Posting in the Magento forums has been disabled pending the implementation of a new and improved forum solution which should better serve the community.

For new questions please post at magento.stackexchange.com, the community-run support site for the Magento community. We will be providing updates on the new forum solution soon. For questions or concerns please email community@magento.com.

Magento Forum

how to prevent web access of /app/etc/local.xml file? 
 
qfmomen
Jr. Member
 
Total Posts:  3
Joined:  2009-12-22
 

I have installed on IIS and i can see app/etc/local.xml file in web browser? .htaccess is in the app folder and it says

Order deny,allow
Deny from all

Does this mean tha .htaccess is igonred when installation is done on IIS?

Is there any solution? keep in mind that the installation is done BY IIS.

Thanks

 
Magento Community Magento Community
Magento Community
Magento Community
 
bigphil
Jr. Member
 
Total Posts:  2
Joined:  2008-10-11
 

Yes, IIS doesn’t listen to .htaccess files. You need to block the file using the IIS URL rewrite module (available from www.iis.net), or through IIS request filtering...the former being the best solution. I am in the process of writing an article on the proper way to go about installing Magento on IIS 7/7.5 as well as properly securing it. I’ll post the article on this sight soon!

 
Magento Community Magento Community
Magento Community
Magento Community
Magento Community
Magento Community
Back to top