Support

Admin Tools

#9962 Noticed Unusual Directory and File - Thoughts?

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Saturday, 23 July 2011 12:48 CDT

user1146
This is a little strange so am interested in the opinions of the pros. This is a newer site still being worked on. Pretty good security practices in place thanks to Nicholas.

I just noticed a home directory in the public_html folder created about 10 days ago 755/644 on all, white page index.html file in there too, and when I drill down in it the path follows something like:

http://site_name.com/home/site_root/new_dir/other_new_dir/thumb_image_cache.jpg

What is odd is that the path:

/new_dir/other_new_dir was created in the site_root to keep files off the web like might be found in the tmp dir.

My instict is to delete it, but trying to understand how it got there. Could an extension create a path automatically if it had an asset it did not like being in the site_root? Sounds crazy just typing the question out.

Any input/feedback appreciated.

nicholas
Akeeba Staff
Manager
Not all extensions understand off-site paths. When they don't, this is what happens.

That said, it's not entirely the developers' fault. They are taught to stupidly use the Joomla! API. However, Joomla!'s own JFile and JFolder classes do NOT work with off-site paths (there are specific checks to make sure about that, for security reasons). Most developers don't know that and this is what you get.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user1146
Is there anything you don't know? (-:

Guess I'll just keep deleting stray folders until you straighten out the rest of the developers, and the problem is fixed once and for all.

When you going to lay down an mp3? (-;

nicholas
Akeeba Staff
Manager
Well, I know what I don't know and don't try pretending to know it ;)

Take a backup and start removing folders with caution. If you bump into any problem, you can extract the backup locally and copy back a filer you accidentally removed.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user1146
Thanks. So far so good. (-;

nicholas
Akeeba Staff
Manager
You're welcome!

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!