We are happy to announce that Vesta is back under active development as of 25 February 2024. We are working on v1 candidate and expect to engage more with the community over the coming months. We are committed to open source, and we encourage contributors to help us build the future of Vesta.
Vestacp , won't allow access files out side html files
Vestacp , won't allow access files out side html files
Hello
i have a php script that store's the mysql connection data out side the public_html folder for security reasons , and i define the file path with
define('PATH', '/home/admin/web/mysite.com/MysqldataFolder');
i get blank page when visiting the script. but moving the file back under public_hml and re define the file path with
define('PATH', '/home/admin/web/mysite.com/public_html/MysqldataFolder');
that's bring back the script to work. so it seems vista not allowing me including files out side public_html folder ,
any idea why?
thx
i have a php script that store's the mysql connection data out side the public_html folder for security reasons , and i define the file path with
define('PATH', '/home/admin/web/mysite.com/MysqldataFolder');
i get blank page when visiting the script. but moving the file back under public_hml and re define the file path with
define('PATH', '/home/admin/web/mysite.com/public_html/MysqldataFolder');
that's bring back the script to work. so it seems vista not allowing me including files out side public_html folder ,
any idea why?
thx
-
- Collaborator
- Posts: 783
- Joined: Mon May 11, 2015 8:43 am
- Contact:
- Os: CentOS 6x
- Web: apache + nginx
Re: Vestacp , won't allow access files out side html files
Vesta has open basedir in /home/admin/web/mysite.com/public_html/
http://php.net/manual/en/ini.core.php#ini.open-basedir
http://php.net/manual/en/ini.core.php#ini.open-basedir
-
- Support team
- Posts: 1096
- Joined: Sat Sep 06, 2014 9:58 pm
- Contact:
- Os: Debian 8x
- Web: apache + nginx
Re: Vestacp , won't allow access files out side html files
be vary of this setting, if this site gets hacked and a script shell loaded, you are doomed. The attacker will have full access to /home/user directory possibly exposing whole site and crawl scripts to each on of them. Sharing a bitter experience with you from an old server I had when Vesta did not have basedir in its default templates .Better safe then sorry.
Re: Vestacp , won't allow access files out side html files
thanks for the tip , i do not have serious website it only for learning and training purpose ..