Open in app

Sign in

Write

Sign in

Sandeep Vishwakarma
Sandeep Vishwakarma

159 Followers

Home

About

Published in

InfoSec Write-ups

·2 days ago

Implementation of Security headers in Apache Server

In an era where cybersecurity threats are rampant, securing your web server is of utmost importance. Apache, one of the most widely used web servers, provides a robust platform for hosting websites and applications. …

Apache Security

2 min read

Implementation of Security headers in Apache Server
Implementation of Security headers in Apache Server
Apache Security

2 min read


Published in

InfoSec Write-ups

·4 days ago

Implementation of Security headers in Microsoft IIS Server

Security headers play a crucial role in enhancing the security of your web applications by providing an additional layer of protection against various types of attacks. In this guide, we will walk through the process of implementing essential security headers on a Microsoft IIS 10 server. Prerequisites - Administrative access…

Microsoft Server

3 min read

Implementation of Security headers in Microsoft IIS Server
Implementation of Security headers in Microsoft IIS Server
Microsoft Server

3 min read


Published in

InfoSec Write-ups

·6 days ago

Implementation of Security headers in Ngnix Server

To implement security headers in an Nginx server, you can modify your server block configuration file. The location of this file can vary depending on your server setup, but common locations include `/etc/nginx/nginx.conf` or `/etc/nginx/sites-available/default`. Here’s an example of how you can add the specified security headers: Strict-Transport-Security: server { …

Ngnix

2 min read

Implementation of Security headers in Ngnix Server
Implementation of Security headers in Ngnix Server
Ngnix

2 min read


Published in

InfoSec Write-ups

·Nov 20

Vulnerability Exploiting Privilege Escalation Discovered in WordPress [CVE-2023–32243]

A security vulnerability has been detected in Essential Addons for Elementor, a widely utilized WordPress plugin with over one million active installations. This specific flaw, identified as CVE-2023–32243, allows an unauthorized attacker to reset the password for any user on the affected website, providing them with administrator privileges. Upon conducting…

Wordpress Plugins

5 min read

Vulnerability Exploiting Privilege Escalation Discovered in WordPress [CVE-2023–32243]
Vulnerability Exploiting Privilege Escalation Discovered in WordPress [CVE-2023–32243]
Wordpress Plugins

5 min read


Published in

InfoSec Write-ups

·Nov 17

A Step-by-Step Guide to Setting Up WordPress on XAMPP Server

Introduction: If you’re eager to dive into the world of website development and design, WordPress is an excellent platform to start with. To make the process smoother and more convenient, using a local server like XAMPP can be a game-changer. …

Xampp

3 min read

A Step-by-Step Guide to Setting Up WordPress on XAMPP Server
A Step-by-Step Guide to Setting Up WordPress on XAMPP Server
Xampp

3 min read


Published in

InfoSec Write-ups

·Nov 17

Exploiting SQL Injection in WP Fastest Cache (CVE-2023–6063)

Exploiting SQL Injection in WP Fastest Cache (CVE-2023–6063) In the ever-changing digital landscape, safeguarding the security of our online assets is of utmost importance. WordPress, a major player in web development, recently faced a significant security challenge with a critical vulnerability in one of its widely-used plugins — WP Fastest Cache. Discovered by the diligent WPScan team from…

Sql Injection Attack

4 min read

Exploiting SQL Injection in WP Fastest Cache (CVE-2023–6063)
Exploiting SQL Injection in WP Fastest Cache (CVE-2023–6063)
Sql Injection Attack

4 min read


Published in

InfoSec Write-ups

·Nov 16

Securing Your Nginx Server: Hiding Version Disclosure

Nginx is a powerful and widely used web server known for its performance and scalability. However, like any software, it’s important to take measures to enhance its security. One commonly recommended practice is to hide the version disclosure information, which can be a valuable asset for potential attackers. …

Ngnix

2 min read

Securing Your Nginx Server: Hiding Version Disclosure
Securing Your Nginx Server: Hiding Version Disclosure
Ngnix

2 min read


Published in

InfoSec Write-ups

·Nov 16

How to Remove WordPress Version Number?

Are you interested in learning how to eliminate the WordPress version number from your website? WordPress typically showcases its version in the header, RSS, and various areas throughout the site. If you’re using WordPress, you’ve likely come across security recommendations advising the concealment of the version number. Despite its popularity…

WordPress

6 min read

How to Remove WordPress Version Number?
How to Remove WordPress Version Number?
WordPress

6 min read


Published in

InfoSec Write-ups

·Nov 15

How to Disable Directory Listing in WordPress

Would you like guidance on turning off directory listing in WordPress? This guide provides precise steps to help you accomplish. Many users overlook the importance of disabling directory listing, which can create privacy, security, and SEO concerns. It might also affect your website’s user experience negatively. …

WordPress

8 min read

How to Disable Directory Listing in WordPress
How to Disable Directory Listing in WordPress
WordPress

8 min read


Published in

InfoSec Write-ups

·Nov 13

Understanding xmlrpc.php in WordPress and the Importance of Disabling It

For those passionate about securing their WordPress websites, the term “xmlrpc.php” is likely familiar. Let’s delve into the significance of xmlrpc.php, its functions, and the reasons behind contemplating its disabling to bolster the security of a WordPress site. Unpacking xmlrpc.php Xmlrpc.php is an integral file within the WordPress core facilitating remote communication…

Wordpress Plugins

3 min read

Understanding xmlrpc.php and Disabling in WordPress
Understanding xmlrpc.php and Disabling in WordPress
Wordpress Plugins

3 min read

Sandeep Vishwakarma

Sandeep Vishwakarma

159 Followers

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams