Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Big security issue
#1
my site has indexing security issue and im guess same for everyone else. people are adle to see my index files, can you added something like Cpanel were if i:

1.log in cpanel
2.then find advanced
3.then find index manager
4. find where find are on hosting
5.No Indexing and save
6. you cud be done run test wiv old links
The Index Manager allows you to customize the way a directory will be viewed on the web. You can select between a default style, no indexes, or two types of indexing. If you do not wish for people to be able to see the files in your directory, choose no indexing.



Restored from old drupal forum, for user uid:3160 username:budgierless
You may reset your password to access your new account here.
Reply
#2
this can be done by adding an apache directive to ehcp gui->choose domain->edit apache template.


Restored from old drupal forum, for user uid:3160 username:budgierless
You may reset your password to access your new account here.
Reply
#3
sorry but i don't know what to do, it was my friend what found the problem, what & how do i need to edit the apache template please?

Restored from old drupal forum, for user uid:1 username:ehcpdeveloper
You may reset your password to access your new account here.
Reply
#4
Options -Indexes

put this in "edit apache template"
please consult on apache documentation for detailed info.

Restored from old drupal forum, for user uid:3160 username:budgierless
You may reset your password to access your new account here.
Reply
#5
i could not find any information about this on the Apache website.

were in the template should i add "-indexes" before or after what line of code?

Restored from old drupal forum, for user uid:1 username:ehcpdeveloper
You may reset your password to access your new account here.
Reply
#6
you can add it under:
Domain Operations
Custom http:Add



Restored from old drupal forum, for user uid:3160 username:budgierless
You may reset your password to access your new account here.
Reply
#7
That did not work for me, below you we see were i put it, tell me what is wrong please.



#____________start of {domainname}__paneluser:{panelusername}_reseller:{reseller}_id:{id}____________
# explanation {aciklama}

<VirtualHost *>
ServerName {domainname}
ServerAlias www.{domainname}
# buraya aliaslar yazilacak..
{aliases}

UseCanonicalName Off
DocumentRoot {homedir}/httpdocs
ScriptAlias /cgi-bin/ {homedir}/httpdocs/cgi-bin/

# this combined log format is understandable by webalizer... some other formats are not recognised by webalizer.. thats why, specified here explicitly..

LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
LogFormat "%v:%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
CustomLog {homedir}/logs/access_log combined
CustomLog /var/log/apache_common_access_log vhost_combined

php_admin_value open_basedir {homedir}
php_admin_value upload_tmp_dir {homedir}/phptmpdir
php_admin_value session.save_path {homedir}/phptmpdir

AccessFileName .htaccess

<Directory {homedir}>
AllowOverride all
</Directory>


{customhttp}
-Indexes <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< THIS IS WERE I ADDED!!!!
</VirtualHost>

<VirtualHost *>
ServerName webmail.{domainname}
ServerAlias mail.{domainname}
ServerAlias email.{domainname}

DocumentRoot /var/www/vhosts/ehcp/webmail

LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
LogFormat "%v:%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
CustomLog {homedir}/logs/access_log combined
CustomLog /var/log/apache_common_access_log vhost_combined

php_admin_value open_basedir /var/www/vhosts/ehcp/webmail
php_admin_value upload_tmp_dir /var/www/vhosts/ehcp/webmail/data
php_admin_value session.save_path /var/www/vhosts/ehcp/webmail/data

</VirtualHost>


<VirtualHost *>
ServerName cpanel.{domainname}
ServerAlias panel.{domainname}
ServerAlias ehcp.{domainname}
ServerAlias cp.{domainname}

DocumentRoot /var/www/vhosts/ehcp/

LogFormat "%v:%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
CustomLog /var/log/apache_common_access_log vhost_combined

php_admin_value open_basedir /var/www/vhosts/ehcp/

</VirtualHost>

#____________end of {domainname}__paneluser:{panelusername}_reseller:{reseller}_id:{id}____________


Restored from old drupal forum, for user uid:133 username:Cool
You may reset your password to access your new account here.
Reply
#8
??

Restored from old drupal forum, for user uid:3160 username:budgierless
You may reset your password to access your new account here.
Reply
#9
if you want to disable for all domains
open apachetemplate file,

just below {customhttp}
add
Options -Indexes

then,
ehcp gui->options->sync domains.
(domains with custom apache template will not be affected. to reset them, just delete custom apache templates for domain)


to disable index for some domains,
click on "edit apache template"
just below {customhttp}
add
options -Indexes

it should work.


Restored from old drupal forum, for user uid:3160 username:budgierless
You may reset your password to access your new account here.
Reply
#10
oh i did not try it with the word: options, ok thanks, i will let you know if i still have problem.

Restored from old drupal forum, for user uid:1 username:ehcpdeveloper
You may reset your password to access your new account here.
Reply


Forum Jump:


Users browsing this thread: 3 Guest(s)

Online Shopping App
Online Shopping - E-Commerce Platform
Online Shopping - E-Commerce Platform
Feinunze Schmuck Jewelery Online Shopping