1
eireann
Sense of XOOPS_TRUST_PATH
  • 2008/10/6 0:03

  • eireann

  • Just popping in

  • Posts: 89

  • Since: 2008/8/21


Ghia wrote when talking about benefits of having that XOOPS_TRUST_PATHQuote:
If the hack means uploading php code to your site, then the hacker has all read abilities of XOOPS, what would stop him from reading your passwords?
Initially it was explained to me that the XOOPS_TRUST_PATH was so that hackers have a more difficult time with your page.
Ghia expressed it as if it want really true.
So, If the XOOPS_TRUST_PATH doesnt give that alleged protection against hackers....what is it for?

2
Mamba
Re: Sense of XOOPS_TRUST_PATH
  • 2008/10/6 0:43

  • Mamba

  • Moderator

  • Posts: 11366

  • Since: 2004/4/23


Ghia is of course right - once the hacker is inside and has access to your passwords, nothing can stop him. Trust_path is to make it more difficult to get into the system.

See here for more info...
Support XOOPS => DONATE
Use 2.5.10 | Docs | Modules | Bugs

3
eireann
Re: Sense of XOOPS_TRUST_PATH
  • 2008/10/6 0:47

  • eireann

  • Just popping in

  • Posts: 89

  • Since: 2008/8/21


I tried to access that page earlier on, but I still get:
Quote:
Forbidden

You don't have permission to access /news-article.storyid-108.htm on this server.

Any chance to put that info somewhere else so that I can read it again?
I just CHMODED the portal to 555 unticked "writing" and it still works fine. Previously I had it set to 755

4
Mamba
Re: Sense of XOOPS_TRUST_PATH
  • 2008/10/6 2:46

  • Mamba

  • Moderator

  • Posts: 11366

  • Since: 2004/4/23


OK, I've added the text to our FAQ
Support XOOPS => DONATE
Use 2.5.10 | Docs | Modules | Bugs

5
eireann
Re: Sense of XOOPS_TRUST_PATH
  • 2008/10/6 7:13

  • eireann

  • Just popping in

  • Posts: 89

  • Since: 2008/8/21


Great,
thanks a lot.
That means it is in fact a bit safer putting the passwords and data base names into the XOOPS_TRUST_PATH.

Well, just now I thought everything is safe when the host got hacked including my Cpanel.
I heard so many complains about that host 3ix. In the beginning I thought everything runs smoothly.
Now I found that 3ix is rubbish.

Login

Who's Online

209 user(s) are online (129 user(s) are browsing Support Forums)


Members: 0


Guests: 209


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits