View Full Version : Recommended security precautions for EE
UncleDoug
22nd of February 2005 (Tue), 12:13
I was wondering what the recommended security precautions are for EE?
Some issues are outlined in the clean install, but I thought I'd put this out to the group.
TIA for any input.
-Doug
Pekka
22nd of February 2005 (Tue), 12:50
In php.ini:
register_globals = off
It is always best to use the latest versions of PHP and MySQL (MySQL 4 is very recommended, not 4.1 yet), especially PHP contains plenty of security fixes.
In EE the most important security action is: rename input folder to something else and change editor username and pass in misc settings.
tommykjensen
22nd of February 2005 (Tue), 12:57
In EE the most important security action is: rename input folder to something else and change editor username and pass in misc settings.
As an alternative to renaming the folder one can also put a .htaccess file in place when using apache. The .htaccess can then limit access to a specific ip.
UncleDoug
22nd of February 2005 (Tue), 15:39
Thanks!
Just wanting to make sure.... :-)
shaun3000
22nd of February 2005 (Tue), 21:37
You can also password-protect the input directory. So you have to go through two logins. If you use .htaccess, it's even more secure. However, .htacess won't work if your ISP gives you a dynamic IP.
vBulletin® v3.6.12, Copyright ©2000-2012, Jelsoft Enterprises Ltd.