Controllare per vulnerabilità
owncloud:
https://owncloud.org/security/
https://hackerone.com/owncloud
http://www.cvedetails.com/vulnerability-list/vendor_id-11929/Owncloud.htm
wordpress:
http://www.cvedetails.com/vulnerability-list/vendor_id-2337/product_id-4096/
- no admin name user, no domain name as user (anche per db e ftp)
- Site always up-date
- controllare commenti chiusi ed iscrizioni utenti chiuse
- no login in wp-admin
- captcha on the login page/ no brute force
- ip list for bot
- https on login
- rewrite rule to 404 for admin area
WP-PLUGIN:
-Anti-Malware and Brute-Force Security by ELI
-iThemes Security (cloud solution, piuttosto invasiva)
-Sucuri (?!?! non aggiornato)