Modul Security review Problem PHP files in the Drupal files directory can be executed.
Eingetragen von rothlive (98)
am 28.04.2014 - 02:21 Uhr in
am 28.04.2014 - 02:21 Uhr in
Hallo
ich habe das Modul Security review installiert und bekomme die Meldung nicht weg:
PHP files in the Drupal files directory can be executed.
Executable PHP in files directory
The Drupal files directory is for user-uploaded files and by default provides some protection against a malicious user executing arbitrary PHP code against your site.
Read more about the risk of PHP code execution on Drupal.org
External Links icon
.
The .htaccess file exists but does not contain the correct content. It is possible it's been maliciously altered.
Die .htaccess Datei habe ich auch neu erstellen lassen.
Sie hat den Inhalt :
# Turn off all options we don't need.
Options None
Options +FollowSymLinks
# Set the catch-all handler to prevent scripts from being executed.
SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006
<Files *>
# Override the handler again if we're run later in the evaluation list.
SetHandler Drupal_Security_Do_Not_Remove_See_SA_2013_003
</Files>
# If we know how to do it safely, disable the PHP engine entirely.
<IfModule mod_php5.c>
php_flag engine off
</IfModule>
Was mache ich Falsch ?
- Anmelden oder Registrieren um Kommentare zu schreiben
Neue Kommentare
vor 1 Tag 4 Stunden
vor 3 Tagen 1 Stunde
vor 3 Tagen 3 Stunden
vor 3 Tagen 4 Stunden
vor 3 Tagen 5 Stunden
vor 3 Tagen 5 Stunden
vor 3 Tagen 5 Stunden
vor 3 Tagen 19 Stunden
vor 5 Tagen 4 Stunden
vor 6 Tagen 3 Stunden