[wordpress插件] NO SSL Flash Upload没有SSL Flash上​​传

wordpress 插件 文章 2020-01-23 18:40 635 0 全屏看文

AI助手支持GPT4.0

评分

0

0

描述

Note: WordPress 3.3 offers a new, non-Flash uploader;

注意:WordPress 3.3提供了一个新的非Flash上​​传器;

this plugin may break it.

该插件可能会破坏它。

If you are using SSL (https) to secure your WordPress admin sessions and you

如果您使用SSL(https)保护WordPress管理会话,那么您

have an SSL certificate that is not trusted by default (because it is self-

具有默认情况下不受信任的SSL证书(因为它是自-

signed, signed by an untrusted certificate authority, signed for a different

已签名,由不受信任的证书颁发机构签名,已为其他签名

domain name, etc.), then you probably have problems using the Flash uploader.

域名等),那么您使用Flash上​​传器时可能会遇到问题。

This plugin disables SSL usage by the Flash uploader.

此插件会禁止Flash上​​传器使用SSL。

This allows you to use

这使您可以使用

the Flash uploader when you have FORCE_SSL_ADMIN enabled, with an untrusted SSL

启用了FORCE_SSL_ADMIN且使用不受信任的SSL的Flash上​​传器

certificate.

证书。

This works around the vague “IO Error” you get from the Flash

这可以解决您从Flash获得的模糊的“ IO错误”

uploader in such a situation.

在这种情况下上传。

Note that this plugin comes with the following security implications:

请注意,此插件具有以下安全隐患:

    • Flash uploads no longer use SSL, thus, your uploaded files aren’t encrypted

    • Flash上​​传不再使用SSL,因此,您上传的文件未加密

      during transmission.

    • 在传输过程中。

    • Uploading files with the Flash uploader will transmit your WordPress

    • 使用Flash上​​传器上传文件会传输您的WordPress

      authentication cookie in plain text.

    • 纯文本身份验证cookie。

    • If someone captures your login cookie (which is transmitted any time you load

    • 如果有人捕获了您的登录Cookie(每次加载时都会传输该邮件

      a page on your WordPress site while logged in, whether you are using SSL or

      无论您使用的是SSL还是
      ,登录后WordPress网站上的页面

      not), they may be able to use it to upload files, view information about

      则),他们也许可以使用它上传文件,查看有关
      的信息

      uploaded files, or change information about uploaded files.

    • 上传的文件,或更改有关上传的文件的信息。

    If the benefit of having the Flash uploader available outweighs these potential

    如果拥有Flash上​​传器的好处超过了这些潜力,

    security risks for you, then you can use this plugin to enable the Flash

    安全隐患,那么您可以使用此插件启用Flash

    uploader.

    上传器。

    Note that this plugin override’s WordPress’s auth_redirect and

    请注意,此插件会覆盖WordPress的auth_redirect和

    wp_validate_auth_cookie functions, and may not work if you are using other

    wp_validate_auth_cookie函数,如果您正在使用其他函数,则可能不起作用

    plugins that override these functions.

    覆盖这些功能的插件。

下载地址

https://downloads.wordpress.org/plugin/aarons-no-ssl-flash-upload.1.0.8.zip

https://downloads.wordpress.org/plugin/aarons-no-ssl-flash-upload.1.0.8.zip

-EOF-

AI助手支持GPT4.0