Part 4: How to secure your free WordPress server on Google Cloud Platform with security headers

Опубликовано: 24 Октябрь 2024
на канале: Tech IT Easy Australia
92
3

Secure your WordPress server to keep hackers away!

Here are all the commands shown in the video
Test web site: https://securityheaders.com/
Enable headers module: sudo a2enmod headers

Add at the end of apache2.conf (you need to replace { and } with corresponding angled brackets because YouTube won't allow angled brackets in the description)

Security settings
{IfModule mod_headers.c}
{Directory /}
Header always set X-XSS-Protection "1; mode=block"
Header always set x-Frame-Options "SAMEORIGIN"
Header always set X-Content-Type-Options "nosniff"
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Header always set Content-Security-Policy "default-src 'self'; connect-src *; font-src *; frame-src *; img-src * data:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline';"
Header always set Referrer-Policy "strict-origin"
Header always set Permissions-Policy: ""
{/Directory}
{/IfModule}

restart apache: sudo service apache2 restart

Thanks for watching and be safe!