You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WordPress服务器防范.jpg.php/.php.jpg恶意文件入侵及存储阻止求助

Dealing with .jpg.php File Upload Attempts on WordPress

Hey there, I’ve handled similar malicious file upload attempts on WordPress sites multiple times, so let me walk you through what you need to know:

Have other WordPress users seen .php.jpg files in their root directories?

Absolutely—this is a super common file upload bypass tactic, and tons of WP admins have reported finding files with mixed extensions like .php.jpg, .jpg.php, .phtml.png, etc., in their root, wp-content, or uploads directories. Attackers rely on these confusing names to get around basic file type checks.

How do these files end up on your server?

There are a few common ways attackers can upload these files:

  • Vulnerable plugins/themes/core: Outdated WordPress components (especially those with custom upload forms) often have weak file validation. Attackers can tamper with HTTP request headers or rename files to bypass checks that only look at the file extension’s last part.
  • Automated scanning tools: Bots constantly scan WordPress sites for open upload endpoints (like media libraries, comment avatar uploads, or custom contact form file fields) to push these malicious files en masse.
  • Compromised credentials: If your FTP, cPanel, or WordPress admin account has weak or leaked credentials, attackers can directly upload these files without needing to exploit a vulnerability.
  • Server misconfigurations: In some cases, loose server permissions (like 777 on directories) let attackers upload files via unintended paths.

How to implement global protection against mixed file extensions

Since you’re looking for global safeguards (not just fixing a single upload script), here are the most effective steps:

1. Server-level configuration (most robust)

This is the strongest defense because it blocks execution and uploads at the server level, bypassing any WordPress-level gaps.

  • Apache: Add these rules to your .htaccess file (or server config) to block parsing of mixed PHP extensions:
    # Block execution of files with mixed PHP extensions
    <FilesMatch "\.(php|phtml|php3|php4|php5|php7|phar)$">
        Require all denied
    </FilesMatch>
    # Only allow exact .php files to be parsed (optional but stricter)
    <FilesMatch "^.*\.php$">
        SetHandler application/x-httpd-php
    </FilesMatch>
    
  • Nginx: Update your server block to only parse exact .php files, and deny access to mixed extensions:
    # Only process exact .php files
    location ~ ^.*\.php$ {
        fastcgi_pass unix:/run/php/php8.1-fpm.sock; # Adjust to your PHP-FPM path
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
    }
    # Block access to files with mixed PHP extensions
    location ~* \.(php|phtml)\..*$ {
        deny all;
    }
    
  • ModSecurity: Enable ModSecurity (if your server supports it) and add rules to block requests with filenames containing multiple dots and PHP-related extensions. For example, a rule that flags filenames like *.php.* or *.*.php.

2. WordPress-level hardening

  • Keep WordPress core, themes, and plugins fully updated—outdated code is the #1 entry point for these attacks.
  • Add this line to your wp-config.php to explicitly disable unfiltered uploads (it’s default, but setting it explicitly removes ambiguity):
    define('ALLOW_UNFILTERED_UPLOADS', false);
    
  • Use a WordPress security plugin like Wordfence or iThemes Security—they include built-in modules to scan for and block malicious file uploads with mixed extensions.
  • Disable any unused upload features (e.g., comment avatar uploads, custom form file fields) if you don’t need them.

3. File permission locks

  • Set strict file permissions: WordPress files should be 644 (read/write for owner, read-only for others) and directories 755 (read/write/execute for owner, read/execute for others).
  • Ensure your web server user (e.g., www-data on Apache) doesn’t have write access to your root directory—only allow write access to necessary folders like wp-content/uploads.

4. Regular monitoring

  • Set up automated scans to check for suspicious files. A simple bash script can help:
    # Scan WordPress root for mixed extension files
    find /path/to/your/wordpress/root -type f \( -name "*.*.php" -o -name "*.php.*" \)
    
  • Check your server access logs regularly for repeated upload attempts targeting your site—this can help you spot and block malicious IPs early.

Since you tested and found the files can’t run, that’s a good sign your current setup has some protection, but don’t let your guard down. Attackers are always looking for new ways to bypass safeguards, so implementing these layered defenses will make your site much harder to compromise.

内容的提问来源于stack exchange,提问作者Dyluck

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:27:35