search
HomeCMS TutorialDEDECMSDEDECMS security settings
DEDECMS security settingsJan 07, 2020 am 09:05 AM
dedecms

DEDECMS security settings

DEDECMS security settings

Many friends who have installed DEDECMS are very concerned about the security of DEDECMS. Trouble, we often encounter things such as horse hanging, hidden links, etc. DreamWeaver Cat has also encountered it. Through Baidu search, we have summarized some methods to improve the security of DreamWeaver. The following settings can significantly improve the security of DreamWeaver. .

Recommended learning: DreamWeaver cms

Recommended to install DreamWeaver Security Assistant

As long as you complete the basic settings, congratulations, your Weaver Dream Security has passed the test. On the contrary, if you do not follow the basics, your website will be in danger.

1 Delete unnecessary directories

After installing Dreamweaver, you need to delete the install directory immediately. If you do not need to use members or topics (99% of users will not use them), you can directly Delete the member and special directories.

2 Delete unnecessary files

plus files It is recommended to keep only the following files: ad_js.php, count.php, list.php, search.php, view.php, and delete the rest.

The functions of the files in the plus folder are as follows. If they are not used, they can be deleted.

File name File description Suggestion

guestbook folder

Message board

Delete

img folder

Picture

Delete

task folder

Scheduled task

Delete

ad_js.php

Call the advertisement. If your advertisement is not set through the background "Advertising Management", you can delete the file and keep

advancedsearch.php, heightsearch.php

Advanced search, generally only use search. php delete

arcmulti.php

Call the specified tag list asynchronously. If you don’t need it, delete it. Delete

bookfeedback.php, bookfeedback_js.php

Book reviews and comment calling files have injection vulnerabilities and are unsafe

Delete

car.php, posttocar.php, carbuyaction.php

Shopping cart Delete

comments_frame.php

There is a security vulnerability when calling comments (now generally third-party comments are used instead of Dreamweaver’s own comments)

Delete

count.php

Statistics on the number of times an article has been read. Keep

digg_ajax.php, digg_frame.php

the upvote function of articles. Delete

disdls.php, download .php

Download count statistics, download function Delete

diy.php

Custom form Keep

erraddsave.php

article Correction Delete

feedback.php, feedback_ajax.php, feedback_js.php

comment related functions Delete

flink.php, flink_add.php

friendship Add links and friendly links (it is recommended to delete, otherwise the template path will be easily exposed) Delete

freelist.php

free list Delete

guestbook.php

leave a message Delete

list.php

Dynamic browsing column page Keep

mytag_js.php

Custom tag js calling method (if the background automatic Define macro tags, please delete)

Delete

qrcode.php

Generate QR code Delete

recommend.php

Information Recommended

Delete

rss.php

RSS list page

Delete

search.php

Search Keep

showphoto.php

Show large pictures (used in the atlas model)

Delete

stow.php

Collect articles Delete

view.php

Dynamic browsing articles Keep

vote.php

vote Delete

3 Modify the default background Folder name

The default background is accessed through the domain name /dede. Please change it to another name. The less likely it is to be guessed, the better. You can use English numbers and other forms. The modification method is to directly rename the name of the dede folder.

4 Create a new administrator account in the background and delete the default admin user

4.1 Create a new administrator account

Click System->System User Management->Add Management Member, fill in the login account and password and other information, select 'Super Administrator' for the user group

4.2 Delete the default admin user

Click System->SQL Command Line Tool and run the SQL command: delete from dede_admin where id = 1;

5 Migrate the data directory outside the web directory

The data directory has serious security risks, so it is necessary to move the data directory outside the site directory. For the specific migration method, you can check this article: http://www.dedemao.com/study/78.html

For students who really do not have the conditions to migrate outside the site, please be sure to change the name of the data directory. .

The above is the detailed content of DEDECMS security settings. For more information, please follow other related articles on the PHP Chinese website!

Statement
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn
dedecms怎么增加多语言dedecms怎么增加多语言Feb 27, 2023 am 09:21 AM

dedecms增加多语言的方法:1、进入dedecms后台,创建封面栏目;2、将封面栏目“常规选项”的文件保存目录设置为cn或者en;3、将封面栏目“高级选项”的列表模板设置为“cn_index.htm”或者“en_index.htm”;4、单独调用每种语言的封面栏目和每种语言下的导航栏目即可。

织梦cms是什么语言写的织梦cms是什么语言写的Feb 21, 2023 am 09:45 AM

织梦cms是用PHP语言写的。织梦CMS(DedeCMS)是一个PHP开源网站管理系统,作用是构建中小型网站;它采用PHP+MySQL技术开发,可同时使用于windows、linux、unix平台。

dedecms是什么语言dedecms是什么语言Feb 24, 2023 am 09:46 AM

dedecms是PHP语言开发的;dedecms中文全称是织梦内容管理系统,是一个PHP开源网站管理系统;dedecms基于PHP和MySQL技术开发,可同时使用于Windows、Linux、Unix平台。

dedecms怎么删除栏目dedecms怎么删除栏目Jul 13, 2023 pm 04:31 PM

dedecms删除栏目的方法:1、登录后台管理;2、进入“栏目管理”,可以看到当前网站所有栏目;3、选择要删除的栏目;4、将鼠标悬停在栏目名称上,删除栏目;5、点击“确认”按钮以继续删除操作;6、删除成功。

2023年织梦dedeCMS视频教程推荐2023年织梦dedeCMS视频教程推荐Oct 25, 2019 pm 01:56 PM

织梦内容管理系统(DedeCMS) 以简单、实用、开源而闻名,是国内最知名的PHP开源网站管理系统,也是使用用户最多的PHP类CMS系统,在经历多年的发展,目前的版本无论在功能,还是在易用性方面,都有了长足的发展和进步。

火车头dedecms出现乱码怎么办火车头dedecms出现乱码怎么办Jul 19, 2023 pm 02:19 PM

火车头dedecms出现乱码解决方法:1、检查数据库编码;2、修改dedecms配置文件;3、检查浏览器编码设置;4、清理缓存和临时文件;5、寻求专业帮助。

dedecms是干什么的dedecms是干什么的Feb 22, 2023 am 09:14 AM

dedecms是指织梦内容管理系统,是一个PHP开源网站管理系统,用于个人网站或中小型门户的构建;dedecms是基于PHP和MySQL技术开发,可同时使用于Windows、Linux、Unix平台。

dedecms无法修改怎么解决dedecms无法修改怎么解决Jun 25, 2023 pm 04:53 PM

dedecms无法修改的解决方法是:1、检查文件夹和文件的读写权限是否正确;2、使用最新版本的DedeCMS,并保持数据库、插件和主题等组件的版本与CMS核心匹配;3、添加了不兼容的插件或主题,导致DedeCMS无法正常工作;4、检查PHP日志和调试信息以找出问题并解决。

See all articles

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
2 weeks agoBy尊渡假赌尊渡假赌尊渡假赌
Repo: How To Revive Teammates
4 weeks agoBy尊渡假赌尊渡假赌尊渡假赌
Hello Kitty Island Adventure: How To Get Giant Seeds
3 weeks agoBy尊渡假赌尊渡假赌尊渡假赌

Hot Tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

SublimeText3 Linux new version

SublimeText3 Linux new version

SublimeText3 Linux latest version

SecLists

SecLists

SecLists is the ultimate security tester's companion. It is a collection of various types of lists that are frequently used during security assessments, all in one place. SecLists helps make security testing more efficient and productive by conveniently providing all the lists a security tester might need. List types include usernames, passwords, URLs, fuzzing payloads, sensitive data patterns, web shells, and more. The tester can simply pull this repository onto a new test machine and he will have access to every type of list he needs.

WebStorm Mac version

WebStorm Mac version

Useful JavaScript development tools

SublimeText3 English version

SublimeText3 English version

Recommended: Win version, supports code prompts!