You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WordPress网站多次遭感染,权限设置方案是否合理?

WordPress权限配置与安全优化答疑

一、移除index.php写入权限是否正确?

这个操作完全正确。index.php是WordPress的核心入口执行文件,正常运行仅需只读权限(通常为644)即可,赋予写入权限反而会给恶意脚本留下篡改入口,移除写入权限能有效降低该文件被恶意修改的风险。

二、你的权限配置脚本有效性分析及优化建议

脚本基础有效性

你的脚本整体遵循了WordPress权限配置的核心原则:

  • 文件默认设为644(所有者读写,组和其他只读)
  • 目录默认设为755(所有者读写执行,组和其他读执行)
  • 对核心目录(wp-admin、wp-includes)和资源目录(themes、plugins)做了针对性处理
    这些设置能大幅降低未授权写入的风险,是提升网站安全性的有效基础措施。

关键优化建议

  1. 修复wp-config.php权限漏洞
    你的脚本未单独处理wp-config.php,该文件包含数据库账号、密钥等敏感信息,必须设置为**600权限**(仅所有者可读写,其他用户无任何权限),避免敏感数据泄露。建议在脚本中添加:

    chmod 600 "$wordpress_root/wp-config.php"
    
  2. 优化find命令执行效率
    原脚本多次重复遍历目录(比如wp-content目录先整体处理,再单独处理themes、plugins),既浪费资源又可能因执行顺序导致权限覆盖。可以调整执行顺序,先处理特殊权限目录,再处理父目录,或通过-path参数排除已处理目录:

    # 先处理themes的特殊权限(如果需要主题编辑器)
    find "$wp_themes" -type f -exec chmod 664 {} \;
    find "$wp_themes" -type d -exec chmod 775 {} \;
    # 处理wp-content时排除themes目录
    find "$wp_content" -path "$wp_themes" -prune -o -type f -exec chmod 644 {} \;
    find "$wp_content" -path "$wp_themes" -prune -o -type d -exec chmod 755 {} \;
    
  3. 补充uploads目录权限配置
    wp-content/uploads是文件上传目录,需要Web服务器有写入权限,但也要兼顾安全。建议单独添加:

    wp_uploads="$wp_content/uploads"
    find "$wp_uploads" -type f -exec chmod 644 {} \;
    find "$wp_uploads" -type d -exec chmod 755 {} \;
    # 确保所有者为Web服务器用户(比如www-data,根据你的服务器调整)
    chown -R www-data:www-data "$wp_uploads"
    
  4. 明确文件所有者配置
    权限数字只是一部分,必须确保WordPress文件的所有者是Web服务器运行用户(如www-data、apache等),避免因权限归属错误导致的功能异常或安全风险。建议在脚本开头添加:

    # 替换为你的Web服务器用户和组
    chown -R www-data:www-data "$wordpress_root"
    
  5. 关闭主题编辑器时收紧主题权限
    如果你不使用WordPress内置的主题编辑器,应删除脚本中find "$wp_themes" -type f -exec chmod 664 {} \;和find "$wp_themes" -type d -exec chmod 775 {} \;这两行,将主题目录权限统一设为644(文件)和755(目录),进一步降低写入风险。

  6. 调整.htaccess权限的灵活性
    若你需要WordPress自动更新固定链接规则,.htaccess需要临时具备写入权限,但日常应保持644。可以在脚本中保留chmod 644 "$wordpress_root/.htaccess",仅在需要修改固定链接时临时调整权限。

优化后的完整脚本示例

#!/bin/bash

# Define variables for directories
wordpress_root="/var/www/mysite.com.br/htdocs"
wp_content="$wordpress_root/wp-content"
wp_themes="$wp_content/themes"
wp_plugins="$wp_content/plugins"
wp_uploads="$wp_content/uploads"
web_user="www-data"
web_group="www-data"

# Set correct owner and group first
chown -R $web_user:$web_group "$wordpress_root"

# Lock down wp-config.php (critical!)
chmod 600 "$wordpress_root/wp-config.php"

# Set permissions for core directories (wp-admin, wp-includes)
find "$wordpress_root/wp-admin" -type f -exec chmod 644 {} \;
find "$wordpress_root/wp-admin" -type d -exec chmod 755 {} \;

find "$wordpress_root/wp-includes" -type f -exec chmod 644 {} \;
find "$wordpress_root/wp-includes" -type d -exec chmod 755 {} \;

# Handle themes directory (only if using built-in theme editor)
# Remove these lines if you don't use the theme editor
find "$wp_themes" -type f -exec chmod 664 {} \;
find "$wp_themes" -type d -exec chmod 775 {} \;

# Handle plugins directory
find "$wp_plugins" -type f -exec chmod 644 {} \;
find "$wp_plugins" -type d -exec chmod 755 {} \;

# Handle uploads directory
find "$wp_uploads" -type f -exec chmod 644 {} \;
find "$wp_uploads" -type d -exec chmod 755 {} \;

# Handle remaining wp-content files/dirs (exclude themes)
find "$wp_content" -path "$wp_themes" -prune -o -type f -exec chmod 644 {} \;
find "$wp_content" -path "$wp_themes" -prune -o -type d -exec chmod 755 {} \;

# Handle root directory files/dirs (exclude wp-content, wp-admin, wp-includes)
find "$wordpress_root" -path "$wp_content" -prune -o -path "$wordpress_root/wp-admin" -prune -o -path "$wordpress_root/wp-includes" -prune -o -type f -exec chmod 644 {} \;
find "$wordpress_root" -path "$wp_content" -prune -o -path "$wordpress_root/wp-admin" -prune -o -path "$wordpress_root/wp-includes" -prune -o -type d -exec chmod 755 {} \;

# Set .htaccess permissions
chmod 644 "$wordpress_root/.htaccess"

echo "Permissions applied successfully!"

内容的提问来源于stack exchange,提问作者Daniel Oliveira da Paixao

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 05:40:36