WordPress网站多次遭感染,权限设置方案是否合理?
一、移除index.php写入权限是否正确?
这个操作完全正确。index.php是WordPress的核心入口执行文件,正常运行仅需只读权限(通常为644)即可,赋予写入权限反而会给恶意脚本留下篡改入口,移除写入权限能有效降低该文件被恶意修改的风险。
二、你的权限配置脚本有效性分析及优化建议
脚本基础有效性
你的脚本整体遵循了WordPress权限配置的核心原则:
- 文件默认设为
644(所有者读写,组和其他只读) - 目录默认设为
755(所有者读写执行,组和其他读执行) - 对核心目录(
wp-admin、wp-includes)和资源目录(themes、plugins)做了针对性处理
这些设置能大幅降低未授权写入的风险,是提升网站安全性的有效基础措施。
关键优化建议
修复
wp-config.php权限漏洞
你的脚本未单独处理wp-config.php,该文件包含数据库账号、密钥等敏感信息,必须设置为**600权限**(仅所有者可读写,其他用户无任何权限),避免敏感数据泄露。建议在脚本中添加:chmod 600 "$wordpress_root/wp-config.php"优化
find命令执行效率
原脚本多次重复遍历目录(比如wp-content目录先整体处理,再单独处理themes、plugins),既浪费资源又可能因执行顺序导致权限覆盖。可以调整执行顺序,先处理特殊权限目录,再处理父目录,或通过-path参数排除已处理目录:# 先处理themes的特殊权限(如果需要主题编辑器) find "$wp_themes" -type f -exec chmod 664 {} \; find "$wp_themes" -type d -exec chmod 775 {} \; # 处理wp-content时排除themes目录 find "$wp_content" -path "$wp_themes" -prune -o -type f -exec chmod 644 {} \; find "$wp_content" -path "$wp_themes" -prune -o -type d -exec chmod 755 {} \;补充
uploads目录权限配置wp-content/uploads是文件上传目录,需要Web服务器有写入权限,但也要兼顾安全。建议单独添加:wp_uploads="$wp_content/uploads" find "$wp_uploads" -type f -exec chmod 644 {} \; find "$wp_uploads" -type d -exec chmod 755 {} \; # 确保所有者为Web服务器用户(比如www-data,根据你的服务器调整) chown -R www-data:www-data "$wp_uploads"明确文件所有者配置
权限数字只是一部分,必须确保WordPress文件的所有者是Web服务器运行用户(如www-data、apache等),避免因权限归属错误导致的功能异常或安全风险。建议在脚本开头添加:# 替换为你的Web服务器用户和组 chown -R www-data:www-data "$wordpress_root"关闭主题编辑器时收紧主题权限
如果你不使用WordPress内置的主题编辑器,应删除脚本中find "$wp_themes" -type f -exec chmod 664 {} \;和find "$wp_themes" -type d -exec chmod 775 {} \;这两行,将主题目录权限统一设为644(文件)和755(目录),进一步降低写入风险。调整
.htaccess权限的灵活性
若你需要WordPress自动更新固定链接规则,.htaccess需要临时具备写入权限,但日常应保持644。可以在脚本中保留chmod 644 "$wordpress_root/.htaccess",仅在需要修改固定链接时临时调整权限。
优化后的完整脚本示例
#!/bin/bash # Define variables for directories wordpress_root="/var/www/mysite.com.br/htdocs" wp_content="$wordpress_root/wp-content" wp_themes="$wp_content/themes" wp_plugins="$wp_content/plugins" wp_uploads="$wp_content/uploads" web_user="www-data" web_group="www-data" # Set correct owner and group first chown -R $web_user:$web_group "$wordpress_root" # Lock down wp-config.php (critical!) chmod 600 "$wordpress_root/wp-config.php" # Set permissions for core directories (wp-admin, wp-includes) find "$wordpress_root/wp-admin" -type f -exec chmod 644 {} \; find "$wordpress_root/wp-admin" -type d -exec chmod 755 {} \; find "$wordpress_root/wp-includes" -type f -exec chmod 644 {} \; find "$wordpress_root/wp-includes" -type d -exec chmod 755 {} \; # Handle themes directory (only if using built-in theme editor) # Remove these lines if you don't use the theme editor find "$wp_themes" -type f -exec chmod 664 {} \; find "$wp_themes" -type d -exec chmod 775 {} \; # Handle plugins directory find "$wp_plugins" -type f -exec chmod 644 {} \; find "$wp_plugins" -type d -exec chmod 755 {} \; # Handle uploads directory find "$wp_uploads" -type f -exec chmod 644 {} \; find "$wp_uploads" -type d -exec chmod 755 {} \; # Handle remaining wp-content files/dirs (exclude themes) find "$wp_content" -path "$wp_themes" -prune -o -type f -exec chmod 644 {} \; find "$wp_content" -path "$wp_themes" -prune -o -type d -exec chmod 755 {} \; # Handle root directory files/dirs (exclude wp-content, wp-admin, wp-includes) find "$wordpress_root" -path "$wp_content" -prune -o -path "$wordpress_root/wp-admin" -prune -o -path "$wordpress_root/wp-includes" -prune -o -type f -exec chmod 644 {} \; find "$wordpress_root" -path "$wp_content" -prune -o -path "$wordpress_root/wp-admin" -prune -o -path "$wordpress_root/wp-includes" -prune -o -type d -exec chmod 755 {} \; # Set .htaccess permissions chmod 644 "$wordpress_root/.htaccess" echo "Permissions applied successfully!"
内容的提问来源于stack exchange,提问作者Daniel Oliveira da Paixao

