IMPORTANT Security Alert: Remove extra folders from your server after install
In a standard Zen Cart install, there are a few additional folders provided which DO NOT need to be uploaded to your live webserver.
In fact, leaving the files in those folders on your server can pose some security risks if not used as intended.
While most of the risks are minor in that attempting to access some of those files/scripts/documentation could reveal some information about your server which might allow more sophisticated hack "probing" to occur, there are some more significant risks including unauthorized access to information on your server or even "accidental" wipe of your whole database in the case of the zc_install folder being left online.
So, it's important that after you've installed your site and are satisfied that it's working properly, including actually doing live transactions to test ALL the payment and shipping modules you're using on your site, be sure to do some cleanup:
REMOVE THE FOLLOWING FOLDERS (and all the files inside them), TO MINIMIZE SECURITY RISKS:
- /install.txt (this file can be removed, too)
It is safe to keep these files on your own computer, since they can be used as references/documentation, or used to aid in troubleshooting as diagnostic tools, or for upgrading/installing again in the future. But those folders/files should *not* be on a live webserver.
Additionally, *IF* you have no intentions of supporting downloadable products or music-media products, you can *also* remove these folders:
(And you'll need to go to your Admin->Configuration->Attribute Settings->Enable Downloads, and set it to False to turn off the warning message about the missing download folder)
In the future, if you choose to add downloadable products to your site or music-products, you will want to re-upload these appropriate folders (and their contents) to your server again, and assign appropriate permissions. (See FAQ are for appropriate permissions instructions.)
Zen Cart - putting the dream of business ownership within reach of anyone!
Donate to: DrByte directly or to the Zen Cart team as a whole
Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.
By Laki in forum General Questions
Last Post: 27 Nov 2015, 03:49 PM
By Loter in forum Setting Up Categories, Products, Attributes
Last Post: 31 Jan 2010, 06:22 PM
Content and Graphics Copyright (c) 2003 - 2017 Zen Ventures, LLC - all rights reserved
Zen Cart® is a Registered Trademark of Zen Ventures, LLC