Home CMS Tutorial DEDECMS DEDECMS security settings

DEDECMS security settings

Jan 07, 2020 am 09:05 AM
dedecms

DEDECMS security settings

DEDECMS security settings

Many friends who have installed DEDECMS are very concerned about the security of DEDECMS. Trouble, we often encounter things such as horse hanging, hidden links, etc. DreamWeaver Cat has also encountered it. Through Baidu search, we have summarized some methods to improve the security of DreamWeaver. The following settings can significantly improve the security of DreamWeaver. .

Recommended learning: DreamWeaver cms

Recommended to install DreamWeaver Security Assistant

As long as you complete the basic settings, congratulations, your Weaver Dream Security has passed the test. On the contrary, if you do not follow the basics, your website will be in danger.

1 Delete unnecessary directories

After installing Dreamweaver, you need to delete the install directory immediately. If you do not need to use members or topics (99% of users will not use them), you can directly Delete the member and special directories.

2 Delete unnecessary files

plus files It is recommended to keep only the following files: ad_js.php, count.php, list.php, search.php, view.php, and delete the rest.

The functions of the files in the plus folder are as follows. If they are not used, they can be deleted.

File name File description Suggestion

guestbook folder

Message board

Delete

img folder

Picture

Delete

task folder

Scheduled task

Delete

ad_js.php

Call the advertisement. If your advertisement is not set through the background "Advertising Management", you can delete the file and keep

advancedsearch.php, heightsearch.php

Advanced search, generally only use search. php delete

arcmulti.php

Call the specified tag list asynchronously. If you don’t need it, delete it. Delete

bookfeedback.php, bookfeedback_js.php

Book reviews and comment calling files have injection vulnerabilities and are unsafe

Delete

car.php, posttocar.php, carbuyaction.php

Shopping cart Delete

comments_frame.php

There is a security vulnerability when calling comments (now generally third-party comments are used instead of Dreamweaver’s own comments)

Delete

count.php

Statistics on the number of times an article has been read. Keep

digg_ajax.php, digg_frame.php

the upvote function of articles. Delete

disdls.php, download .php

Download count statistics, download function Delete

diy.php

Custom form Keep

erraddsave.php

article Correction Delete

feedback.php, feedback_ajax.php, feedback_js.php

comment related functions Delete

flink.php, flink_add.php

friendship Add links and friendly links (it is recommended to delete, otherwise the template path will be easily exposed) Delete

freelist.php

free list Delete

guestbook.php

leave a message Delete

list.php

Dynamic browsing column page Keep

mytag_js.php

Custom tag js calling method (if the background automatic Define macro tags, please delete)

Delete

qrcode.php

Generate QR code Delete

recommend.php

Information Recommended

Delete

rss.php

RSS list page

Delete

search.php

Search Keep

showphoto.php

Show large pictures (used in the atlas model)

Delete

stow.php

Collect articles Delete

view.php

Dynamic browsing articles Keep

vote.php

vote Delete

3 Modify the default background Folder name

The default background is accessed through the domain name /dede. Please change it to another name. The less likely it is to be guessed, the better. You can use English numbers and other forms. The modification method is to directly rename the name of the dede folder.

4 Create a new administrator account in the background and delete the default admin user

4.1 Create a new administrator account

Click System->System User Management->Add Management Member, fill in the login account and password and other information, select 'Super Administrator' for the user group

4.2 Delete the default admin user

Click System->SQL Command Line Tool and run the SQL command: delete from dede_admin where id = 1;

5 Migrate the data directory outside the web directory

The data directory has serious security risks, so it is necessary to move the data directory outside the site directory. For the specific migration method, you can check this article: http://www.dedemao.com/study/78.html

For students who really do not have the conditions to migrate outside the site, please be sure to change the name of the data directory. .

The above is the detailed content of DEDECMS security settings. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Roblox: Bubble Gum Simulator Infinity - How To Get And Use Royal Keys
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Nordhold: Fusion System, Explained
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Mandragora: Whispers Of The Witch Tree - How To Unlock The Grappling Hook
3 weeks ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Hot Topics

Java Tutorial
1672
14
PHP Tutorial
1277
29
C# Tutorial
1256
24
Where is the imperial cms resource network template? Where is the imperial cms resource network template? Apr 17, 2024 am 10:00 AM

Empire CMS template download location: Official template download: https://www.phome.net/template/ Third-party template website: https://www.dedecms.com/diy/https://www.0978.com.cn /https://www.jiaocheng.com/Installation method: Download template Unzip template Upload template Select template

How to upload local videos to dedecms How to upload local videos to dedecms Apr 16, 2024 pm 12:39 PM

How to upload local videos using Dedecms? Prepare the video file in a format that is supported by Dedecms. Log in to the Dedecms management backend and create a new video category. Upload video files on the video management page, fill in the relevant information and select the video category. To embed a video while editing an article, enter the file name of the uploaded video and adjust its dimensions.

How dedecms implements template replacement How dedecms implements template replacement Apr 16, 2024 pm 12:12 PM

Template replacement can be implemented in Dedecms through the following steps: modify the global.cfg file and set the required language pack. Modify the taglib.inc.php hook file and add support for language suffix template files. Create a new template file with a language suffix and modify the required content. Clear Dedecms cache.

What website can dedecms do? What website can dedecms do? Apr 16, 2024 pm 12:24 PM

Dedecms is an open source CMS that can be used to create various types of websites, including: news websites, blogs, e-commerce websites, forums and community websites, educational websites, portals, other types of websites (such as corporate websites, personal websites, photo album websites, video sharing website)

What loopholes does dedecms have? What loopholes does dedecms have? Aug 03, 2023 pm 03:56 PM

DedeCMS is an open source content management system that has some potential vulnerabilities and security risks: 1. SQL injection vulnerability. Attackers can perform unauthorized operations or obtain sensitive data by constructing malicious SQL query statements; 2. File Upload vulnerability, attackers can upload files containing malicious code to the server to execute arbitrary code or obtain server permissions; 3. Sensitive information leakage; 4. Unauthenticated vulnerability exploitation.

How to use dedecms How to use dedecms Apr 16, 2024 pm 12:15 PM

Dedecms is an open source Chinese CMS system that provides content management, template system and security protection. The specific usage includes the following steps: 1. Install Dedecms. 2. Configure the database. 3. Log in to the management interface. 4. Create content. 5. Set up the template. 6. Manage users. 7. Maintain the system.

How to change pictures in dedecms How to change pictures in dedecms Apr 16, 2024 pm 12:27 PM

Steps to modify images in DedeCMS: Log in to the DedeCMS backend. Visit the System > Media Management page. Select the image you want to edit. Click the "Edit" button. Modify image titles, descriptions, tags, and copyright information. Crop or resize picture. Click the "Save" button to save changes. Return to the media management page and click the "Update Image Library" button to apply the changes to the site.

How does dedecms implement template replacement? How does dedecms implement template replacement? Apr 16, 2024 pm 12:21 PM

To implement template replacement in DedecMS, you need to perform the following steps: Determine the template file to be replaced. Common files include index.htm, list.htm and show.htm. Create a new template file, retaining the DedecMS markup. Upload the new template file, overwriting the original file. clear cache. Refresh the site to see the changes.

See all articles