ais681
Forum Replies Created
-
Thanks.
It is the settings in the Multi network Single Site that I do not want the Network site administrators to be able to use and that is still included.
According to our security Scanning staff in a Network Multi site you can Turn off Security in your network site i=on the settings TAB after which your https://mydomain/mynetworksite becomes vulnerable Vulnerable.
WE want to force Brute Force security in all multisites and not allow a Network Site administrator to Turn off Security. Can we take out that Button from Security Settings or make it Can only be done by a super Admin?
I said to my security scanner person surely all the Security we set for all multisites in Network Admin All in One WP security settings would remain on the Network site off button only turns off extra added stuff set in the network site dashboard.
I said OK Tell me what Vulnerabilities your scan found after you said Turn off Security in settings.
GET me before and after scan results.
I am very busy and not wordpress experisnces so I hav enot had time to check this out.
Had to go with “Do not use this Plugin Netwotrk Activated”.
Also Miscellaneous in a single network site allows turn off of iframe and user enumeration protection.
THERE is nothing in this DOC to tell me how to Prevent these 2 cases.
SORRY Must be brain dead? OR still did not discover how to set this?
Forum: Plugins
In reply to: [Multisite Plugin Manager] WordPress V4.4 wp-includes/plugin.php memory leak?THANKS for your reply.
A bit out of my depth and had to give up because we had too much else on and too many people away.
I did not try deactivating the plugin yet.
I have not been able to get any response from the wordpress site administrator.
I will organise to deactivate your plugin and see what happens and I will take a look at https://blackfire.io
There is more than 1 wordpress site on this server.
This is the only Site that is doing this.I settled back to these changes to php defaults.
They are in .htaccess and you can see in apache logs that they apply to this WP instance.I had increased memory_limit up and up to 2048 to see a lot more Kernel out of memory in the messages files.
max_Execution_time is also reached in comment-template.php line 1337 frequently.
I increased the limit up to > 10 minutes and max_exection_time FATAL error still happens.php_value upload_max_filesize 999M
php_value post_max_size 999M
php_value memory_limit 256M
<IfModule mod_php5.c>
php_value max_execution_time 60
</IfModule>When I look at PERFORMANCE NOW CPU is 99 or 100% out of 8G 2.4G used 5.6G free.