ataylorme / WordPress-Hosting-Best-Practices-Documentation

Other
84 stars 16 forks source link

Using the default Apache virtualhost #2

Open aaroncampbell opened 7 years ago

aaroncampbell commented 7 years ago

There was recently an issue where a potential vulnerability was only possible if the site was using a default catch-all virtual host in Apache. Generally speaking, a catch-all should be for catching things you didn't expect. Known domains should have a unique virtual host set up, and the catch-all should be handled carefully as though the domain name itself is untrusted.