*.ini.append.php~ backups & admin interface

Author Message

Vjeran Vlahovic

Sunday 12 June 2005 4:04:57 pm

Hi,
When I edit ini files trough administration interface, backups are being created on the server. This could be considered as a security issue, because such files can be easily accessed on poorly configured virtual hosts, e.g: http://www.ezsite.com/settings/siteacces/en/site.ini.append.php~

Is there a way to turn this off?

Thanks, Vjeran

http://www.netgen.hr/eng

Ɓukasz Serwatka

Monday 13 June 2005 12:45:11 am

Hi Vjeran,

Yes, this is problem on poorly configured VH. We will look in to this issue. Replacing name with ~ at the end to site.ini.append.old.php for example.

Personal website -> http://serwatka.net
Blog (about eZ Publish) -> http://serwatka.net/blog

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 19 2025 11:43:09
Script start
Timing: Jan 19 2025 11:43:09
Module start 'layout'
Timing: Jan 19 2025 11:43:09
Module start 'content'
Timing: Jan 19 2025 11:43:10
Module end 'content'
Timing: Jan 19 2025 11:43:10
Script end

Main resources:

Total runtime0.8506 sec
Peak memory usage4,096.0000 KB
Database Queries54

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0086 589.2969152.6406
Module start 'layout' 0.00860.0035 741.937539.4766
Module start 'content' 0.01210.8370 781.4141531.3672
Module end 'content' 0.84910.0014 1,312.78138.2813
Script end 0.8505  1,321.0625 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00370.4318160.0002
Check MTime0.00140.1665160.0001
Mysql Total
Database connection0.00150.179910.0015
Mysqli_queries0.793593.2869540.0147
Looping result0.00060.0755520.0000
Template Total0.809795.220.4049
Template load0.00240.284620.0012
Template processing0.807394.907220.4036
Template load and register function0.00010.014310.0001
states
state_id_array0.00140.168310.0014
state_identifier_array0.00160.184220.0008
Override
Cache load0.00190.2196120.0002
Sytem overhead
Fetch class attribute can translate value0.00210.252220.0011
Fetch class attribute name0.00200.233040.0005
XML
Image XML parsing0.00480.562120.0024
class_abstraction
Instantiating content class attribute0.00000.001040.0000
General
dbfile0.00310.3678250.0001
String conversion0.00000.001140.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
2content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
2content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
1content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
2content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 9
 Number of unique templates used: 6

Time used to render debug report: 0.0001 secs