1% of CMS-Powered Sites Expose Their Database Passwords (2011)
21–30 of 94 posts
Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#22While this is bad of course, you also would have to allow network access to your mysql from remote ips. Which if allowed is even more stupid. If you run mysql only locally then do skip-networking and if you have to have networking restrict the ips it's allowed from. If they can use the mysql password locally, well then you have far bigger problems with security than mysql and exposed php configuration files.
Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#23Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#24How utterly stupid do you have to be to engineer software that requires you to have configuration files in a publicly accessible folder? Even most shared hosts now will have a public_html folder and the ability to put sensitive stuff not inside it. The .htaccess hacks are great but they are just patching the symptom, and one slip up and you're back to square one. The best way to do configuration is to have it in envi…
Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#25Quite an old issue (2011), did anybody run the script to see if as many sites still publicly expose these files?
Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#26The title of the linked post is 1% of CMS-Powered Sites Expose Their Database Passwords - has it changed since submission?
Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#27Order allow,deny Deny from all
What would be the equivalent of this for Nginx?
Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#28Some things never change.
Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#29 "If the text editor crashes or the SSH connection drops during editing"
What about the time of editing? During that time, the temp files exist. Are they readably? I would guess so. So even if you just edit them and have to crash, you are vurnurable.Re: 1% of CMS-Powered Sites Expose Their Database Passwords (2011)
#30The title of the linked post is 1% of CMS-Powered Sites Expose Their Database Passwords - has it changed since submission?
Could be HN mod editorialising at work