Results 1 to 5 of 5
  1. #1
    Join Date
    Jan 2007
    Location
    Victoria, BC, Canada
    Posts
    47
    Plugin Contributions
    0

    Default False Message about config file writable

    I am getting a security message on my site www.therasounds.com
    "Warning: I am able to write to the configuration file: /home/therscom/public_html/store/includes/configure.php. This is a potential security risk - please set the right user permissions on this file (read-only, CHMOD 644 or 444 are typical). You may need to use your webhost control panel/file-manager to change the permissions effectively. Contact your webhost for assistance."
    However, when I check both the configure .php are set to 644. Is this a bug or a breach?
    Keith

  2. #2
    Join Date
    Jan 2007
    Location
    Victoria, BC, Canada
    Posts
    47
    Plugin Contributions
    0

    Default Re: False Message

    Th host of my site asked that I change the CHMOD to 444. as they have changed to PHP 5.
    Sorry for the false alarm.

    Keith

  3. #3
    Join Date
    Jan 2007
    Location
    Victoria, BC, Canada
    Posts
    47
    Plugin Contributions
    0

    Default Re: False Message

    Just had a thought - does this mean I have to change all file that were 644 to 444? Please advise.

    Keith

  4. #4
    Join Date
    Mar 2004
    Posts
    16,042
    Plugin Contributions
    5

    Default Re: False Message

    No only that config file,
    Zen cart PCI compliant Hosting

  5. #5
    Join Date
    Jan 2007
    Location
    Victoria, BC, Canada
    Posts
    47
    Plugin Contributions
    0

    Default Re: False Message

    Thanks for the reassurance Merlinpa.

    Keith

 

 

Similar Threads

  1. v150 recurring message stating i need to install of fix config file
    By jolenemacinjax in forum General Questions
    Replies: 1
    Last Post: 22 Jul 2012, 05:02 AM
  2. non-writable configure file being flagged as writable
    By schwimwastaken in forum Installing on a Linux/Unix Server
    Replies: 1
    Last Post: 20 Jan 2010, 01:40 AM
  3. about config file
    By DarkAngel in forum General Questions
    Replies: 5
    Last Post: 7 Oct 2008, 01:45 AM
  4. SSL -- admin blank in secure, 'false' in config will not reset to http
    By fabrikation in forum Installing on a Linux/Unix Server
    Replies: 11
    Last Post: 18 Dec 2006, 05:03 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg