SymLinks and security concerns - Joomla! Forum - community, help and support
two of sites got hacked (1.5 , 2.5 joomlas) , traced down symlinks requirement joomla site run (as set in .htaccess). seems enabling symlinks major , known security risk.
as working our host patch hole , recover sites have ask... why joomla need this? , isn't there safe workaround?
thanks
as working our host patch hole , recover sites have ask... why joomla need this? , isn't there safe workaround?
thanks
first short answer - enabled symlink option needed in older versions sorts of sef. turn off , test sites functionality, if working expected without "option +symlink",or better "option -symlink" explicitly disable it.
but, don't consider primary issue facing - happens crackers plant symlinks on infested sites - should go further , identify vulnerability led infestation of site. did identify way able plant symlink?
also, on sites saw infected symlinks there additional injected files, advisable quick scan jamss viewtopic.php?f=621&t=777957
but, don't consider primary issue facing - happens crackers plant symlinks on infested sites - should go further , identify vulnerability led infestation of site. did identify way able plant symlink?
also, on sites saw infected symlinks there additional injected files, advisable quick scan jamss viewtopic.php?f=621&t=777957
Comments
Post a Comment