Hello,
I've just started playing with ISPConfig yesterday and I found one thing that I was truly shocked about, when I create a protected folder under some website, the resulting .htpasswd file is WORLD READABLE!!

What the heck is that? Am I missing something? That's like putting a door key under the floor mat. Is there any way how to easily fix this "feature"? I can set permissions manually of course, but I am using the panel to do all the dirty work for me...
I was quite enthusiastic about ISPConfig, but now I'm really having doubts about the security of the whole thing when I see thing like having a password file world readable...
Recent comments
15 hours 38 min ago
18 hours 33 min ago
19 hours 47 min ago
21 hours 11 min ago
22 hours 49 min ago
1 day 17 min ago
1 day 1 hour ago
1 day 17 hours ago
1 day 18 hours ago
1 day 22 hours ago