{"id":232139,"date":"2023-01-21T11:47:00","date_gmt":"2023-01-21T08:47:00","guid":{"rendered":"https:\/\/wordpress.mediadoma.com\/?p=232139"},"modified":"2022-11-10T07:47:53","modified_gmt":"2022-11-10T04:47:53","slug":"tystnad-aer-guld-regel-i-webbserverkataloger","status":"publish","type":"post","link":"https:\/\/wordpress.mediadoma.com\/sv\/tystnad-aer-guld-regel-i-webbserverkataloger\/","title":{"rendered":"[Tystnad \u00e4r guld] Regel i webbserverkataloger"},"content":{"rendered":"<p>Webbservern kommer att ha vissa standardfilnamn (i prioritetsordning) som index.php, index.html etc om du skriver in URL till en webbmapp ist\u00e4llet f\u00f6r en specifik fil. Men om det inte finns n\u00e5gra s\u00e5dana standardfiler, kommer den eventuellt att lista filnamnen (med l\u00e4nkar) i den aktuella katalogen i webbl\u00e4saren eller, en b\u00e4ttre och s\u00e4krare inst\u00e4llning skulle vara att inaktivera detta och visa 403 beh\u00f6righeter f\u00f6rbjudet fel.<\/p>\n<p>Med wordpress-mappar, speciellt plugin-mapparna d\u00e4r webbadresserna inte \u00e4r t\u00e4nkta att bes\u00f6kas direkt i webbl\u00e4saren, s\u00e5 hittar du massor av index.php som inneh\u00e5ller n\u00e5got s\u00e5nt h\u00e4r:<\/p>\n<pre><code>&lt;?php \/\/You don't belong here. ?&gt;<\/code><\/pre>\n<p>Eller i annat liknande format:<\/p>\n<pre><code>&lt;?php\n\/\/ Silence is golden.\n?&gt;<\/code><\/pre>\n<p>Naturligtvis finns det m\u00e5nga andra m\u00f6jliga inneh\u00e5ll som alla tyst inaktiverar mappsurfandet. Om filerna \u00e4r listade kommer eventuellt vissa filer som inneh\u00e5ller k\u00e4nslig information att exponeras.<\/p>\n<p>Ett b\u00e4ttre s\u00e4tt, enligt min mening, \u00e4r att ha en <strong>index.php<\/strong> som har f\u00f6ljande:<\/p>\n<pre><code>&lt;?php\n\u00a0 header($_SERVER['SERVER_PROTOCOL']. ' 404 Not Found');\n\u00a0 exit(\"&lt;!DOCTYPE HTML PUBLIC \"-\/\/IETF\/\/DTD HTML 2.0\/\/EN\"&gt;rn&lt;html&gt;&lt;head&gt;&gt;rn&lt;title&gt;404 Not Found&lt;\/title&gt;rn&lt;\/head&gt;&lt;body&gt;rn\n&lt;h1&gt;Not Found&lt;\/h1&gt;rn&lt;p&gt;The requested URL \". $_SERVER['SCRIPT_NAME']. \" was not found on this server.&lt;\/p&gt;rn&amp;lgt;\/body&gt;&lt;\/html&gt;\");\n?&gt;<\/code><\/pre>\n<p>P\u00e5 s\u00e5 s\u00e4tt kommer det att visa ett 404-fel som inte hittats, vilket ser ut som ett riktigt fel, vilket vilseleder potentiella hackare.<\/p>\n<p>I vissa inkluderade filer, som inte \u00e4r t\u00e4nkta att n\u00e5s direkt, kan du hitta n\u00e5gra kontroller i b\u00f6rjan:<\/p>\n<pre><code>if (!defined('IN_PHPBB'))\n\u00a0 \u00a0 exit;\n\u00a0\n\/\/ don't load directly\nif (!defined('ABSPATH')) \u00a0 \u00a0 die('-1');<\/code><\/pre>\n<p>P\u00e5 s\u00e5 s\u00e4tt undviker man eventuellt l\u00e4ckage av k\u00e4nslig information om det finns skriptfel som visas i webbl\u00e4saren. F\u00f6r mappar som inte ska exponeras helt kan du l\u00e4gga till f\u00f6ljande rader i filen <strong>.htaccess<\/strong><\/p>\n<pre><code>order allow,deny \ndeny from all <\/code><\/pre>\n<p>P\u00e5 s\u00e5 s\u00e4tt kommer inga filer att n\u00e5s i offentlig URL. Till exempel \u00e4r logg- och s\u00e4kerhetskopieringsmapparna f\u00f6r <a href=\"https:\/\/helloacm.com\/how-to-login-to-wordpress-when-away-mode-is-enabled-by-ithemes-security-plugin\/\" target=\"_blank\" rel=\"noopener nofollow\" class=\"external external_icon\">Plugin itheme-s\u00e4kerhet<\/a> inst\u00e4llda p\u00e5 detta.<\/p>\n<p><div id=\"PostUnique_PostSource\" style=\"padding-top: 50px\">Inspelningsk\u00e4lla:  <a target=\"_blank\" rel=\"noopener nofollow\" href=\"\/\/helloacm.com\" class=\"external external_icon\">helloacm.com<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Tystnad \u00e4r guld] Regel i webbserverkataloger<\/p>\n","protected":false},"author":1,"featured_media":224083,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wp_rev_ctl_limit":""},"categories":[838,848,901,922,1034,724],"tags":[1173],"class_list":["post-232139","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guide-foer-nyboerjare","category-handledningar","category-koda","category-oevrig","category-sakerhet","category-utvecklaren","tag-affiai-sv"],"_links":{"self":[{"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/posts\/232139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/comments?post=232139"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/posts\/232139\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/media\/224083"}],"wp:attachment":[{"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/media?parent=232139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/categories?post=232139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.mediadoma.com\/sv\/wp-json\/wp\/v2\/tags?post=232139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}