[TYPO3-ect] Securing typo3conf

Steffen Ritter info at rs-websystems.de
Mon Sep 8 16:51:51 CEST 2008


Hi,
whenever there is a pulic part of the Extension it would be easy to 
check if the extension exists or not. Because everybody knows what would 
be in this public part an may test for. Random path would no help either 
because in you HTML Code the path to the public folder has to be 
included, to use CSS or Images and so on.

But as others said before: I do not think that there is a security risk.
Even if they know what Extensions im Using it would be difficult to 
determine the version.
So far...
Steffen


More information about the TYPO3-team-extension-coordination mailing list