Print Topic - Archive

E-Blah Community  /  News  /  Platinum 9 Security Warning
Posted by: Justin, October 28, 2005, 4:07pm
On some servers you can access the member files directly via going to their data file (username.dat).  In previous versions a .htaccess file was added into the install so no ones accounts could ever be compromised.  However, with Platinum 9, I forgot to add this file so some servers may be at risk.  To fix this problem upload the attached unzipped file to the following directories:

/Members/
/Boards/
/Prefs/
/Messages/
/Code/
/Languages/
/Mods/

On most servers, files inside the CGI-BIN are, by default, protected.  Not all servers are like this, though.

Please note that this ONLY works on Apache web servers.  If you are not on an Apache web server you should contact your host on how to disable access to these directories from the web or move them to an area that is not located in the /www/ directory (one that can be seen by others).

Sorry about the problems this may cause...
Posted by: ricardogz, November 18, 2005, 2:28pm; Reply: 1
Also upload to the subdirectories?
Posted by: Craig, November 19, 2005, 3:23am; Reply: 2
Yeah, you need to add this to BHITS, HITS, and the English directory under Languages.
Posted by: Tim Linden, January 19, 2006, 8:48pm; Reply: 3
Umm..  Someone forgot something..  It's "Deny from all" - not "Deny all". You may not notice, but it spewed errors in my error log. You may not have noticed cuz mod rewrite will try to change the url anyways.. (at least it is on mine)
Posted by: Craig, January 22, 2006, 1:53am; Reply: 4
hmmm...that is interesting.  All E-Blah releases including 9.6 have .htacess files that say deny all.

Justin, you may want to change this :P.
Posted by: sundance, January 22, 2006, 6:31am; Reply: 5
If anyone is interested... I had eBlah .htaccess files dating back to Nov 2004 saying "Deny all".
Posted by: Justin, January 22, 2006, 9:12am; Reply: 6
Quoted from sundance
If anyone is interested... I had eBlah .htaccess files dating back to Nov 2004 saying "Deny all".


Yeah, old versions had the .htaccess files included.
Print page generated: December 3, 2008, 2:54pm