Results 1 to 6 of 6
  1. #1
    Join Date
    Feb 2004
    Location
    Georgia, USA
    Posts
    1,948
    Plugin Contributions
    0

    Default .htaccess problems with media previews in music products

    I am wondering if there is a better solution to provide similar security offer by the different .htaccess included with 1.3.9.

    At the moment the new .htaccess is causing more headaches than helping.

    I just noticed in our log today that the server was filling up with errors like:

    [error] [client 61.135.249.120] client denied by server configuration: /***/media/csmus0901/8.wma

    The problem is resulting from the new .htaccess file in media folder.

    This line
    Code:
    <FilesMatch ".*\.(js|css|jpg|gif|png|html)$">
    must be adjusted to accommodate for all possible file types that could be in any of the giving folder that is using this new .htaccess file

    So for example, in the media folder one needs to add things like wma, ra, rm, ram, etc.

    I think there should be a note in the installation guide to warning users about this.

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: 1.3.9A Breaks FCKEditor?

    Quote Originally Posted by BlessIsaacola View Post
    the new .htaccess file in media folder.

    This line
    Code:
    <FilesMatch ".*\.(js|css|jpg|gif|png|html)$">
    must be adjusted to accommodate for all possible file types that could be in any of the giving folder that is using this new .htaccess file

    So for example, in the media folder one needs to add things like wma, ra, rm, ram, etc.
    Yes, that is correct, as explained inside the .htaccess file itself.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Feb 2004
    Location
    Georgia, USA
    Posts
    1,948
    Plugin Contributions
    0

    Default Re: 1.3.9A Breaks FCKEditor?

    Quote Originally Posted by DrByte View Post
    Yes, that is correct, as explained inside the .htaccess file itself.
    DrByte, I completely understand! Is there an alternative situation to secure some of those folders like media that's doesn't require manual intervention. The thought of remembering to update the .htaccess file with new file types for the different folder is too much for my brain :) I guess a person could take the time and add all possible file type that could be in a specific folder now and in the future.

    Well, at least the solution is an easy one to get things moving along. I am just glad I was checking the server log today to see all the customers we were frustrating.

  4. #4
    Join Date
    Feb 2004
    Location
    Simcoe, Ontario, Canada
    Posts
    2,479
    Plugin Contributions
    1

    Default Re: 1.3.9A Breaks FCKEditor?

    BlessIsaacola, as you requested that I look into this via another post, I agree with DrByte.

    You will need to make the file extention additions if you are adding non stock items. I wish there was a better way of this but it seems this is the best way to do it for right now. Give it some time and a new better way could be incorporated in the future.

    Security is a finiky thing and is never ending. The idea of denying everything and only accepting certain files is a very secure method and is widely used in cisco hardware and firewalls among many others.

    It can be a pain in the bum and redundant...but, when it comes down to being hacked; this little thing could be your savior.
    Windows, BSD, Linux, Cisco, Hardware & IT Security Tech
    GeekHost - Zen Cart Certified & PCI Compliant Hosting

    Qdixon's Security Blog

  5. #5
    Join Date
    Feb 2004
    Location
    Georgia, USA
    Posts
    1,948
    Plugin Contributions
    0

    Default Re: 1.3.9A Breaks FCKEditor?

    Thanks to both of you for the prompt responses. One last question.

    If I have folders like:

    media/music
    media/video/
    media/books/

    do I just put the .htaccess in media folder and it will apply to all sub-folders or do I have to do each sub-folder as well?

    Thanks!

  6. #6
    Join Date
    Feb 2004
    Location
    Simcoe, Ontario, Canada
    Posts
    2,479
    Plugin Contributions
    1

    Default Re: 1.3.9A Breaks FCKEditor?

    Htaccess will cover subfolders
    Windows, BSD, Linux, Cisco, Hardware & IT Security Tech
    GeekHost - Zen Cart Certified & PCI Compliant Hosting

    Qdixon's Security Blog

 

 

Similar Threads

  1. v139h Music Samples with Media Manager
    By Lowell37 in forum Setting Up Categories, Products, Attributes
    Replies: 10
    Last Post: 17 Mar 2012, 04:19 AM
  2. Can I add MP3 music previews to my products?
    By raunharman in forum Setting Up Categories, Products, Attributes
    Replies: 0
    Last Post: 29 Dec 2008, 12:50 PM
  3. Music previews
    By uncletadd in forum Setting Up Categories, Products, Attributes
    Replies: 2
    Last Post: 23 Jan 2008, 04:55 PM
  4. Music previews not working
    By steveedge in forum General Questions
    Replies: 3
    Last Post: 10 Jul 2007, 05:21 AM
  5. Replies: 1
    Last Post: 9 Feb 2007, 03:48 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR