If you are using aeDating v3.2 (patch 1), which has the new aeDating coded database backup feature in the admin panel, you need to make sure your /backup directory is protected from web browsing by one of these three methods:
1) .htaccess file
2) index.html file
3) or turn off directory browsing in your web server configuration file
If you do not, others will be able to browse your backups directory and download your sql files (with all your user information and emails).
Though aeDating supplies an .htaccess file, you should be certain that others can not browse this directory. You can check it by entering the following in your web browser:
http://www.mysite.com/backup (replace mysite with your domain name).
Smoge


LinkBack URL
About LinkBacks



Reply With Quote
Bookmarks