Page 1 of 2 12 LastLast
Results 1 to 10 of 16
  1. #1
    Join Date
    Jul 2007
    Location
    Sunny Cornwall
    Posts
    73
    Plugin Contributions
    0

    red flag Warning Message - I can write to configure.php

    I get the Warning: I am able to write to the configuration file: /home/fhlinux163/m/momentsstore.co.uk/user/htdocs/shop/includes/configure.php. This is a potential security risk - please set the right user permissions on this file (read-only, CHMOD 644 or 444 are typical). You may need to use your webhost control panel/file-manager to change the permissions effectively. Contact your webhost for assistance.

    I have checked my reard write status and it is set to 644.

    Any ideas Please

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Warning Message

    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  3. #3
    Join Date
    Jul 2007
    Location
    Sunny Cornwall
    Posts
    73
    Plugin Contributions
    0

    Default Re: Warning Message - I can write to configure.php

    Hi,

    Yes I tried 444 even got the web company (streamline) to do it,

    They tell me the server defaults to 664 which should be ok

    Sorry to be a pain

  4. #4
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Warning Message - I can write to configure.php

    Be warned that overriding that warning by turning off the alert does *not* protect the file from security risks. If you believe the file is safe, you can follow the instructions and warnings in this thread in order to suppress the warning message from being displayed.
    http://www.zen-cart.com/forum/showthread.php?t=44721
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Jul 2007
    Location
    Sunny Cornwall
    Posts
    73
    Plugin Contributions
    0

    Default Re: Warning Message - I can write to configure.php

    Hi,

    Many thanks for the info, I was wondering if anyone else using STREAMLINE had the same problem. Is there any other way to test the file to see what the setting for it is.

    Regards


  6. #6
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: Warning Message - I can write to configure.php

    That warning is telling you that PHP sees the file as writable.

    As for Streamline, do a forum search for *streamline* (with the *'s) for some interesting reading.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  7. #7
    Join Date
    Jul 2007
    Location
    Sunny Cornwall
    Posts
    73
    Plugin Contributions
    0

    Default Re: Warning Message - I can write to configure.php

    Hi, sorry to go around in circles but when I check the properties through my FTP program and FTP control pannel it does state that it is set to 644.

    I dont want to deactivate the message unless it is ok to do so

  8. #8
    Join Date
    Feb 2004
    Location
    Simcoe, Ontario, Canada
    Posts
    2,479
    Plugin Contributions
    1

    Default Re: Warning Message - I can write to configure.php

    Heed our advice over your host's advice.

    Some configurations need 444 and others 644.

    If the shopping cart shows the red bar saying to increase your chmod for security, it is very important to do so.

    Mine is always 444
    Windows, BSD, Linux, Cisco, Hardware & IT Security Tech
    GeekHost - Zen Cart Certified & PCI Compliant Hosting

    Qdixon's Security Blog

  9. #9
    Join Date
    Jul 2007
    Location
    Sunny Cornwall
    Posts
    73
    Plugin Contributions
    0

    Default Re: Warning Message - I can write to configure.php

    Hi,

    Streamline not very helpful with solving problem, but they did hint towards PuTTY and haypresto all is now good, Warning has gone.

  10. #10
    Join Date
    Dec 2007
    Posts
    25
    Plugin Contributions
    0

    Default Re: Warning Message - I can write to configure.php

    I also use STREAMLINE Grrrr I also had this message appear out of nowhere after being up online and fully functioning for two months! I think they tinkered at their end and it made it just appear. I submitted a support ticket to help fix the problem and all I got was a reply with a link to their tutorial that doesn't work like I needed it too. I have supressed the message so it doesn't show, while I wait for them to either do it for me or help me figure it out. Anyone reccomend a more helpful server service?

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Replies: 2
    Last Post: 28 Mar 2013, 10:53 PM
  2. Receiving can write to configure file warning.
    By awhfy99 in forum General Questions
    Replies: 1
    Last Post: 14 Aug 2010, 03:09 PM
  3. Security warning message: configure.php is writeable
    By sccr410 in forum General Questions
    Replies: 6
    Last Post: 11 Apr 2007, 01:41 AM
  4. Can't write configure.php
    By dtakle in forum Installing on a Windows Server
    Replies: 5
    Last Post: 11 Nov 2006, 08:06 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR