The docs say nothing about making this writable folder secure. Very scary. I tried putting a .htaccess file in it with
Order deny,allow
Deny from all
But that prevents images from displaying in the module.
Posted: 25.05.2006, 20:35
rank:
12
registered:
March 2009
Status:
offline
last visit:
Posts:
0
Mediashare is not secure in that way. Please check the readme file which has an explanation.
Future releases will let you change the storage system to more secure but slower solutions.
Posted: 25.05.2006, 21:55
rank:
12
registered:
March 2009
Status:
offline
last visit:
Posts:
0
Bummer. Every folder I've left open this way eventually gets hacked. Putting an empty index.html doesn't prevent this.
I won't be able to use Mediashare until it's more secure :( I liked the way photoshare could place the writable directory above web root - even remembering the original file name - or (better!) putting the images in the db.