CloudSecure WP Security
管çç»é¢ã¨ãã°ã¤ã³URLããµã¤ãã¼æ»æããå®ããå®å¿ã®å½ç£ã»æ¥æ¬èªå¯¾å¿ãã©ã°ã¤ã³ã§ãã ãããããªè¨å®ãè¡ãã ãã§ã䏿£ã¢ã¯ã»ã¹ã䏿£ãã°ã¤ã³ããããªãã®WordPressãä¿è·ããã»ãã¥ãªãã£ãåä¸ãã¾ãã ã¾ããåæ©è½ã®æå¹ã»ç¡å¹ï¼ONã»OFFï¼ãè¨å®ãªã©ãã好ã¿ã«ã«ã¹ã¿ãã¤ãºãããã¤ã§ãä¿è·ç¶æ ã管çã§ãã¾ãã
ããã¥ã¡ã³ããFAQãªã©ãããè©³ç´°ãªæ å ±ã¯ ãã¡ã ã§ã覧ããã ãã¾ãã
- WordPressã®ãã«ããµã¤ãæ©è½ã«ã¯å¯¾å¿ãã¦ãã¾ããã
- Webãµã¼ãã¼ã®Apache1.3ã2.xã«ã®ã¿å¯¾å¿ãã¦ãã¾ãã
- ç»åèªè¨¼è¿½å æ©è½ãå©ç¨ããããã«ã¯ãPHPã«æ¡å¼µã©ã¤ãã©ãªãgdããã¤ã³ã¹ãã¼ã«ããå¿ è¦ãããã¾ãã
- 管çç»é¢ã¢ã¯ã»ã¹å¶éæ©è½ããã°ã¤ã³URL夿´æ©è½ãå©ç¨ããããã«ã¯ãApacheã«ãmod_rewriteããèªã¿è¾¼ãå¿ è¦ãããã¾ãã
æ¬ãã©ã°ã¤ã³ã®æ©è½ã¯ä»¥ä¸ã®ã¨ããã§ãã
ãã°ã¤ã³ç¡å¹å
æå®ããæéå ã«æå®ããåæ°ãã°ã¤ã³ã«å¤±æããå ´åãæå®ããæéãã°ã¤ã³ãç¡å¹åï¼ãããã¯ï¼ãã¾ãã ãã«ã¼ããã©ã¼ã¹ã¢ã¿ãã¯ããã¹ã¯ã¼ããªã¹ãæ»æãªã©ã䏿£ãªãã°ã¤ã³ã試ã¿ãæ»æãé²ãããã®æ©è½ã§ãã ã¨ãã«ãèªååãããæ»æã«æå¹ã§ãã
ãã°ã¤ã³URL夿´
ãã°ã¤ã³URLï¼wp-login.phpï¼ã夿´ãã¾ãã åè§è±å°æåãåè§æ°åããã¤ãã³ãã¢ã³ãã¼ã¹ã³ã¢ã®ããããã使ç¨ãã4æå以ä¸12æå以ä¸ã§ã好ã¿ã®ååï¼æååï¼ã«è¨å®ã§ãã¾ãã ãã«ã¼ããã©ã¼ã¹ã¢ã¿ãã¯ããã¹ã¯ã¼ããªã¹ãæ»æãªã©ã䏿£ãªãã°ã¤ã³ã試ã¿ãæ»æãåãã«ããããããã®æ©è½ã§ãã
ãã°ã¤ã³ã¨ã©ã¼ã¡ãã»ã¼ã¸çµ±ä¸
ãã°ã¤ã³æãã¦ã¼ã¶ã¼åããã¹ã¯ã¼ããç»åèªè¨¼ã®ã©ããééãã¦ãåä¸ã®ã¡ãã»ã¼ã¸ã表示ãã¾ãã ã¦ã¼ã¶ã¼åã®åå¨ã調æ»ããæ»æãåãã«ããããããã®æ©è½ã§ãã
2段éèªè¨¼
ãã°ã¤ã³æãã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã®å ¥åã«å ããå¥ã®ã³ã¼ãã§è¿½å èªè¨¼ãè¡ãã¾ãã å©ç¨ããã«ã¯ãGoogle Authenticator ã¢ããªã±ã¼ã·ã§ã³ã§ããã¤ã¹ãç»é²ããå¿ è¦ãããã¾ãã ã¢ããªã±ã¼ã·ã§ã³ã«è¡¨ç¤ºããã6æ¡ã®èªè¨¼ã³ã¼ãããã°ã¤ã³ç»é¢ã§å ¥åãããã¹ã¦ã®æ å ±ãä¸è´ããã°ãã°ã¤ã³ã§ãã¾ãã ã¦ã¼ã¶ã¼åããã¹ã¯ã¼ãã䏿£å ¥æãã第ä¸è ã«ãããã°ã¤ã³ããªããã¾ãã鲿¢ããã»ãã¥ãªãã£ãå¼·åãã¾ãã
ç»åèªè¨¼è¿½å
ç»åãã¼ã¿ä¸ã«ã©ã³ãã ã«è¡¨ç¤ºãããæåã®å ¥åãæ±ããä¸è´ããªããã°æ¬¡ã®ç»é¢ã«é²ããªãããã«ããæ©è½ã§ãã ãã°ã¤ã³ãã©ã¼ã ãã³ã¡ã³ããã©ã¼ã ããã¹ã¯ã¼ããªã»ãããã©ã¼ã ãã¦ã¼ã¶ã¼ç»é²ãã©ã¼ã ã«è¨å®ã§ãã¾ãã ãã«ã¼ããã©ã¼ã¹ã¢ã¿ãã¯ããã¹ã¯ã¼ããªã¹ãæ»æãªã©ã®ä¸æ£ãªãã°ã¤ã³ã試ã¿ãæ»æããæªæã®ããããã°ã©ã ããã®æ©æ¢°çãªä¸æ£ã¢ã¯ã»ã¹ã鲿¢ããæ©è½ã§ãã
管çç»é¢ã¢ã¯ã»ã¹å¶é
管çç»é¢ã«ãã°ã¤ã³ãã¦ããªãæ¥ç¶å IPã¢ãã¬ã¹ãã管çãã¼ã¸ï¼/wp-admin/以éï¼ã«ã¢ã¯ã»ã¹ããã¨ã404ã¨ã©ã¼ï¼Not Foundï¼ãè¿ãã¾ãã 24æé以ä¸ç®¡çç»é¢ã«ãã°ã¤ã³ãã¦ããªãæ¥ç¶å IPã¢ãã¬ã¹ã対象ã§ãã ãã°ã¤ã³ããã¨æ¥ç¶å IPã¢ãã¬ã¹ãè¨é²ããã管çç»é¢ã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã¾ãã ãã®æ©è½ãé¤å¤ãããã¼ã¸ï¼wp-admin以ä¸ï¼ãæå®ã§ãã¾ãã
è¨å®ãã¡ã¤ã«ã¢ã¯ã»ã¹é²æ¢
WordPressã®ã·ã¹ãã ã«é¢ãããã¡ã¤ã«ã¸ã®ä¸æ£ã¢ã¯ã»ã¹ã鮿ããæ©è½ã§ãã
ã¦ã¼ã¶ã¼åæ¼ãã鲿¢
ã?author=æ°åãã¢ã¯ã»ã¹ã«ããã¦ã¼ã¶ã¼åã®æ¼ããã鲿¢ãã¾ãã
XML-RPCç¡å¹å
XML-RPCæ©è½ãã¾ãã¯ãã³ããã¯æ©è½ãç¡å¹åãããã®ä¹±ç¨ãã管çç»é¢ãä¿è·ãã¾ãã
REST APIç¡å¹å
REST APIãç¡å¹åãããã®æªç¨ãã管çç»é¢ãå®ãã¾ãã
ã·ã³ãã«WAF
WordPressã¸ã®æ»æã«å¯¾ãã¦ãåºæ¬çãªé²å¾¡æ©è½ãåããã·ã³ãã«ãªWAFï¼Web Application Firewallï¼æ©è½ã§ãã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ãªã©ã®ä¸è¬çãªæ»æã鮿ãã¾ãã
ãã°ã¤ã³éç¥
ãã°ã¤ã³ããã£ãã¨ããã¦ã¼ã¶ã¼ã«ã¡ã¼ã«ã§éç¥ãã¾ãã å¿å½ããã®ãªãã¡ã¼ã«ãåä¿¡ããå ´åã䏿£ãªãã°ã¤ã³ãçã£ã¦ãã ããã
ã¢ãããã¼ãéç¥
WordPressããã©ã°ã¤ã³ããã¼ãã®æ´æ°ãå¿ è¦ã«ãªã£ãã¨ãã管çè ã«ã¡ã¼ã«ã§éç¥ãã¾ãã æ´æ°ã®ç¢ºèªã¯24æéãã¨ã«è¡ããã¾ãã å¸¸ã«ææ°çã使ç¨ãããã¨ããã»ãã¥ãªãã£ã®åºæ¬ã§ãã
ãµã¼ãã¼ã¨ã©ã¼éç¥
ãµã¼ãã¼ã¨ã©ã¼ãHTTPã¹ãã¼ã¿ã¹ã³ã¼ã500ï¼Internal Server Errorï¼ããçºçããã¨ããã¨ã©ã¼ã®å±¥æ´ãè¨é²ãã管çè ã«ã¡ã¼ã«ã§éç¥ãã¾ãã 1æé以å ã«åãã¿ã¤ãã®ã¨ã©ã¼ãçºçããå ´åãã¨ã©ã¼ã®å±¥æ´ã¯è¨é²ãã¾ãããã¡ã¼ã«ã§ã®éç¥ã¯è¡ãã¾ããã
ãã°ã¤ã³å±¥æ´
管çç»é¢ã«ãã°ã¤ã³ããå±¥æ´ã表示ãã¾ãã ããããã®é ç®ã§çµãè¾¼ãã§ã®æ¤ç´¢ãå¯è½ã§ãã ãã°ã¤ã³éç¥ã¨åæ§ã䏿£ãªãã°ã¤ã³ã®æ°ã¥ããä¿ãæ©è½ã§ãã
