任意のWordPressインストールのセキュリティを強化します。
❮ 注意 ❯ このツールは定期的に新バージョンをリリースしています。最新バージョンを入手するために、依存関係を頻繁に更新してください。新機能については、チェンジログまたはCHANGELOG.mdを確認してください。
WPHardeningのインストールには、1つのコンソールコマンドを実行する必要があります。
$ pip install -r requirements.txt
$ python wphardening.py -h
__ _______ _ _ _ _
\ \ / / __ \| | | | | | (_)
\ \ /\ / /| |__) | |__| | __ _ _ __ __| | ___ _ __ _ _ __ __ _
\ \/ \/ / | ___/| __ |/ _` | '__/ _` |/ _ \ '_ \| | '_ \ / _` |
\ /\ / | | | | | | (_| | | | (_| | __/ | | | | | | | (_| |
\/ \/ |_| |_| |_|\__,_|_| \__,_|\___|_| |_|_|_| |_|\__, |
__/ |
Fortify the security of any WordPress installation. |___/
Caceria de Spammers - http://www.caceriadespammers.com.ar
Usage: python wphardening.py [options]
Options:
--version show program's version number and exit
-h, --help show this help message and exit
-v, --verbose Active verbose mode output results
--update Check for WPHardening latest stable version
Target:
This option must be specified to modify the package WordPress.
-d DIRECTORY, --dir=DIRECTORY
**REQUIRED** - Working Directory.
--load-conf=FILE Load file configuration.
Hardening:
Different tools to hardening WordPress.
-c, --chmod Chmod 755 in directory and 644 in files.
-r, --remove Remove files and directory.
-b, --robots Create file robots.txt
-f, --fingerprinting
Deleted fingerprinting WordPress.
-t, --timthumb Find the library TimThumb.
--chown=user:group Changing file and directory owner.
--wp-config Wizard generated wp-config.php
--plugins Download Plugins Security.
--proxy=PROXY Use a HTTP proxy to connect to the target url for
--plugins and --wp-config.
--indexes It deny you to display the contents of directories.
--minify Compressing static file .css and .js
--malware-scan Malware Scan in WordPress project.
--6g-firewall 6G Firewall.
--rest-api Disable REST API.
Miscellaneous:
-o FILE, --output=FILE
Write log report to FILE.log
ツールを使用する前に、作業ディレクトリがWordPressであることを確認してください。
$ python wphardening.py -d /home/path/to/wordpress -v
このオプションは、ファイルとディレクトリに正しいパーミッションを設定します。
$ python wphardening.py -d /home/path/to/wordpress --chmod -v
システムの強化の一環として、不要なファイル、ディレクトリ、コンポーネントを削除します。
$ python wphardening.py -d /home/path/to/wordpress --remove -v
WordPressのデフォルトではrobots.txtファイルが含まれていませんが、このオプションを使用してカスタマイズできます。
$ python wphardening.py -d /home/path/to/wordpress --robots -v
詳細については robots.txt を参照してください。
$ python wphardening.py -d /home/path/to/wordpress --fingerprinting -v
$ python wphardening.py -d /home/path/to/wordpress --timthumb -v
このファイルは、ディレクトリの閲覧を防ぐために作成されます。
$ python wphardening.py -d /home/path/to/wordpress --indexes -v
以下は、自動的にダウンロードできる一般的なセキュリティプラグインのリストです。
$ python wphardening.py -d /home/path/to/wordpress --plugins
このコマンドは、wp-config-wphardening.phpというファイルを自動的に作成します。その後、名前を変更できます。
$ python wphardening.py -d /home/path/to/wordpress --wp-config
$ python wphardening.py -d /home/path/to/wordpress --6g-firewall
$ python wphardening.py -d /home/path/to/wordpress --rest-api
このオプションを使用すると、常に最新バージョンのWPHardeningを利用できます。
$ python wphardening.py --update
$ python wphardening.py -d /home/path/to/wordpress -c -r -f -t --wp-config --indexes --plugins --6g-firewall --rest-api -o /home/user/wphardening.log
https://github.com/elcodigok/wphardening