Lockdown of Dynamic Files

Home Forums BulletProof Security Pro Lockdown of Dynamic Files

Viewing 2 posts - 1 through 2 (of 2 total)
  • Author
    Posts
  • #7711
    Jonathan
    Participant

    Hello again. I have one nagging question before I install BPS Pro on a live site. When the WordPress filesystem is locked down and being checked by the cron feature, how can a non-sophisticated user add or delete plugins and update his media library. I need to be able to explain this to my client. If this has already been documented, please point me to the pertinent information. Thanks for your help.

    #7712
    AITpro Admin
    Keymaster

    The Media library (WordPress uploads folder) is not monitored by AutoRestore/Quarantine and is protected by the Uploads Anti-Exploit Guard instead.  This means file uploading happens as it normally should without anything else required on the users part.

    The plugins folder is protected by the Plugin Firewall and if you use the BPS Pro Setup Wizard then a plugins folder exclude rule is automatically created in AutoRestore when running the Setup Wizard.  AutoRestore/Quarantine will not monitor the plugins folder so this means that installing or upgrading plugins happens as it normally should without anything else required on the users part.

    Please read the AutoRestore/Quarantine Guide in the link below for an explanation of when you would need to do the standard ARQ procedures for turning off ARQ when modifying files on the site.  Basically when you perform WordPress upgrades, Theme installations or when you are modifying individual website files would be the only time you would need to do the ARQ procedural steps.

    http://forum.ait-pro.com/forums/topic/autorestore-quarantine-guide-read-me-first/

    And just in case the user asks about this.  Posts and Pages in WordPress are stored in the WordPress Database.  AutoRestore/Quarantine does not look at the WordPress Database content and only monitors website files.  In other words, creating content on the site happens as it normally should without anything else required on the users part.

Viewing 2 posts - 1 through 2 (of 2 total)
  • You must be logged in to reply to this topic.