PEAK XOOPS - Re: Fastest Cache Hack - TRUST_PATH Location in englishin japanese

Re: Fastest Cache Hack - TRUST_PATH Location

Target Downloads
Subject Fastest Cache Hack (Experimental version)
Summary == 最速キャッシュハック (FCH) ==●特長ページまるごと単位でキャッシュする高速化ハックです。ただし、使い方はそれなりに難しい上に、セッションについての危険性を理解していないと思わぬセキュリティホールの原因になりますので、決して初心者向きではありません...

List posts in the topic

normal Re: Fastest Cache Hack - TRUST_PATH Location

msg# 1.1
depth:
1
Previous post - Next post | Parent - Children.1 | Posted on 2006/5/15 4:34 | Last modified
GIJOE  先任軍曹   Posts: 4110
hi tl.

Quote:
What would be the security implications, if any, if XOOPS_TRUST_PATH = XOOPS_ROOT_PATH

In FCH, someone can see admin's cache by
XOOPS_URL/fullcache/(md5(uid))_(md5(requesturi))
Though I think it is not so severe problem...

At least, put .htaccess under fullcache/

Anyway, I will release modules using XOOPS_TRUST_PATH.
Votes:1 Average:10.00

Posts tree

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!