• You MUST read the Babiato Rules before making your first post otherwise you may get permanent warning points or a permanent Ban.

    Our resources on Babiato Forum are CLEAN and SAFE. So you can use them for development and testing purposes. If your are on Windows and have an antivirus that alerts you about a possible infection: Know it's a false positive because all scripts are double checked by our experts. We advise you to add Babiato to trusted sites/sources or disable your antivirus momentarily while downloading a resource. "Enjoy your presence on Babiato"

Babiato Resources getting hacked or malicious codes? Do THESE NOW!

Hi @Escanor64, thank you for pointing us in the right direction.
If it's not too much trouble, would you kindly share the links to the plugins you found?

Many Thanx
Yeah, will do. I actually realized that some of the plugins are not exactly ideal as they block some important parts of your website's functionality. I should create another thread with a proper walkthrough today.
 
All Security plugins are USELESSSSS, depending on who is targeting you.. Yea that's right!
Learn how to use Cloudflare to protect your website and sleep with your 2 eyes closed 😴
All of my site's are routed through Cloudflare. I still didn't prevent them from getting hacked.
 
  • Like
Reactions: Escanor64
All Security plugins are USELESSSSS, depending on who is targeting you.. Yea that's right!
Learn how to use Cloudflare to protect your website and sleep with your 2 eyes closed 😴
Not properly so, what about HTTP Request Smuggling attacks? :) Plugins are useful, a good web server configuration following proper hardening best practices even more (i.e. IPTabes Rules, Strict CSP, etc.), especially while using HTTP/3 QUIC. ;)
 
Last edited:
  • Like
Reactions: amit338
What the purpose of xmlrc file? Can you please share how did you delete that file?
I use apache include file to block at server level, so xmlrpc will be blocked in all sites.


Code:
<Files xmlrpc.php>
Order allow,deny
Allow from 192.0.64.1/192.0.127.254
Deny from all
Satisfy All
ErrorDocument 403 http://127.0.0.1/
</Files>

The allowed IP addresses are related to Jetpack plugin.
 
Actually I have installed wordfence and until now I didnt face any issue .
 
All of my site's are routed through Cloudflare. I still didn't prevent them from getting hacked.

And if you need the perfect scanner to check the security of your website, use Sudomy: https://github.com/screetsec/Sudomy - it uses many services like the following:

Code:
https://censys.io
https://developer.shodan.io
https://dns.bufferover.run
https://index.commoncrawl.org
https://riddler.io
https://api.certspotter.com
https://api.hackertarget.com
https://api.threatminer.org
https://community.riskiq.com
https://crt.sh
https://dnsdumpster.com
https://docs.binaryedge.io
https://securitytrails.com
https://graph.facebook.com
https://otx.alienvault.com
https://rapiddns.io
https://spyse.com
https://urlscan.io
https://www.dnsdb.info
https://www.virustotal.com
https://threatcrowd.org
https://web.archive.org

It works directly from your CLI, it provides you with a list of Matches found after each scan in order to patch them, it's open-source and well documented!

Additionally, if you use WordPress, you can check for vulnerabilities to patch using one of this tools:
  • WPScan (CLI Tool)
  • WPSec (SaaS with Free Tier for your own website)
Enjoy :D
 
Last edited:
  • Like
Reactions: amit338

Forum statistics

Threads
79,603
Messages
1,146,080
Members
250,561
Latest member
maur39
AdBlock Detected

We get it, advertisements are annoying!

However in order to keep our huge array of resources free of charge we need to generate income from ads so to use the site you will need to turn off your adblocker.

If you'd like to have an ad free experience you can become a Babiato Lover by donating as little as $5 per month. Click on the Donate menu tab for more info.

I've Disabled AdBlock