Support

Admin Tools

#22552 .htaccess maker

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by dlb on Thursday, 30 April 2015 09:18 CDT

Lumiga
Hi,

I have a question about the .htaccess maker.

In your documentation you wrote that if you put a directory in the field [Allow direct access, including .php files, to these directories] you are opening a security hole on your site!

But is this hole already there when you use the standard Joomla .htaccess file provided during the installation? Or do I make it more unsecure to use .htaccess maker and fill in this URL which I want to use the exception for.

In my case:
templates/yoo_digit
cache/com_zoo/
cache/template/
cache/widgetkit/

Hope to hear from you.

Kind regards,
Lumiga

dlb
Lumiga,

The object is to minimize these security holes. Some of them are necessary to run your site properly. I recognize the ones on your site, they are needed. You are correct, some are already open just to run Joomla!. You can try to minimize the number of openings, but you can never close off everything.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Lumiga
Hi Dale,

So if I understand it correctly, these holes I make are not worse than already present with the standard Joomla .htaccess file. So it is always better to use the .htaccess maker?

Thanks!

dlb
Yes, .htaccess Maker has protections that the standard Joomla! .htaccess file does not have. So your site is more secure with the .htaccess Maker file. In your case, you need to open just a little hole to allow your template to work properly.

The Yoo guys have been told that they should not be using the cache folders like they do, they refuse to acknowledge the problem or to fix it.


Dale L. Brackin
Support Specialist


us.gifEnglish: native


Please keep in mind my timezone and cultural differences when reading my replies. Thank you!


????
My time zone is EST (UTC -5) (click here to see my current time in Philadelphia, PA)

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!