Security Problem ?

Author Message

Heiner Wurbs

Thursday 09 November 2006 9:09:08 am

I have a question concerning the security of documents inside the storage directory.

I can access them via URL:
http://www.my-site.de/var/mysite/storage/original/application/.....

Can we avoid this with the mod_rewrite ?

Heiner

Claudia Kosny

Thursday 09 November 2006 9:24:33 am

Hello Heiner

As far as I know this should have been forbidden by the lines

<FilesMatch ".">
order allow,deny
deny from all
</FilesMatch>

in the default htaccess.

Regards

Claudia

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 11:12:11
Script start
Timing: Jan 18 2025 11:12:11
Module start 'layout'
Timing: Jan 18 2025 11:12:11
Module start 'content'
Timing: Jan 18 2025 11:12:12
Module end 'content'
Timing: Jan 18 2025 11:12:12
Script end

Main resources:

Total runtime0.7114 sec
Peak memory usage4,096.0000 KB
Database Queries54

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0056 588.9141152.6094
Module start 'layout' 0.00560.0036 741.523439.4297
Module start 'content' 0.00930.7005 780.9531457.9688
Module end 'content' 0.70980.0016 1,238.92198.1875
Script end 0.7113  1,247.1094 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00340.4820160.0002
Check MTime0.00150.2109160.0001
Mysql Total
Database connection0.00060.079410.0006
Mysqli_queries0.658992.6200540.0122
Looping result0.00060.0780520.0000
Template Total0.666693.720.3333
Template load0.00240.341920.0012
Template processing0.664293.361720.3321
Template load and register function0.00050.069010.0005
states
state_id_array0.00160.227410.0016
state_identifier_array0.00100.138220.0005
Override
Cache load0.00210.3012150.0001
Sytem overhead
Fetch class attribute can translate value0.00070.096220.0003
Fetch class attribute name0.00200.286620.0010
XML
Image XML parsing0.00030.043220.0002
class_abstraction
Instantiating content class attribute0.00000.000920.0000
General
dbfile0.00070.0956100.0001
String conversion0.00000.001840.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
2content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
4content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
1content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
1content/datatype/view/ezxmltags/literal.tpl<No override>extension/community/design/standard/templates/content/datatype/view/ezxmltags/literal.tplEdit templateOverride template
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 10
 Number of unique templates used: 6

Time used to render debug report: 0.0001 secs