Forums / General / urgent...security issues!

urgent...security issues!

Author Message

kevin wei

Tuesday 11 January 2005 10:34:26 pm

i in stall ez on a non-virtual host, and i cannot put .htaccess under my root folder, which will cause i cannot access the whole site, so i change all file's name under settings to xxx.ini.php.
to my surprise, i can see all contents by http://xxx.com/settings/xxx.ini.php

how can i protect these file from accessing by http protocol?

thanks!

Gabriel Ambuehl

Tuesday 11 January 2005 11:59:22 pm

Sounds like a misconfiguration of the webserver. You should talk to your webhoster.

Visit http://triligon.org

kevin wei

Wednesday 12 January 2005 12:24:55 am

yes,
but i cannot ask him changed for me, do there have any other way can make it securty.
i found i can not access xxx.ini.append file, so can i rename all ini files under settings to ini.append or delete theme all, only left files under override and siteaccess.

thx

Björn Dieding@xrow.de

Wednesday 12 January 2005 1:51:17 pm

if

http://xxx.com/settings/xxx.ini.php files are readable and you cannot place a .htaccess there is no hope for you :-)... Still liek said before talk to your host

another idea could be to place a .htaccess in setttings/

also remove the runcronjobs.php

Looking for a new job? http://www.xrow.com/xrow-GmbH/Jobs
Looking for hosting? http://hostingezpublish.com
-----------------------------------------------------------------------------
GMT +01:00 Hannover, Germany
Web: http://www.xrow.com/

eZ debug

Timing: Jan 18 2025 22:32:24
Script start
Timing: Jan 18 2025 22:32:24
Module start 'content'
Timing: Jan 18 2025 22:32:24
Module end 'content'
Timing: Jan 18 2025 22:32:24
Script end

Main resources:

Total runtime0.1890 sec
Peak memory usage2,048.0000 KB
Database Queries141

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0057 588.7188180.8516
Module start 'content' 0.00570.0047 769.570393.8203
Module end 'content' 0.01040.1785 863.3906522.1484
Script end 0.1889  1,385.5391 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00341.7916200.0002
Check MTime0.00130.6904200.0001
Mysql Total
Database connection0.00070.364110.0007
Mysqli_queries0.141174.68961410.0010
Looping result0.00160.82341390.0000
Template Total0.178294.310.1782
Template load0.00080.424910.0008
Template processing0.177493.888310.1774
Override
Cache load0.00060.308010.0006
Sytem overhead
Fetch class attribute can translate value0.00100.532910.0010
XML
Image XML parsing0.00030.142310.0003
General
dbfile0.00402.0977200.0002
String conversion0.00000.003830.0000
Note: percentages do not add up to 100% because some accumulators overlap

CSS/JS files loaded with "ezjscPacker" during request:

CacheTypePacklevelSourceFiles
CSS0extension/community/design/community/stylesheets/ext/jquery.autocomplete.css
extension/community_design/design/suncana/stylesheets/scrollbars.css
extension/community_design/design/suncana/stylesheets/tabs.css
extension/community_design/design/suncana/stylesheets/roadmap.css
extension/community_design/design/suncana/stylesheets/content.css
extension/community_design/design/suncana/stylesheets/star-rating.css
extension/community_design/design/suncana/stylesheets/syntax_and_custom_tags.css
extension/community_design/design/suncana/stylesheets/buttons.css
extension/community_design/design/suncana/stylesheets/tweetbox.css
extension/community_design/design/suncana/stylesheets/jquery.fancybox-1.3.4.css
extension/bcsmoothgallery/design/standard/stylesheets/magnific-popup.css
extension/sevenx/design/simple/stylesheets/star_rating.css
extension/sevenx/design/simple/stylesheets/libs/fontawesome/css/all.min.css
extension/sevenx/design/simple/stylesheets/main.v02.css
extension/sevenx/design/simple/stylesheets/main.v02.res.css
JS0extension/ezjscore/design/standard/lib/yui/3.17.2/build/yui/yui-min.js
extension/ezjscore/design/standard/javascript/jquery-3.7.0.min.js
extension/community_design/design/suncana/javascript/jquery.ui.core.min.js
extension/community_design/design/suncana/javascript/jquery.ui.widget.min.js
extension/community_design/design/suncana/javascript/jquery.easing.1.3.js
extension/community_design/design/suncana/javascript/jquery.ui.tabs.js
extension/community_design/design/suncana/javascript/jquery.hoverIntent.min.js
extension/community_design/design/suncana/javascript/jquery.popmenu.js
extension/community_design/design/suncana/javascript/jScrollPane.js
extension/community_design/design/suncana/javascript/jquery.mousewheel.js
extension/community_design/design/suncana/javascript/jquery.cycle.all.js
extension/sevenx/design/simple/javascript/jquery.scrollTo.js
extension/community_design/design/suncana/javascript/jquery.cookie.js
extension/community_design/design/suncana/javascript/ezstarrating_jquery.js
extension/community_design/design/suncana/javascript/jquery.initboxes.js
extension/community_design/design/suncana/javascript/app.js
extension/community_design/design/suncana/javascript/twitterwidget.js
extension/community_design/design/suncana/javascript/community.js
extension/community_design/design/suncana/javascript/roadmap.js
extension/community_design/design/suncana/javascript/ez.js
extension/community_design/design/suncana/javascript/ezshareevents.js
extension/sevenx/design/simple/javascript/main.js

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1pagelayout.tpl<No override>extension/sevenx/design/simple/templates/pagelayout.tplEdit templateOverride template
 Number of times templates used: 1
 Number of unique templates used: 1

Time used to render debug report: 0.0001 secs