Results 1 to 6 of 6
  1. #1
    Join Date
    Feb 2006
    Posts
    37
    Plugin Contributions
    0

    Default renaming configure.php

    As I don't have access to the root level of my server (without contacting my hosting provider) and not being able to set configure.php to read-only, I was wondering whether or not I would be able to rename configure.php making it harder for a would-be attacker to target my site.

    Is this possible? If not can anyone else suggest a method of protection for a hosting account on a Windows shared server?

    Thanks,
    S

  2. #2
    Join Date
    Aug 2005
    Location
    Arizona
    Posts
    27,761
    Plugin Contributions
    9

    Default Re: renaming configure.php

    You have FTP correct??

    I believe that you can FTP it to your win local change it to RO there and FTP it back
    Zen-Venom Get Bitten

  3. #3
    Join Date
    Feb 2006
    Posts
    37
    Plugin Contributions
    0

    Default Re: renaming configure.php

    That doesn't work. I have tried setting the IUSR account setting to read only but it does nothing. I am running WAMP server locally but my actual domain will be hosted on Windows.

    So my original query...can configure.php be renamed?

  4. #4
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: renaming configure.php

    Quote Originally Posted by g1media View Post
    So my original query...can configure.php be renamed?
    If you rename it, then you have to alter all the core code locations that reference it to use the new name.
    Renaming doesn't solve the problem of the file being writable and thus editable and your site defacable and database-connection breakable if someone were to break in.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Feb 2006
    Posts
    37
    Plugin Contributions
    0

    Default Re: renaming configure.php

    but what are the chances of someone guessing what the file is now called?

    so, other than accessing IIS at server level, there's no way to secure this file on Windows?

  6. #6
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: renaming configure.php

    If PHP discovers the configure.php files to be writable, you will continue to see warnings.
    If you feel the security risk is minimal or moot, you can customize code to either bypass the warnings or look for the configure.php files by a different name. Feel free to do as you wish.

    Setting file/folder permissions on Windows hosting, esp with IIS, has always been a problem.
    If your hosting company cannot give you the control you need to secure your site (not just the configure.php files), then perhaps you should consider other hosting options.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. Replies: 9
    Last Post: 1 Sep 2012, 03:13 AM
  2. renaming dist-configure.php
    By Millielou in forum Installing on a Windows Server
    Replies: 4
    Last Post: 28 Apr 2011, 06:18 PM
  3. Can't rename dist-configure.php because there is already a configure.php
    By mamasylvia in forum Installing on a Linux/Unix Server
    Replies: 1
    Last Post: 17 Mar 2008, 06:57 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR