GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Rimu (rimu@mastodon.nzoss.nz)'s status on Wednesday, 08-May-2024 15:52:19 JST Rimu Rimu

    @jalefkowit Yuup.

    Also.

    If you disable a plugin or theme it stops receiving security updates yet the files are still sitting there on your web server and can be executed by doing a request e.g. yoursite.com/wp-content/plugin/disabled-plugin/insecure_code.php

    In conversation about a year ago from mastodon.nzoss.nz permalink

    Attachments


    • Embed this notice
      Rimu (rimu@mastodon.nzoss.nz)'s status on Thursday, 09-May-2024 06:46:14 JST Rimu Rimu
      in reply to
      • Advanced Persistent Teapot
      • Thomas Kräftner

      @http_error_418 @kraftner @jalefkowit That's my method too, plus delete a plugin after disabling it. If I remember...

      In conversation about a year ago permalink
    • Embed this notice
      Thomas Kräftner (kraftner@mastodon.social)'s status on Thursday, 09-May-2024 06:46:15 JST Thomas Kräftner Thomas Kräftner
      in reply to

      @rimu @jalefkowit WP warns you about this. Also if a plugin has any code that runs by directly accessing a PHP file in it that is just a really shitty plugin one should avoid.

      In conversation about a year ago permalink
    • Embed this notice
      Advanced Persistent Teapot (http_error_418@hachyderm.io)'s status on Thursday, 09-May-2024 06:46:15 JST Advanced Persistent Teapot Advanced Persistent Teapot
      in reply to
      • Thomas Kräftner

      @kraftner @rimu @jalefkowit the problem with this is, to someone who's just installing the code by clicking a gui, how do you -know- it's shitty code you should avoid underneath?

      I try to keep myself safe by only using highly reviewed plugins with shit tons of downloads, but I know this is a fairly terrible crutch.

      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.