Results 1 to 3 of 3
  1. #1
    Join Date
    Feb 2009
    Posts
    88
    Plugin Contributions
    1

    help question Are there .htaccess files for Apache 1.3 available for ZC 1.3.x?

    I've been asked to build a site for a customer, and based it on Zen Cart 1.3.9f, or g, or something very recent. I've spent some time developing it locally, come to deploy it to their web host, and found that they are hosting it with Fasthosts in the UK, who seem to give us Apache 1.3.

    As is quite well documented elsewhere, the .htaccess files that ship with Zen Cart are incompatible with Apache 1.3, and cause all sorts of 500 Internal Server Error messages and occasionally 404 File Not Founds. My initial workaround is simply to rename all .htaccess files.

    This obviously removes some important security concerns. I guess from what I've read that we are immediately at risk of some malicious behaviour. Is there a set of Apache 1.3 compatible .htaccess files available somewhere that we can drop in as a replacement?

    I really don't want to have to dig through each one and translate its directives to be compatible with 1.3. I feel I'm duplicating work that someone else may have already done.

    The debate about upgrading our web host to use Apache 2.x may take some time and for now I'd just like to get online with as little risk of being hacked as possible.

    Thanks
    Nick

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Are there .htaccess files for Apache 1.3 available for ZC 1.3.x?

    1. Fasthosts is a BAD choice. You'll have no end of problems if you intend to use SSL to protect your customers shopping experiences from prying eyes.
    2. Apache 1.3 is no longer supported, and is not PCI compliant. Why would you run a store on that anyway?
    3. That said, Zen Cart 1.3.x works fine with Apache 1.3. You just have to configure your apache to handle the security protections set up in the .htaccess files. Instructions are inside the .htaccess files.

    Do yourself a favour and get a better host before you even start. You'll regret it later if you don't.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Feb 2009
    Posts
    88
    Plugin Contributions
    1

    Default Re: Are there .htaccess files for Apache 1.3 available for ZC 1.3.x?

    Quote Originally Posted by DrByte View Post
    1. Fasthosts is a BAD choice. You'll have no end of problems if you intend to use SSL to protect your customers shopping experiences from prying eyes.
    I've read this elsewhere too. I'm used to a nice clean VPS environment, which fasthosts doesn't seem to provide.. running 'ps' and seeing lots of other website processes (and the command line details that expose their inner workings) does not fill me with confidence.

    I might have some trouble pushing a hosting move past my client, though.

    Quote Originally Posted by DrByte View Post
    2. Apache 1.3 is no longer supported, and is not PCI compliant. Why would you run a store on that anyway?
    If you mean Payment Card Industry, we do not actually intend to take any payments on this site. We are essentially running in showcase mode. However I take your point, and am horrified that they're running 1.3 at all. Amusingly, PHP on their box is at 5.2.6, which is at least recent enough to support ZC quite well.

    Quote Originally Posted by DrByte View Post
    3. That said, Zen Cart 1.3.x works fine with Apache 1.3. You just have to configure your apache to handle the security protections set up in the .htaccess files. Instructions are inside the .htaccess files.
    Yes, it is this digging through apache docs that I want to avoid.. I'm not familiar with the directives, it'll take me a while and I'm not being paid for this work. I've quoted fixed price to deliver a shop, not fiddle with their awful hosting platform :)

    I'll push to switch hosting asap. Thank you for your comments.
    Nick

 

 

Similar Threads

  1. Nginx equivalents for htaccess files
    By Dayo in forum Code Collaboration
    Replies: 6
    Last Post: 8 May 2016, 06:59 PM
  2. v155 Are htaccess files invisible
    By soxophoneplayer in forum Installing on a Linux/Unix Server
    Replies: 2
    Last Post: 8 Apr 2016, 09:39 PM
  3. Replies: 2
    Last Post: 29 Dec 2012, 12:15 AM
  4. My .htaccess files are restricting access to my images
    By Elly in forum Templates, Stylesheets, Page Layout
    Replies: 8
    Last Post: 24 May 2011, 11:25 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR