Quantcast
Channel: BulletProof Security Forum » All Posts
Viewing all articles
Browse latest Browse all 12461

Reply To: Random General Questions

$
0
0

Ok haha, well thank you for confirming the other approach (“just let files be quarantined and restore them from quarantine when that happens”) as this seems somewhat more secure (i.e. we never are in a position where the ARQ is completely turned off), so we are happy to use that approach.

Perhaps we could look at another example which feels quite crucial to us at this moment. Our website was hacked earlier this month and so we’re wanting to be very thorough with our understanding of the functionality of BPS Pro in order to make sure we’re using it correctly so that we’re maximizing its potential.

We just uploaded a test folder (with 2 files in it) into the wp-content/ directory while leaving the ARQ Cron turned ON. We expected that the folder would get quarantined. However, nothing happened and the folder was fully accepted by the site. This concerns us because obviously if a hacker happened to gain FTP access to our site, they could easily upload a folder without us knowing about it.

We also tried uploading a different folder into the root directory as well as uploading an individual file into the wp-content/ directory. None of these tests triggered the Quarantine. Just to be sure everything was still on, we repeated our test of adding an individual file into the root directory, and that did trigger the Quarantine.

Ideally, we want everything on our site to be protected by ARQ. Do these tests make sense to you and what would you recommend as the easiest way that we make sure everything is fully protected?


Viewing all articles
Browse latest Browse all 12461

Trending Articles