Empire CMS 6.5 features decryption: Site Security Firewall Instructions

CMS introduced a new version of Empire about the firewall can view: http://bbs.phome.net/showthread-13-136169-0.html This article is to explain how to use the site Firewall: First, configure the "Site Firewall" There are two ways: 1. background> "system settings"> "site firewall." 2, modify e / class / config.php file configuration. Second, explain the role and use of the following related settings: 1, firewall encryption key: This must be set to fill 10 to 50 arbitrary characters, a variety of the best combination of characters. And recommend changes once every week or every month. 2, allowing the Manage Domain: Set the background to allow only domain names, the domain name is bound to the root of the site, accessible only by this domain e / admin background is allowed. General secondary domain name with a domain name of the site can be, if more for the insurance can also bind a new domain name of second level domain. For example: domain: http://www.phome.net , and access to back the domain name with http://abc.digod.com domain name and bindings also support an increase in ports, such as: HTTP: //abc.phome. NET: 8080 , provided that the server supports the use of this port visit. Binding domain ( http://abc.digod.com visit backstage after the address) is: http://abc.digod.com/e/admin/ , and backstage access by other domain names are blank.



















3, allowing the landing point of time the background, the background to allow the landing of the week:
to facilitate the work of the unit set working hours, to make the site easier to maintain security control, let the user into the background outside of working hours.
If the emergency exception can modify e / class / config.php file configuration manually.

4, firewall backstage pre-landing verification variable names and firewall backstage pre-login authentication code
both must be set.
Pre login authentication variable name: can contain letters + numbers (must begin with a letter), 5 to 20 characters.
Pre-login authentication number: the number of any characters 10 to 50, more preferably a combination of characters.
And recommend changes once every week or every month.

5, shielded submit sensitive characters:
This feature is the core firewall security, safety can be filtered to the front desk all the information entered by the user. Usually associated character set php, mysql and other attacks.
For example: sql injection characters are usually used: select, outfile, union, delete , insert, update, replace, sleep, benchmark, load_file, create


links:
Empire CMS 6.5 features decryption: The procedures debris
Empire CMS 6.5 features decryption: Description workflow used

Guess you like

Origin www.cnblogs.com/lazb/p/11718026.html