forum : config.cfg file security - file no longer in use

You must be logged in to post Login Register

config.cfg file security – file no longer in use

UserPost

1:23 pm
August 26, 2009


themattreid

Admin

Nevada

posts 48

1

If you're running a version prior to rev-111 then your $install_location/config.cfg file might be vulnerable to viewing with a web browser. If you did not change the permission to the kontrollbase script user the the webserver might have read permissions on the file. 

This was fixed in rev-111 and above by using a totally new method of accessing database connection variables for the server scripts. They now access the CodeIgniter system/application/config/database.php file directly so there is no config.cfg file in the main folder anymore. 

Solution


  1. Upgrade to the current version or revision 111 or higher.
  2. If you do not want to upgrade, just run the following command – replace [user] with the user that you are using to run the bin/ scripts
    shell> chown user:user config.cfg && chmod 0400 config.cfg


http://kontrollsoft.com http://themattreid.com

7:00 am
November 14, 2009


xstar

Junior-DBA

posts 16

2

I get kontrollbase whether through SVN check out or download kontrollbase-rev225.tar.gz, can't found the config.cfg file in package.

I had create config.cfg in kontrollbase root directory to test set the DEBUG file,but it's no effects.

10:10 am
November 14, 2009


themattreid

Admin

Nevada

posts 48

3

config.cfg is no longer used. I'll remove that information from the documentation.

http://code.google.com/p/kontr…..tail?id=78

http://kontrollsoft.com http://themattreid.com

 

About the kontrollsoft forum

Most Users Ever Online:

9


Currently Online:

3 Guests

Forum Stats:

Groups: 3

Forums: 12

Topics: 33

Posts: 79

Membership:

There are 425 Members

There has been 1 Guest

There is 1 Admin

There are 0 Moderators

Top Posters:

xstar – 16

Prabhat – 3

christian.keil – 2

massoo – 2

j2ict – 2

chaq – 1

Administrators: themattreid (48 Posts)