Results 1 to 3 of 3
  1. #1
    Join Date
    Oct 2010
    Posts
    7
    Plugin Contributions
    0

    Default htaccess file in the main directory (custom question)

    Hi.

    Zencart ver 1.3.9h
    Payment addon
    CAPTCHA TTF addon by RLEXYD

    I know, that htaccess file ain't in the main directory of zencart, because the security is sufficient without it.

    The problem is, when I added 2 addons (CAPTCHA + payment module), 4 custom .php files reside in the main shop directory.

    Do I need to protect these files by using htaccess file? If so, how should it be done?

    The payment module .php file might contain custom admin directory name. All the files are chmoded 644. The captcha files are debug, info and test. Can these files reside there without any risk?

    Thanks in advance.

  2. #2
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: htaccess file in the main directory (custom question)

    There is no security you can provide for these files using an .htaccess file, although, having a payment file within main shop dir. is definitely odd; should be in the Admin dir. at the very least. You'll have to depend upon the Server security established by your Hoster.

  3. #3
    Join Date
    Oct 2010
    Posts
    7
    Plugin Contributions
    0

    Default Re: htaccess file in the main directory (custom question)

    The file doesn't do anything else than collect information from the payment processor and redirect to checkout_success or checkout_error pages.

    The main payment files are in the includes/modules/payment/ directory.

    The payment file in the main dir has my admin directory information, but to prevent that, I've just added a new require to includes/configure.php which points to the admin dir. Then added the DIR_WS_ADMIN2 to the payment files instead of raw admin dir name.

    I guess it doesn't have to do anything with the security, or maybe it's better to make a file which will execute the hidden file in the includes directory? That's confusing.

 

 

Similar Threads

  1. .htaccess file for root directory needed
    By samar777 in forum Installing on a Linux/Unix Server
    Replies: 4
    Last Post: 28 Jul 2010, 03:13 AM
  2. .htaccess file in root directory- yes or no?
    By ttoonz in forum Installing on a Linux/Unix Server
    Replies: 6
    Last Post: 25 Nov 2008, 01:45 PM
  3. Question about file/ directory paths
    By chillout_buddha in forum General Questions
    Replies: 3
    Last Post: 2 Sep 2008, 03:16 AM
  4. Replies: 6
    Last Post: 23 Oct 2007, 06:28 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR