We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28042 ☆ A M B ☆
    • 24,524 Posts
    The web server can be configured to use an "index" page in the order specified:
    index.html index.php

    With this configuration, if the request is for a directory, such as "domain.com/" or "domain.com/manager/" then the index.html file will be used first; if index.html doesn't exist then index.php will be used.

    The server can also be configured to show a directory listing if no index page is found, or not. It is obviously more secure if directory listing is turned off, so that the files in a directory aren't listed if there's no index file to be found. For example, if you could go to domain.com/core/configs/ and get a listing of files, you'd be able to download the config.inc.php file and get the database password for the site.
      Studying MODX in the desert - http://sottwell.com
      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
      Join the Slack Community - http://modx.org
      • 19872
      • 1,078 Posts
      I had tech support change the server config to not show a directory listing. So let me ask you this though in regard to config.inc.php: What prevents someone, who knows MODx from navigating to that file and obtaining the password for the database and then wrecking it?
        • 19872
        • 1,078 Posts
        Just for grins.. I navigated to my config.inc.php and all that displays is a blank page. Hmmm?
          • 42046
          • 436 Posts
          Quote from: mmcgee at Jul 28, 2013, 08:03 PM
          I had tech support change the server config to not show a directory listing. So let me ask you this though in regard to config.inc.php: What prevents someone, who knows MODx from navigating to that file and obtaining the password for the database and then wrecking it?

          It shouldn't be readable in a web browser. Regardless it's best practice to put your core directory under the web directory.
            • 28042 ☆ A M B ☆
            • 24,524 Posts
            That's because you executed the .php file, and it doesn't do anything besides define a bunch of variables. You can deny access in the .htaccess file. This won't bother MODx, because MODx includes the file, which doesn't trigger the web server.

            <Files config.inc.php>
                Order Allow,Deny
                Deny from all
            </Files>


            There is also a file ht.access in the /core/ directory that you can rename to .htaccess; this denies direct access to all .php files in the core directory.
              Studying MODX in the desert - http://sottwell.com
              Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
              Join the Slack Community - http://modx.org
              • 19872
              • 1,078 Posts
              I believe I do have my core directory under the web directory — assuming 'web directory' = 'root directory'. I get confused by the terminology at times.

              Quote from: absent42 at Jul 28, 2013, 08:24 PM
              Quote from: mmcgee at Jul 28, 2013, 08:03 PM
              I had tech support change the server config to not show a directory listing. So let me ask you this though in regard to config.inc.php: What prevents someone, who knows MODx from navigating to that file and obtaining the password for the database and then wrecking it?

              It shouldn't be readable in a web browser. Regardless it's best practice to put your core directory under the web directory.
                • 28042 ☆ A M B ☆
                • 24,524 Posts
                The file may not be readable in a browser, but those who know how can download the file if they can access it at all.

                I think "above the web directory" was what was meant here. You can put the core directory anywhere you like, you just need to edit the paths in the three config.core.php files (web root, manager, connectors). This will not work, however, on servers with restrictive PHP settings for where .php files can be included from http://www.php.net/manual/en/ini.core.php#ini.open-basedir

                The ht.access file in the core directory can be renamed to .htaccess; this will deny direct access to any .php file in the core directory and all of its subdirectories. If you're using apache, that is. [ed. note: sottwell last edited this post 13 years, 2 months ago.]
                  Studying MODX in the desert - http://sottwell.com
                  Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
                  Join the Slack Community - http://modx.org
                  • 19872
                  • 1,078 Posts
                  I am using apache. This seems like a potentially a security issue that maybe as part of the installation instructions there should be a big note that says, rename ht.access in the core to .htaccess.

                    • 32699 ☆ A M B ☆
                    • 427 Posts
                    Quote from: mmcgee at Jul 28, 2013, 08:09 PM
                    Just for grins.. I navigated to my config.inc.php and all that displays is a blank page. Hmmm?

                    It just executed a bunch of settings.

                    There are a few chmod settings to keep that from being executable on top of the restrictions sottwell suggested.

                    It is not mentioned in the docs, for a very simple reason: The premiss of MODX is to provide a framework and platform to build the web your way... Hence the title of my book.

                    MODX stays out of your way, but the developers did offer the file there for those who are interested.

                    There are even more crazy things to do, but frankly have never seen the need to - except in situations I want a single core to run multiple domains...
                      Get your copy of MODX Revolution Building the Web Your Way http://www.sanitypress.com/books/modx-revolution-building-the-web-your-way.html

                      Check out my MODX || xPDO resources here: http://www.shawnwilkerson.com
                      • 19872
                      • 1,078 Posts
                      Thanks for the feedback. I do really like the creative freedom that comes from working with MODx, and it's the primary reason I decided to jump on board and learn CMS. This forum especially has been a great resource! I truly appreciate the helpful, encouraging feedback I always receive whenever I post question.