Dukecitysolutions / Sentora-Live-v1.0.3.1

Sentora Live is a new version outside of Sentora_core 1.0.3 used for testing PHP 7.3 Support. WORK IN PROGRESS!!!
GNU General Public License v3.0
3 stars 1 forks source link

security hardening #12

Closed VedranIteh closed 4 years ago

VedranIteh commented 4 years ago

/etc/lib and /etc/cnf both contain files that are loaded from within other php scripts so there is no need for them to be publicly available. it would be even better to move them outside web root and allow the path with SP rule si it can be accessed from .php scripts. Until than lets block them here. Furthermore etc/lib contains third party modules that may have vulns.