We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!

Answered Security of Evo

    • 37909
    • 153 Posts
    Hi!

    I wonder about the security of Evo. The abandonment of its development is a real problem?

    My client asked me if there is a risk. There is always a risk but what guarantee can I give him? Especially if I told him he is no more developed (this is scary).

    I remember the spam attacks on Evo (just before 1.0.15). I don't want to deal with this anymore.

    What should I do to make Evo the most secure possible?

    This question has been answered by danilocuculic. See the first response.

    [ed. note: neoziox last edited this post 11 years, 2 months ago.]
    • discuss.answer
      • 36416
      • 589 Posts
      Quote from: neoziox at Jul 27, 2015, 07:45 AM
      What should I do to make Evo the most secure possible?


      • upgrade all sites to 1.0.15
      • rename Manager folder
      • host your sites with competent provider (securing accounts with cagefs, modsecurity, csf, fail2ban...)
        • 13226
        • 953 Posts
        Remove all snippets, plugins, modules and chunks that are not required by deleting them from the server and database
          • 37909
          • 153 Posts
          Thanks!

          Question: if I change the name of the Manager folder, but I write it clearly in a file, which CHMOD can I use to protect this file?
            • 13226
            • 953 Posts
            I just changed the permissions of the "siteManager.php" to CHMOD 400 - read only, works perfectly

            But there is an .htaccess file in the cache folder which denies access anyway - try reaching the file directly and you will get a 403

            At the end of the day, renaming the Manager folder is relative - if your site has an error of some kind, it's possible that the path to the renamed manager folder will be displayed in the error as the document-parser.php (in the includes folder in the manager) is referenced many time
              • 37909
              • 153 Posts
              Quote from: iusemodx at Jul 29, 2015, 02:16 AM
              At the end of the day, renaming the Manager folder is relative - if your site has an error of some kind, it's possible that the path to the renamed manager folder will be displayed in the error as the document-parser.php (in the includes folder in the manager) is referenced many time

              Do you mean that this feature doesn't work properly?
                • 36416
                • 589 Posts
                Quote from: iusemodx at Jul 29, 2015, 02:16 AM
                At the end of the day, renaming the Manager folder is relative - if your site has an error of some kind, it's possible that the path to the renamed manager folder will be displayed in the error as the document-parser.php (in the includes folder in the manager) is referenced many time

                Nope, default error handler hides descriptive messages from anonymous visitors.
                  • 13226
                  • 953 Posts
                  Quote from: danilocuculic at Jul 29, 2015, 04:16 AM
                  Nope, default error handler hides descriptive messages from anonymous visitors.

                  I stand corrected, I just forced an error without being logged in and as you say, it simply shows "Error" - when did this change ?

                  I have to date always hacked the core and removed the error reporting code because of this problem
                    • 36416
                    • 589 Posts
                    Quote from: iusemodx at Jul 29, 2015, 06:55 AM
                    I stand corrected, I just forced an error without being logged in and as you say, it simply shows "Error" - when did this change ?
                    I have to date always hacked the core and removed the error reporting code because of this problem

                    A couple of years, maybe more.