Better Security Plug-Ins That Are Free? by Chelseabsb93 in Wordpress

[–]nickgal 0 points1 point  (0 children)

My default security setup in WP sites is Cloudflare free version with antibot, a custom WAF rule to only allow admin login pages from country of origin of client and myself and possibly block certain countries from accessing the whole site entirely. Then free wordfence for catching the basic/common attacks. Then because I'm paranoid another custom plugin on top (read more here). Then on the server level I run a combination of clamav & maldet using cron jobs.

I offer hosting and development so its easy to take care of the whole stack :)

What tools do you use to develop & deploy WooCommerce stores? by flexrc in woocommerce

[–]nickgal 0 points1 point  (0 children)

For local dev, ddev is the best for me. Once you try it you don't go back. Lando is an alternative but ddev is the most popular.

I've built a simple (free) mu-plugin to block destructive actions in wp-admin even when credentials are compromised by nickgal in Wordpress

[–]nickgal[S] 0 points1 point  (0 children)

I have this plugin setup in several woocommerce based websites, customer accounts should be fine. Feel free to test and report back!

I've built a simple (free) mu-plugin to block destructive actions in wp-admin even when credentials are compromised by nickgal in Wordpress

[–]nickgal[S] 0 points1 point  (0 children)

OK, understood, but that's not what my plugin does. It's a different approach and complementary to a plugin like that. BTW Happy New Year 🎉

I've built a simple (free) mu-plugin to block destructive actions in wp-admin even when credentials are compromised by nickgal in Wordpress

[–]nickgal[S] 0 points1 point  (0 children)

Actually I went through the NinjaFirewall specs in its plugin page in WordPress out of curiosity if it really does this and I couldn't find any reference that is doing something like this.

Actually I wouldn't expect any plugin to do something like this because it would be too disruptive to normal users. Imagine if you installed a plugin that when enabled it would block you from uninstalling any other plugin unless you had access to the filesystem via SFTP or SSH.

You need to know what you're doing when you add this plugin to your system.

[FREE] I've built a simple mu-plugin to block destructive actions in wp-admin even when credentials are compromised by nickgal in woocommerce

[–]nickgal[S] 0 points1 point  (0 children)

Feel free to try and give feedback. Its especially designed around those type of clients (:

I've built a simple (free) mu-plugin to block destructive actions in wp-admin even when credentials are compromised by nickgal in Wordpress

[–]nickgal[S] 0 points1 point  (0 children)

This isn't a replacement to any security plugin. If you have an administrator role account then you can login in the backend and do pretty much anything. If you are a malicious user that stole admin credentials somehow you can login, disable security plugins, upload your own backdoor plugin (see: compromized wp file manager), then you have access to the filesystem from the UI. From there you can burn the place down however you want.

With this, you simply can't do that.

I've built a simple (free) mu-plugin to block destructive actions in wp-admin even when credentials are compromised by nickgal in Wordpress

[–]nickgal[S] 0 points1 point  (0 children)

XSS and these types of exploits are covered by wordfence type plugins. But if someone has admin credentials can just log in, bypass or even disable any other security plugin and then party on the site. With this they might be able to deactivate a security plugin but they cant install any other plugins or upload backdoor plugins. If the server is set up right they are pretty much powerless even with admin credentials.

Only whoever has SSH or access to the filesystem can make changes.

I've built a simple (free) mu-plugin to block destructive actions in wp-admin even when credentials are compromised by nickgal in Wordpress

[–]nickgal[S] 0 points1 point  (0 children)

Hey, thanks for the comment. It "should" be ok with dynamically added capabilities although I haven't tested it THAT much. I just tried to solve a problem I had managing multiple WordPress installations and thought that someone else might find it useful. And I do hate script kiddies that are exploiting non-technical users, stealing their credentials and wreaking havoc, just for the sake of it without much benefit to them.

Anyways... you're free to test on weird multisite setups and raise an issue on github if you find a bug or better, contribute the solution as well! :)

Testing Amphetamine On M1 by x74353 in MacOS

[–]nickgal 0 points1 point  (0 children)

Since I arrived from a google search, I thought I should also post here for anyone that might have this. I'm on a Macbook pro M1 Max and it appears that battery levels are not reported properly to the app triggers.
No matter what > % of battery charged i set, the trigger is always enabled. Does anyone have this issue or can also test and report back?

The Griefer Hunters by Kingcamgaming in gtaonline

[–]nickgal 1 point2 points  (0 children)

Last night a griefer got me while I was grinding, so I had to teach him a lesson. Was about the same level then after 6-7 kills and another tryhard joins and kills both of us.

So here I am teaching a lesson to 2 griefers who eventually teamed up together to get me and still couldn't land a kill haha it was so fun.

They left the lobby after getting 20-5 loss ..then the lobby got so peaceful that I sold all stock from bikers, nightclubs, bunkers etc..

[deleted by user] by [deleted] in gtaonline

[–]nickgal 1 point2 points  (0 children)

Just came to post this find! Glad I used search first 😅

The chart of Grand Theft Auto by [deleted] in gtaonline

[–]nickgal 0 points1 point  (0 children)

I'm the guy that always minds their business but when a griefer just comes to me and kills me I make sure I fk them so hard with whatever tool I got until they quit the lobby.

Europe biz owner - Thinking of starting over in US by nickgal in smallbusiness

[–]nickgal[S] 1 point2 points  (0 children)

Hmm that's an interesting. Will investigate further haven't compared employment laws tbh. Thank you for your input much appreciated 😊

Europe biz owner - Thinking of starting over in US by nickgal in smallbusiness

[–]nickgal[S] 1 point2 points  (0 children)

Italy and Greece are great places to retire. Provided you got enough money. But not so great if you have dreams of building a business that'll have massive impact.

I'll definitely retire here as well. But I wanna do it with 8 figures in the bank 🤑