Alright, I've just removed the offending line in .htaccess and replaced
it with a few empty index.html in appropriate directories.

Yeah, it's a crappy solution but the .htaccess one isn't actually very
reliable.

** Changed in: mahara
       Status: In Progress => Fix Released

** Changed in: mahara
       Status: Fix Released => Fix Committed

-- 
Mahara core files are exposed
https://bugs.launchpad.net/bugs/571709
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.

Status in Mahara ePortfolio: Fix Committed

Bug description:
Mahara files are available in google, i.e. 
http://www.google.com/search?hl=en&client=opera&hs=Ebo&rls=en&q=%22Index+of%22+%2B%22%2Flib%2Fdwoo%2Fmahara%22

This does not seem to be a security risk as is, but it might be, because people 
might put stuff in accessible files that don't belong there, and all in all I 
think you should protect your users against stupid mistakes.



_______________________________________________
Mailing list: https://launchpad.net/~mahara-contributors
Post to     : mahara-contributors@lists.launchpad.net
Unsubscribe : https://launchpad.net/~mahara-contributors
More help   : https://help.launchpad.net/ListHelp

Reply via email to