Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
htaccess changes in core
#4
There were plenty situations when temp.htaccess hasn't been renamed during installation.
If you place all deny rules within root .htaccess file, and this situation happens again, houston might get a security problem with a free access to user.xml Wink
(this of course is still possible on non apache webservers)
Uploads and thumbs dirs might be moved to root, and deny rule might get into root htaccess (look here: http://get-simple.info/forums/showthread...3#pid31223) as it shouldn't open a security hole (as long as script file within upload/thumb dir wouldn't be executed by GS)

ps. many plugins also have deny rules in own htaccess files
Don't you think that GS should disallow accessing all mentioned dirs, and plugin files on his own, instead of basing on apache's deny mechanism ?
Addons: blue business theme, Online Visitors, Notepad
Reply


Messages In This Thread
htaccess changes in core - by shawn_a - 2013-01-14, 02:15:16
RE: htaccess changes in core - by Carlos - 2013-01-14, 05:03:27
RE: htaccess changes in core - by shawn_a - 2013-01-14, 07:54:54
RE: htaccess changes in core - by yojoe - 2013-01-14, 10:36:14
RE: htaccess changes in core - by shawn_a - 2013-01-14, 12:39:35
RE: htaccess changes in core - by yojoe - 2013-01-14, 18:13:05
RE: htaccess changes in core - by eatons - 2013-01-14, 23:33:08
RE: htaccess changes in core - by shawn_a - 2013-01-15, 00:13:47
RE: htaccess changes in core - by eatons - 2013-01-15, 02:24:28
RE: htaccess changes in core - by shawn_a - 2013-01-15, 02:45:22
RE: htaccess changes in core - by eatons - 2013-01-15, 23:18:33



Users browsing this thread: 1 Guest(s)