2013-01-31 34 views
1

我的目標是在訪問wp-includes目錄中的任何內容時將用戶重定向到自定義404頁面。我試圖隱藏任何證據表明我正在運行WordPress並阻止任何黑客。從wp-includes重定向到404錯誤頁面

我不希望Apache默認設置的默認Forbidden消息,而是使用WordPress 404.php模板之一。

我已經嘗試了HTACCESS文件方法,但它會影響任何css,jpg和js文件。你能幫忙的話,我會很高興。

回答

1

你應該給wordpress docs一個閱讀。他們有整個頁面Hardening Wordpress。請參閱部分上保護WP-包括:

http://codex.wordpress.org/Hardening_WordPress#Securing_wp-includes

# Block the include-only files. 
RewriteEngine On 
RewriteBase/
RewriteRule ^wp-admin/includes/ - [F,L] 
RewriteRule !^wp-includes/ - [S=3] 
RewriteRule ^wp-includes/[^/]+\.php$ - [F,L] 
RewriteRule ^wp-includes/js/tinymce/langs/.+\.php - [F,L] 
RewriteRule ^wp-includes/theme-compat/ - [F,L] 

# BEGIN WordPress