Kayako logo
SupportSuite, eSupport and LiveResponse Discussion, troubleshooting and feedback related to Kayako's flagship support desk products SupportSuite, eSupport and LiveResponse.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  (#1) Old
BigDawgRob Offline
Member
 
Posts: 82
Join Date: May 2006
Location: Luton, UK
Security Audit of Document Root - 15-02-2007, 05:54 PM

Hi,

I'm currently reviewing my Kayako server against 'Essential PHP Security' (http://www.oreilly.com/catalog/phpsec/). One recommendation is that:

Quote:
In order to prevent backdoor URLs, make sure you store your includes out of document root. The only files that should be stored within document root are those that absolutely must be accessible via URL.
I note that Kayako stores all it's files in the document root. Does anyone have any comments of if they feel the above quote is relevent to Kayako or any tips of how to avoid security breaches of this nature?

Thanks,
Rob
   
Reply With Quote
  (#2) Old
bear Offline
Community Moderator
 
Posts: 677
Join Date: Jan 2005
16-02-2007, 04:30 PM

I don't know as much as I'd like about security, but having them in the "www" directory means that on many systems folks could see them from inside the server if they had sufficient access, so, yes, it's a problem. Of course, if someone has that sort of access you have some issues anyway...
   
Reply With Quote
Reply

Tags
audit, document, root

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Spell Checker Failure. Darren SupportSuite, eSupport and LiveResponse 23 30-10-2006 05:06 PM
Successful install on Debian Stable Mike_eQuest Installation & Upgrading 1 13-06-2006 02:23 PM



Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46