• Inviting everyone who uses WordPress management tools in Plesk
    The Plesk team is conducting a 60-minute research session that includes an interview and a moderated usability test.
    To participate, please use this link .
    Your experience will help shape product decisions and ensure the tools better support real-world use cases.

New big bug with php-fpm and htaccess/protected directory??

sebgonzes

Silver Pleskian
Hi all

I still have no solution for the problem of massive domain with php-fpm on an server (https://talk.plesk.com/threads/prob...eout-specified-has-expired-ah01075-er.335211/) but now have discover what seem an new critical bug with php-fpm, if you put an protect directory or include an .htaccess with "deny from all" in your httpdocs domain, to an domain configurated with php-fpm, you will not be able to access to raiz domain (that is correct), but able to access to subdirectory!!! (that is not correct).

I discover the bug, with an hack and spam to an wordpress domain (that is something comun), we lock access from plesk with an protected directory, but spam still... we discover so that http://www.domain.com is correctly locked, but http://www.domain.com/wp-content/uploads/2015/07/list24.php still accesible!!!! so spam continue and continue. We change config from php-fpm to php-cgi, and all work fine.

What is the problem/bug?? Do plesk can also apport an solution for first problem?

Thanks
Merry chistmas for all!
 
Back
Top