Results 1 to 4 of 4
  1. #1
    Join Date
    Jun 2008
    Posts
    328
    Plugin Contributions
    0

    help question http://<www.domain.com>/editors/htmlarea/ world readable - a problem?

    While implementing the latest security patch, I discovered that two of my subdirectories seem to be not protected by .htaccess and thus instead of producing a blank web page, it produces a "live" web page (with content, links, etc.).

    The two subdirectories are:
    1. /editors/htmlarea/
    2. /editors/htmlarea/examples/

    I checked some other zen-cart based stores on the web to see if they exhibit the same behavior and they do (i.e. this seems to be zen-cart's default, not specific to my site).

    Is this a potential security problem?

    Or is this by design?


    Thanks.

  2. #2
    Join Date
    Nov 2007
    Location
    Woodbine, Georgia, United States
    Posts
    4,024
    Plugin Contributions
    61

    Default Re: http://<www.domain.com>/editors/htmlarea/ world readable - a problem?

    Ideally, this folder should be no more than 755 for compliance.... At least put a blank index.html file in them.

    ~Melanie
    PRO-Webs, Inc. :: Recent Zen Cart Projects :: Zen Cart SEO – 12 Steps to Success
    **I answer questions in the forum, private messages are NOT answered. You are welcome to contact us via our website for professional engagements.

  3. #3
    Join Date
    Jun 2008
    Posts
    328
    Plugin Contributions
    0

    help question Re: http://<www.domain.com>/editors/htmlarea/ world readable - a problem?

    Quote Originally Posted by mprough View Post
    Ideally, this folder should be no more than 755 for compliance.... At least put a blank index.html file in them.
    These two folders do have 755 permissions. But their index.html is not blank.

    I am afraid that if I put a blank index.html in them (instead of the functional ones) I may break some Zen-Cart functionality (probably in the Admin). That's why I am asking.

    Pick randomly any store in the "Live Showcase Shops" section, append /editors/htmlarea/ to their base URL - and you will see a non-blank html... Is this benign?

  4. #4
    Join Date
    Nov 2007
    Location
    Woodbine, Georgia, United States
    Posts
    4,024
    Plugin Contributions
    61

    Default Re: http://<www.domain.com>/editors/htmlarea/ world readable - a problem?

    Blank or not if an index files exists the directory cannot be browsed....

    ~Melanie
    PRO-Webs, Inc. :: Recent Zen Cart Projects :: Zen Cart SEO – 12 Steps to Success
    **I answer questions in the forum, private messages are NOT answered. You are welcome to contact us via our website for professional engagements.

 

 

Similar Threads

  1. Problem with pointing to http://www.mydomain.com
    By lindanewbie in forum Basic Configuration
    Replies: 1
    Last Post: 7 Mar 2011, 10:36 AM
  2. Replies: 6
    Last Post: 18 Aug 2010, 10:32 PM
  3. Help My domain rewrites to http://domain.com instead of www
    By toussi in forum Installing on a Linux/Unix Server
    Replies: 3
    Last Post: 21 Aug 2008, 03:55 AM
  4. SSL problems (www.domain.com vs. domain.com)
    By Kevad in forum General Questions
    Replies: 3
    Last Post: 28 Apr 2007, 01:01 AM
  5. http://www.domain.com or http://domain.com
    By mydanilo in forum General Questions
    Replies: 3
    Last Post: 13 Apr 2007, 08:36 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR