We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 22303 MODX Staff
    • 10,725 Posts
    Quote from: BobRay at Sep 20, 2009, 10:04 PM

    Putting the core a non web-accesible directory is a good security measure even for a single domain.
    True, though the ht.access delivered in the core/ directory can be renamed to prevent access to any of the files from the web directly, as an alternative to moving the core.
      • 6057
      • 26 Posts
      Hi BobRay and OpenGeek,

      As I prepare to make my first MODx website go live, I did some reading up on PHP security. One suggestion was to move the ’code’ of the site out of the web root, as suggested by BobRay above.

      Reading the instructions above I realise I’m probably too close to my deadline to take that approach sad

      So, OpenGeek, can you explain how I use the .htaccess file to prevent any direct web access? I am already using it for friendly URLs. What more can I do in the .htaccess to improve the security of the site?

      Any advice appreciated.

      Colin
        • 22303 MODX Staff
        • 10,725 Posts
        There is an ht.access file included in the core/ directory. Just rename it to .htaccess in the same location and all direct access to files in core/ will be denied by Apache.

        It’s also fairly easy to change the core location: just move the core and then edit the three config.core.php files found in the root, manager/ and connectors/ directories.