Magento Forum

   
config.xml
 
papimigas
Jr. Member
 
Avatar
Total Posts:  2
Joined:  2011-11-14
 

Hi.

This is my first time with this program rasberry
I’m using Magento 1.6.1, the most recent, with ubuntu 10.04 (apache2+mysql+php5).

Is there any way to stop acess from public to config.xml file?

I tried to change permissions to 551 but there’s still acess.

Obrigado,

PapiMigas

 
Magento Community Magento Community
Magento Community
Magento Community
 
thebod
Moderator
 
Avatar
Total Posts:  81
Joined:  2010-08-11
 

Hello,

first of all: which config.xml file do you mean?
The most important file ist the local.xml inside app/etc/, which includes the database config.

Every file inside app/, lib/, var/ (and some else) are blocked by htaccess-rules by default on apache servers. On nginx or other servers you probably must setup your own configuration to block access to these folders.

 
Magento Community Magento Community
Magento Community
Magento Community
 
papimigas
Jr. Member
 
Avatar
Total Posts:  2
Joined:  2011-11-14
 

Thank U very much for your reply.
That´s the .xml I’m talking about. And yes, is visible from outside and I understand the problem…
Do you know any good howto about Apache security so I can follow?
I swear I googled this matter.

Once more, thank’s for your attention.

PapiMigas

 
Magento Community Magento Community
Magento Community
Magento Community
 
thebod
Moderator
 
Avatar
Total Posts:  81
Joined:  2010-08-11
 

In fact it’s quite simple:

All you need is a .htaccess file which contains the following lines:
Order deny, allow
Deny from all
These file should block every external access.

If this won’t work take a look in your configuration. You need to set the AllowOverride-directive to “all”, and activate the mod_authz_host module.

Take a look here: http://httpd.apache.org/docs/2.2/mod/mod_authz_host.html

 
Magento Community Magento Community
Magento Community
Magento Community
 
goivvy
Guru
 
Avatar
Total Posts:  322
Joined:  2010-12-15
Moscow, Russia
 

on nginx you add

location /app/etc/local.xml {
                 deny all

                 return 
404;
         
}

 
Magento Community Magento Community
Magento Community
Magento Community
 
blau16
Member
 
Total Posts:  31
Joined:  2011-12-12
 

uh, that all sounds a little difficult for me....

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
    Back to top