Results 1 to 6 of 6

Hybrid View

  1. #1
    Join Date
    Mar 2007
    Posts
    3
    Plugin Contributions
    0

    application error Still able to write to configure file!!!!!!

    Warning: I am able to write to the configuration file: /services/webpages/s/p/public/Store/zen-cart-v1.3.7-full-fileset-/includes/configure.php. This is a potential security risk - please set the right user permissions on this file (read-only, CHMOD 644 or 444 are typical). You may need to use your webhost control panel/file-manager to change the permissions effectively. Contact your webhost for assistance.
    I have set the right permissions to 644,444,and 400 on FTP and File manger and I have been in contact with my web host who says everything is good on there end check the Zen FAQ. Could this have anything to do with the fact that my public an secure are linked? How do I stop this from viewing?

  2. #2
    Join Date
    Aug 2004
    Location
    New York City
    Posts
    7,174
    Plugin Contributions
    0

    Default Re: Still able to write to configure file!!!!!!

    Check the permissions using your file manager. The change didn't take or Zen Cart wouldn't be warning you. Simply removing the message won't fix the security problem.
    Mary Ellen
    I came; I saw; I Zenned
    Taking over the world... one website at a time
    Make sure brain is engaged before putting mouth in gear... or fingers to keyboard.

    Holzheimer
    Fan Odyssey

  3. #3
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Still able to write to configure file!!!!!!

    If you're absolutely convinced that there is no security risk in leaving that file's permissions as-is, then you can turn off the warning by following this:
    http://www.zen-cart.com/forum/showth...384#post341936
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  4. #4
    Join Date
    Mar 2007
    Posts
    3
    Plugin Contributions
    0

    Default Re: Still able to write to configure file!!!!!!

    Hello,
    I am not totally convinced. What I do know is that when I view or change the configure files in file manger on my web host it indicates whatever changes I make wether they be a 400, 444, 644, or 777. These changes are also aparent in file manager when I make the changes using FTP. Why is it that when I change admin/ includes/ cofigure to 400, 444, 644, or 777 this warning message does not show for that cofigure file. When I got rid of the zc_install file that warning message went away, but never did I see one for the admin/ includes/ configure.

  5. #5
    Join Date
    Jan 2004
    Posts
    66,443
    Plugin Contributions
    279

    Default Re: Still able to write to configure file!!!!!!

    Quote Originally Posted by bottleburner View Post
    but never did I see one for the admin/ includes/ configure.
    Zen Cart only shows the warning on the store-front.
    Right or wrong, it presently assumes that you'll set it properly because of the warning on the storefront and the documented instructions during and after installation.

    The warning may be added to the admin as well in a future release.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  6. #6
    Join Date
    Mar 2007
    Posts
    3
    Plugin Contributions
    0

    Default Re: Still able to write to configure file!!!!!!

    Thanks for the info your post on ridding the message worked well and my host assured me that the sight is secure.

 

 

Similar Threads

  1. Replies: 2
    Last Post: 28 Mar 2013, 10:53 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg