Bienvenue, Invité. Veuillez vous connecter ou vous inscrire.
Avez-vous perdu votre courriel d'activation?
*


Dossiers à supprimer après installations


Pages: [1]
  Imprimer  

  Dossiers à supprimer après installations
Auteur Message
jean-luc
Modérateurs
Intarissable
*****

Points gagnés: 3
Messages: 1561



Voir le profil WWW
Dossiers à supprimer après installations
« le: 30 Novembre 2009 à 20:55:59 »

Bonjour,

les dernières infos du site ZC US:

certains dossiers peuvent poser des problèmes de sécurité, si vous ne les utilisez pas supprimez les ci-dessous la version originales du message :

Bien évidement comme toujours sauvegarde, sauvegarde et encore sauvegarde avant de bidouiller

In a standard Zen Cart install, there are a few additional folders provided which DO NOT need to be uploaded to your live webserver.
In fact, leaving those folders on your server can pose some security risks if not used as intended.
While most of the risks are minor in that attempting to access some of those files/scripts/documentation could reveal some information about your server which might allow more sophisticated hack "probing" to occur, there are some more significant risks including unauthorized access to information on your server or even "accidental" wipe of your whole database in the case of the zc_install folder being left online.

So, it's important that after you've installed your site and are satisfied that it's working properly, including actually doing live transactions to test ALL the payment and shipping modules you're using on your site, be sure to do some cleanup:

REMOVE THE FOLLOWING FOLDERS (and all the files inside them), TO MINIMIZE SECURITY RISKS:
- /docs
- /extras
- /zc_install
- /install.txt (this file can be removed, too)

It is safe to keep these files on your own computer, since they can be used as references/documentation, or used to aid in troubleshooting as diagnostic tools, or for upgrading/installing again in the future. But those folders/files should *not* be on a live webserver.


Optional:
Additionally, *IF* you have no intentions of supporting downloadable products or music-media products, you can *also* remove these folders:
- /download
- /media
- /pub

(And you'll need to go to your Admin->Configuration->Attribute Settings->Enable Downloads, and set it to False to turn off the warning message about the missing download folder)
In the future, if you choose to add downloadable products to your site or music-products, you will want to re-upload these appropriate folders (and their contents) to your server again, and assign appropriate permissions. (See FAQ are for appropriate permissions instructions.)
Journalisée

jean-luc Evil or Very Mad

pas bon, mais promis j'essaye de m'améliorer tous les jours Evil or Very Mad

www.anneg-lingerie.com

Pages: [1]
  Imprimer  
 

Aller à: