[TYPO3-core] RFC #14719: Automatically create ENABLE_INSTALL_TOOL file when 1-2-3 Install Tool is used

Dmitry Dulepov dmitry.dulepov at gmail.com
Tue Jun 15 09:36:16 CEST 2010


Hi!

Jeff Segars wrote:
> Problem:
> When a new user first installs TYPO3, they must create the
> ENABLE_INSTALL_TOOL file before installation can continue. For a
> friendlier first install, it would be nice to automatically create the
> file and go directly to the 1-2-3 Install Tool

This may cause security issues. The most obvious is when the site is in
prepared but not yet installed. If it is left like this, anybody from the
Internet will be able to access Install tool.

I insist that it must be evaluated by the security team before it is committed.

-- 
Dmitry Dulepov
TYPO3 expert / TYPO3 core&security teams member
Twitter: http://twitter.com/dmitryd
Read more @ http://dmitry-dulepov.com/


More information about the TYPO3-team-core mailing list