Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #https://premium.wpmudev.org/blog/htaccess/
- 1.- En .htaccess de la raiz del sitio
- #Evitar el listado de directorios
- #Options All -Indexes
- #Evitar llamadas a wp-includes
- #wp-includes NO debe recibir llamaras directas, es el CORE del Framework
- RewriteEngine On
- RewriteBase /
- RewriteRule ^wp-admin/includes/ - [F,L]
- RewriteRule !^wp-includes/ - [S=3]
- RewriteRule ^wp-includes/[^/]+\.php$ - [F,L]
- RewriteRule ^wp-includes/js/tinymce/langs/.+\.php - [F,L]
- RewriteRule ^wp-includes/theme-compat/ - [F,L]
- #Evitar llamadas a URL php en pluggins
- #RewriteCond %{REQUEST_URI} !^/wp-content/plugins/file/to/exclude\.php
- #RewriteCond %{REQUEST_URI} !^/wp-content/plugins/directory/to/exclude/
- RewriteRule wp-content/plugins/(.*\.php)$ - [R=404,L]
- #Evitar llamadas a URL php en themes
- #RewriteCond %{REQUEST_URI} !^/wp-content/themes/file/to/exclude\.php
- #RewriteCond %{REQUEST_URI} !^/wp-content/themes/directory/to/exclude/
- RewriteRule wp-content/themes/(.*\.php)$ - [R=404,L]
- #Prevenir scan de usuarios del sistema
- RewriteCond %{QUERY_STRING} author=d
- RewriteRule ^ /? [L,R=301]
- #Proteger los archivos .htaccess de llamadas
- # Deny access to all .htaccess files
- <files ~ "^.*\.([Hh][Tt][Aa])">
- order allow,deny
- deny from all
- satisfy all
- </files>
- #Proteger llamadas a wp-config
- <files wp-config.php>
- order allow,deny
- deny from all
- </files>
- #Habilitar el cache del browser del cliente
- <IfModule mod_expires.c>
- ExpiresActive On
- ExpiresByType image/jpg "access 1 year"
- ExpiresByType image/jpeg "access 1 year"
- ExpiresByType image/gif "access 1 year"
- ExpiresByType image/png "access 1 year"
- ExpiresByType text/css "access 1 month"
- ExpiresByType application/pdf "access 1 month"
- ExpiresByType text/x-javascript "access 1 month"
- ExpiresByType application/x-shockwave-flash "access 1 month"
- ExpiresByType image/x-icon "access 1 year"
- ExpiresDefault "access 2 days"
- </IfModule>
- #DESDE AQUI AGREGAR LO QUE TRAE EL ORIGINAL DE WORDPRESS
- 2.- en carpeta wp-content, crear .htaccess (incluye uploads)
- # Permitir el llamado solo a archivos seguros
- Order deny,allow
- Deny from all
- <Files ~ ".(xml|css|js|jpe?g|png|gif|pdf|docx|rtf|odf|zip|rar)$">
- Allow from all
- </Files>
Advertisement
Add Comment
Please, Sign In to add comment