We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 45742
    • 10 Posts
    I submitted the change to “.htaccess” as feature request: http://bugs.modx.com/issues/10343
      • 38290
      • 712 Posts
      Quote from: ox6a6e at Nov 20, 2013, 06:01 PM
      In order to avoid a modx finger print, I integrated the root config.core.php into the index.php (plus renaming and moving around the root directories). Probably, I can achieve the same goal with .htaccess rewriting.

      Technically, I'm free to put the assets directory anywhere. The “hardening MODX” documentation even suggests moving it to another server — possibly without PHP.

      The manager and connectors directories are somehow self-contained: both have a separate config.core.php, can be moved to arbitrary directories/URLs. Assets isn't and extras rely on a config.core.php in “assets/..“.

      I don't understand what you mean by a "fingerprint"? Is your goal to delete the config.core.php file? Because that file along with core/config.config.inc.php, connectors.config.core.php and manager/config.core.php are required. It sounds like you deleted it and integrated it into index.php would could be the cause of your errors.
        jpdevries
        • 45742
        • 10 Posts
        config.core.php is quite special to MODX, a fingerprint. If I get a “200” on this URL, I can be pretty sure that MODX is installed. MODX goes a long a way to avoid such fingerprints (see: http://rtfm.modx.com/revolution/2.x/administering-your-site/security/hardening-modx-revolution). This is (was) the last one left.

        Yes, the deletion was the cause and I reinstalled it. I’m sorry that I did not make this totally clear.
          • 38290
          • 712 Posts
          You can do an advanced install and set the config_key to be something other than config to make MODX sites less detectable. Also can change name and location of connector and manager folders
            jpdevries
            • 45742
            • 10 Posts
            (synchronicity?)

            Yes, I did this. However, the config in “config.core.php” cannot be changed… smiley
              • 45742
              • 10 Posts
              Anyway, backend .php-files should not stay in the (sort of) frontend assets/ directory. Unfortunately, this apparently is documented common practice: http://rtfm.modx.com/revolution/2.x/developing-in-modx/advanced-development/custom-manager-pages#CustomManagerPages-CustomConnectors