Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: [Solved]: Files to delete after installation?  (Read 2280 times)

0 Members and 1 Guest are viewing this topic.

jenepherre

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Gender: Female
  • Posts: 54
  • there's beauty in the breakdown
[Solved]: Files to delete after installation?
« on: April 16, 2004, 04:53:21 am »

I know with other PHP scripts/programs I've used, you're usually told to delete the config.php file to prevent possible security loopholes.  I didn't see anything saying what files should be deleted after installation in the install instructions (which seem very... brief compared to the install instructions for the last version... am I wrong about that?  I wish you went into more detail...).  :|

Can you tell me which files should be deleted, if any, and also which files are safe to delete?  I assume the docs folder doesn't actually have to be on the server, right?  What else?  :?:

Thanks in advance,
Jen
===============================
Jen Robertson
B/J Journal Archives: http://bj.irishcaelan.com/
jen_robertson@sbcglobal.net
===============================
"The only constant is change."
 - Trance Gemini,
"Gene Roddenberry's Andromeda"
Logged
=================================
Jen Robertson
=================================
I don't want to explain, I just want to dance.

hyperion

  • VIP
  • Coppermine addict
  • ***
  • Offline Offline
  • Posts: 1317
  • - retired -
[Solved]: Files to delete after installation?
« Reply #1 on: April 16, 2004, 05:02:53 am »

You can leave all files on the server if you wish, as Coppermine locks the installation once it has run.

However, if you wish to save space, you can get rid of install.php, the documentation, and any languages or themes you are not using. Also, xp_publish.php can be removed if you do not want to allow uploads using the XP Publishing utitlity.

You can remove the config.php if you desire, but you will need to put it back anytime you want to change the gallery config.  It is secure, so there is really no need.

I know of one user who had someone try to brute-force attack the login.php script (30,000 requests per hour), so he removed it (he was the only user).  If you needed to login, you could put it back.

Again, all the files have authentication controls, so it is not really necessary to remove anything.

Directory permissions are more important, and you should basically avoid 777 permissions whenever possible.
Logged
"Then, Fletch," that bright creature said to him, and the voice was very kind, "let's begin with level flight . . . ."

-Richard Bach, Jonathan Livingston Seagull

(https://forum.coppermine-gallery.net/proxy.php?request=http%3A%2F%2Fwww.mozilla.org%2Fproducts%2Ffirefox%2Fbuttons%2Fgetfirefox_small.png&hash=9f6d645801cbc882a52f0ee76cfeda02625fc537)

jenepherre

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Gender: Female
  • Posts: 54
  • there's beauty in the breakdown
[Solved]: Files to delete after installation?
« Reply #2 on: April 16, 2004, 05:26:35 am »

Thanks so much!  Just the info I needed.   :)
Logged
=================================
Jen Robertson
=================================
I don't want to explain, I just want to dance.
Pages: [1]   Go Up
 

Page created in 0.018 seconds with 19 queries.