Silk Road forums

Support => Bug reports => Topic started by: boaclon224 on September 05, 2013, 09:46 am

Title: MediaWiki better practises
Post by: boaclon224 on September 05, 2013, 09:46 am
Not sure if this is the ideal place to bring this up, but hopefully the right people will see it.

MediaWiki by default has a page called "Special:Version". This tells exactly what versions of PHP, MySQL & MediaWiki are running, which in the case of the SR servers is giving rather more away than it should. It can be disabled the same way as other special pages, with a little addition to LocalSettings.php; see: https://www.mediawiki.org/wiki/Manual:Special_pages#Disabling_Special:UserLogin_and_Special:UserLogout_pages

Also, you should switch to the LTS release of MediaWiki, rather than 1.17, which has plenty of known vulnerabilities (most of which won't be relevant to the way you're using it, but some probably are). The 1.19 series is the current LTS, and will be supported until May 2015 - see https://www.mediawiki.org/wiki/Version_lifecycle