paul&John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 02:54 AM   #4
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Your issue won't be with PHP, it will be with wordpress itself if it's an older version + whatever million plugins you have installed for it. You don't even get the common courtesy of a human being hacking you anymore, it's just bots doing it at this point. If you are running PHP 5 or PHP 8 it won't make a difference if your code has exploits.

The PHP version is largely irrelevant - I know alot of people are all worried about EOL on PHP 7 and so forth but the concern with these older PHP versions isn't that your site will get hacked - anything exploit that comes out for older PHP is very likely to be something that requires local access to the server to begin with rather then something that can be done remotely. There's still sites running PHP 5.2 out there and not getting hacked.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 03:00 AM   #5
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,166
Quote:
Originally Posted by Paul&John View Post
You mean security wise? Fortunately I didn't had any issues (hacks etc) in the last year (or I just dont know about it which is always a possibility).
Yes, was talking security wise. As Konrad up there mentioned also, i know plenty of sites on php 5. Nothing wrong with them. They might have some upgrading issues like you're facing etc, but other then that, it works, it won't stop working cause of eol.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 04:13 AM   #6
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
It depend on several factors , like:

- How big is your site. If your site receives only few hits daily mostly like nobody knows about it therefore wont be interesting to "get in" even if you leave open door
- what kind of plugins you have installed
- is it WordPress version up to date
- do you have installed script firewall of any kind (mod security, CSF, your own rules)
- do you have installed security patches for old PHP version
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 04:32 AM   #7
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by Klen View Post
It depend on several factors , like:

- How big is your site. If your site receives only few hits daily mostly like nobody knows about it therefore wont be interesting to "get in" even if you leave open door
Bots are going to hammer it 24/7 looking for exploits. If he has anything else on the same server it can get compromised.

Like I said though bigger issue is old wordpress and plugins and not PHP or Apache itself.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 04:57 AM   #8
Mr Pheer
Living inside your head.
 
Mr Pheer's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: In your AirBNB
Posts: 20,434
Best thing you can do is get rid of "Generated by wordpress" and all other wordpress identifiers out of your source code. There are plugins to help do that.
Mr Pheer is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 06:01 AM   #9
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by Mr Pheer View Post
Best thing you can do is get rid of "Generated by wordpress" and all other wordpress identifiers out of your source code. There are plugins to help do that.
That will make no difference. There are other markers that something is wordpress like shit in the html source with directories like wp-content and so forth.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 06:20 AM   #10
Mr Pheer
Living inside your head.
 
Mr Pheer's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: In your AirBNB
Posts: 20,434
Quote:
Originally Posted by k0nr4d View Post
That will make no difference. There are other markers that something is wordpress like shit in the html source with directories like wp-content and so forth.
It isn't foolproof, but it helps. Not all bots are searching for every marker. Most are searching for the most obvious.
Mr Pheer is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 06:31 AM   #11
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by Mr Pheer View Post
It isn't foolproof, but it helps. Not all bots are searching for every marker. Most are searching for the most obvious.
The bots are searching for known exploits, so they'll attack specific files and paths for specific plugins. They aren't just looking for wordpress installations in general.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 06:57 AM   #12
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by k0nr4d View Post
Bots are going to hammer it 24/7 looking for exploits. If he has anything else on the same server it can get compromised.

Like I said though bigger issue is old wordpress and plugins and not PHP or Apache itself.
I base that on behavior on two remain sites which i have - first one , which was my flagship site and had 65k daily traffic and tons of backlinks at one point but now almost nothing, it is still hammered on daily bases by various bots trying get into wordpress and other common security holes. But the second site which had only 3k daily in it's best day and which is even older site, from year 1998, but it's not hammered by any bot compared to first site.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 12:06 PM   #13
Paul&John
Confirmed User
 
Paul&John's Avatar
 
Industry Role:
Join Date: Aug 2005
Location: YUROP
Posts: 8,595
Thanks for the answers
__________________
Use coupon 'pauljohn' for a $1 discount at already super cheap NameSilo!
Anal Webcams | Kinky Trans Cams Live | Hotwife XXX Tube | Get your Proxies here
Paul&John is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 12:10 PM   #14
Huggles
GFY'S #1 retard
 
Industry Role:
Join Date: Feb 2003
Location: Kelowna
Posts: 10,478
Good thing about Wordpress is even if someone hacked my shit and destroyed my entire site I could have my backup running again in 10 minutes.
__________________
I make my money from people jerking off
Huggles is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-04-2023, 11:30 PM   #15
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by Huggles View Post
Good thing about Wordpress is even if someone hacked my shit and destroyed my entire site I could have my backup running again in 10 minutes.
No one really destroys sites now unless they hate you specifically. What they do instead is they make redirects to some affiliate offers to make money off your traffic. Sometimes it takes weeks or months before people realize they were even hacked because it only redirects for certain geos for instance.
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2023, 12:08 AM   #16
Huggles
GFY'S #1 retard
 
Industry Role:
Join Date: Feb 2003
Location: Kelowna
Posts: 10,478
Quote:
Originally Posted by k0nr4d View Post
No one really destroys sites now unless they hate you specifically. What they do instead is they make redirects to some affiliate offers to make money off your traffic. Sometimes it takes weeks or months before people realize they were even hacked because it only redirects for certain geos for instance.

Well I make $0 off my site right now so does it even fucking matter?


I have the most innovative, most advanced website for media display... $0 per month


Meanwhile if you run a shit tube you can be loaded with 0 innovation


Such is life in 2023
__________________
I make my money from people jerking off
Huggles is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2023, 06:36 AM   #17
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by k0nr4d View Post
No one really destroys sites now unless they hate you specifically. What they do instead is they make redirects to some affiliate offers to make money off your traffic. Sometimes it takes weeks or months before people realize they were even hacked because it only redirects for certain geos for instance.
Yep. times when purpose of hacking was to post message "you been defaced" are long gone.
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2023, 06:37 AM   #18
k0nr4d
Confirmed User
 
k0nr4d's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Poland
Posts: 9,228
Quote:
Originally Posted by Huggles View Post
Well I make $0 off my site right now so does it even fucking matter?


I have the most innovative, most advanced website for media display... $0 per month
Yeah but maybe the hacker is making money
k0nr4d is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2023, 08:11 AM   #19
Colmike9
(>^_^)b
 
Colmike9's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 7,224
Quote:
Originally Posted by Klen View Post
Yep. times when purpose of hacking was to post message "you been defaced" are long gone.
I still do this
__________________
Join the BEST cam affiliate program on the internet!
I've referred over $1.7mil in spending this past year, you should join in.
I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years..
Colmike9 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2023, 03:07 PM   #20
SCORE Ralph
Confirmed User
 
SCORE Ralph's Avatar
 
Industry Role:
Join Date: Mar 2003
Location: Miami, FL
Posts: 2,089
Quote:
Originally Posted by k0nr4d View Post
That will make no difference. There are other markers that something is wordpress like shit in the html source with directories like wp-content and so forth.
Leaving your default folder structure is a big security issue. I can't tell you how many times I check for wp-admin and shake my head that a login pops up.
__________________
GetSCORECash.com | In the Biz Since 1991
Big Tits | Granny & MILFs | Amateurs | Big Booty | Foot Fetish | BBW | Teens
Hosted Embeds | MP4s | RSS Feeds | FHGs | Model Directory
SCORE Ralph is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2023, 03:55 PM   #21
sandman!
Icq: 14420613
 
sandman!'s Avatar
 
Industry Role:
Join Date: Mar 2001
Location: chicago
Posts: 15,432
Old plugins is where you will get fucked
__________________
Need WebHosting ? Email me for some great deals [email protected]
sandman! is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-05-2023, 03:57 PM   #22
Colmike9
(>^_^)b
 
Colmike9's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 7,224
Just use Joomla, no one hacks that unless it's a targeted brute force to get login info or something not worth the effort like that.
__________________
Join the BEST cam affiliate program on the internet!
I've referred over $1.7mil in spending this past year, you should join in.
I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years..
Colmike9 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-06-2023, 12:29 AM   #23
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Quote:
Originally Posted by Colmike9 View Post
I still do this
You going to jail pal
Klen is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-06-2023, 12:35 AM   #24
Huggles
GFY'S #1 retard
 
Industry Role:
Join Date: Feb 2003
Location: Kelowna
Posts: 10,478
Wordpress is actually pretty awesome... so much shit you can do with it, mostly for free!
__________________
I make my money from people jerking off
Huggles is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2023, 10:35 AM   #25
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,166
Quote:
Originally Posted by SCORE Ralph View Post
Leaving your default folder structure is a big security issue. I can't tell you how many times I check for wp-admin and shake my head that a login pops up.
It's not a "big security issue" :P. It's actually just a small nuissance. You think it would take a long time to find your admin login?
Furthermore, your admin login is irrelevant. You can identify wordpress just through certain source code things. Check wpscan. it has a hash for each wordpress version, so not only are you going to get identified, you're also going to be identified which version of wordpress you're running just from looking at your index source code and how it's layed out. Then it's free game, every plugin you have will get identified, and then the fun starts.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2023, 11:10 AM   #26
Colmike9
(>^_^)b
 
Colmike9's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 7,224
Honestly, no one's going to bother with hacking a WP porn site, except for rare targeted cases.
All I ever did were things like doing an injection when WP was more vulnerable with sites using pagination and not setting it up to use slugs, then adding in a funny pic somewhere. Or getting into workers' computers, turning up the volume, then making Appletalk scare them..
Or in school, making the teacher's CD drive constantly open
__________________
Join the BEST cam affiliate program on the internet!
I've referred over $1.7mil in spending this past year, you should join in.
I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years..
Colmike9 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2023, 02:49 PM   #27
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,229
too many hosts have servers with outdated php. for wp minimum is 7.4, but 8.0 or 8.1 (this is what i use)

7.4 is the more "safe" version as some peoples code may be incompatible with 8.1 etc.

i noticed while doing dev work for a few clients on vacares, they are shipping 7.3 on their servers wish they could upgrade the defaults for that, its a pain when doing work and want to use updated code.
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2023, 04:54 PM   #28
ladida
Confirmed User
 
ladida's Avatar
 
Join Date: Nov 2005
Posts: 2,166
Quote:
Originally Posted by Colmike9 View Post
All I ever did <cut> Or getting into workers' computers, turning up the volume, then making Appletalk scare them..
Or in school, making the teacher's CD drive constantly open
Yea, the way you describe things, it's rather clear you didnt do anything.
__________________
agentGFY *at* gmail.com
ladida is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2023, 05:04 PM   #29
Colmike9
(>^_^)b
 
Colmike9's Avatar
 
Industry Role:
Join Date: Dec 2011
Posts: 7,224
Quote:
Originally Posted by ladida View Post
Yea, the way you describe things, it's rather clear you didnt do anything.
k
__________________
Join the BEST cam affiliate program on the internet!
I've referred over $1.7mil in spending this past year, you should join in.
I make a lot more money in the medical field in a lab now, fuck you guys. Don't ask me to come back, but do join Chaturbate in my sig, it still makes bank without me touching shit for years..
Colmike9 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-08-2023, 08:19 PM   #30
Kittens
👏 REVOLUTIONARY 👏
 
Kittens's Avatar
 
Industry Role:
Join Date: Jan 2016
Posts: 1,440
Quote:
Originally Posted by Huggles View Post
Well I make $0 off my site right now so does it even fucking matter?


I have the most innovative, most advanced website for media display... $0 per month


Meanwhile if you run a shit tube you can be loaded with 0 innovation


Such is life in 2023
The worst part is that you think if you get hacked that someone's gonna inject an ad on your site and not completely destroy your server IP and domain's reputation with spam filters because the main reason to hack sites is to spam from them.

But hey, when you're back here in a month complaining don't act surprised when people point at your neglect here as the reason why.
__________________
Kittens is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-09-2023, 10:30 PM   #31
jamezon
Confirmed User
 
Industry Role:
Join Date: Apr 2019
Posts: 125
you can mitigate a lot of potential wordpress attacks on cloudflare with filters, if you know a bit about wordpress and bots and attackers metrics . i use a couple of older wp versions and also older php versions and they havent been hacked yet. just close everything that lets people from outside try to comment, mail, post etc. the easiest way is to use cloudflares waf > xmlrpc.php, wp-login.php, wp-comments.php, wp-admin, wp-mail, rest api, throw and block everyone out who is trying to access those from outside,+ it also takes load from your own server , its also good to do this on newer versions
jamezon is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 09-10-2023, 08:32 AM   #32
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,229
Quote:
Originally Posted by Mr Pheer View Post
Best thing you can do is get rid of "Generated by wordpress" and all other wordpress identifiers out of your source code. There are plugins to help do that.
add_filter( 'the_generator', '__return_null' );
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks

Tags
upgrade, running, wordpress, updating, guess, thinking, trouble, aioseo, discontinued, 7.3.3, support, blogs, 8.x, risk, versions, php, security, php7.2/7.3, stable, 2-3, move, plugins



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.