"delete kickstart.ini after installation" option

"delete kickstart.ini after installation" option

Tuesday 07 March 2006 5:16:09 am - 2 replies

Author Message

Gabriel Ambuehl

Tuesday 07 March 2006 5:49:40 am

Those passwords are stored in the site.ini anyhow so it's probably not a very big additional risk...

Visit http://triligon.org

Stephan Staubli

Wednesday 08 March 2006 2:31:09 am

so because the risk is their anyway its no problem to have more additional risk??

i dont know how often people use kickstart.ini but i think chances that access to
domain.tld/kickstart.ini are allowed than domain.tld/settings/site.ini are much bigger if someone uses not the .htaccess of ezpublish.

i think its also not difficult for some kiddies to search with google for "Powered by eZ publish® " to find a bad configured ezp and try to find a kickstart.ini with admin pw.

You must be logged in to post messages in this topic!

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.