Veuillez remplir les champs ci-dessous pour que nous puissions vous aider. Remarque : vous devez fournir votre nom de domaine pour obtenir de l’aide. Les noms de domaine des certificats émis sont tous rendus publics dans les journaux de Transparence de Certificat (par exemple, crt.sh | example.com). Par conséquent, le fait de ne pas indiquer votre nom de domaine ici n’aide pas à le garder secret, mais rend plus difficile pour nous le fait de vous aider.
Le système d’exploitation sur lequel mon serveur Web s’exécute est (version incluse) :
Mon hébergeur, le cas échéant, est : IONOS
Je peux me connecter à un shell root sur ma machine (oui ou non, ou je ne sais pas) : je ne sais pas
J’utilise un panneau de configuration pour gérer mon site (non, ou fournit le nom et la version du panneau de configuration) : wordPress
Bonjour,
Mon site wordpress est hébergé chez IONOS, et il s'avère que j'atteins la limite du nombre de fichiers autorisés (258 065 / 262 144 utilisé(s)). Je fais donc "du ménage" et je voulais savoir si dans les répertoires well-known certains fichiers pouvaient être supprimés ? IONOS m'a notamment indiqué que les répertoires ED-Configs contenus dans pli-validation et acme-challenge étaient très lourds.. J'ai également vu, en parcourant les fichiers via FTP, qu'il y avait des fichiers nommés "joomla ou encore magento" etc.. or je suis sur un site wordpress, est-ce que c'es fichiers txt sont tous utiles ?
Merci de votre aide,
thank you @9peppe for your answer. So do you mean that I can remove all folders and files in well-known/acme-challenge ? I don't know what is "my acme" ?
You put a point before well-known (.well-known) and I see that there is 2 folders :
the first one :
/.well-known/apple-developer-merchantid-domain-association --> can I delete it ?
the other one :
/well-known/acme-challenge/(with folders a, b, d...) --> you say I can remove it ?
/well-known/pki-valdiation/(with folders a, b, d...) --> what about this one, can I remove it too ?
there is no dot before the folder well-known which contain directories named a, b, c, d etc...., and in one of them there is a directory called ED-Configs with lots of files..
I don't know how these directories arrived here and I don't know who can I help me to know if I can delete them or not...
If it doesn’t make any sense, I suppose I could delete these folders..?
Nobody create these files manually but perhaps were they created when the site was hacked there is 6 months ago ??
IMHO, I would delete the ENTIRE well-known and .well-known directories, then start from scratch. I would also start with a fresh wordpress install and run every security tool on it. I would also make sure your ACME account keys were recycled, along with any other credentials on that server.
The only reference I have found online for directory structures like yours, are when hackers compromise a website and try to hide files so people do not realize it is compromised. This often happens with wordpress installs. Using a deeply nested directory structure like that, hackers can hide malicious content without you realizing. For example, look at this url that uses the same structure as yours: https://awmci.us/well-known/pki-validation/h/b/j/b/ED-Configs/JumpF0x/0-blockbeats/blog-full-left-sidebar-with-frame/page/2/index.html. There are several other sites that appear to be compromised with JumpF0x in their urls. Most seem to have full wordpress installs in there, and spoof various websites. Most likely, hackers compromise a site like that and then direct people to it with spam/phishing campaigns. Because the content is hidden, the compromised site owners have no idea.
je suis desole, mais mon Français c'est tres mal. j'espère que vous pouvez comprendre mon Anglais. même aprés plus des années des études à l'école et à l'université.
Thank you very much @jvanasco for your answer.
your French is not worse than my English
I don't know how I can make sure my ACME account keys have been recycled, who can tell me? I don't know what an "ACME" is..
Another question: if I rename the well-known directory, I will see if it breaks my site or not? If not, I can delete the directories, what do you think?
Thank you @9peppe, if i can avoid deleting everything that would be great
I was wondering if I rename the folder and my site still works is that I can delete this folder without any consequences, isn't it ?
That logic stands to reason, but I would wait still a few days (or weeks) to ensure nothing actually needs that information before deleting it.
Better to have and not need that to need and not have.