Post by johnchi » Thu Apr 22, 2010 12:56 pm

instead of deleting the system/helper/domphp subdirectory to block the hack can i simply rename that subdirectory so i can keep the files in that directory without the program finding them?

john in chicago

Newbie

Posts

Joined
Tue Mar 02, 2010 1:11 pm

Post by rph » Thu Apr 22, 2010 3:00 pm

That's security through obscurity and it's not usually looked on as a good solution.

-Ryan


rph
Expert Member

Posts

Joined
Fri Jan 08, 2010 5:05 am
Location - Lincoln, Nebraska

Post by Qphoria » Thu Apr 22, 2010 8:08 pm

1.4.7 doesn't even come with the main bad dompdf.php file anymore. I left the other classes in for the pdf invoice mod that fido made as it was alleged that they were not dangerous. But I am not taking any chances and going to be looking at a completely different solution in 1.5.x. Something that doesn't allow passing remote urls as a $_GET value

Image


User avatar
Administrator

Posts

Joined
Tue Jul 22, 2008 3:02 am
Who is online

Users browsing this forum: No registered users and 21 guests