InMotion Hosting Support Center
After installing osCommerce you will see a message similar to "I am able to write to the configuration file: /home/userna99/public_html/includes/configure.php. This is a potential security risk - please set the right user permissions on this file."

In this tutorial I will show you how to modify the permissions of the configure.php file, so it is secured and the notification will go away.

Securing the configure.php File:

  1. Login to your cPanel.
  2. Under the File section, click the File Manager. If the File Manager Directory Selection window comes up, click Web Root, and click the Go Button.
  3. Navigate to the configure.php file specified in the error. In my tests it is: /home/userna99/public_html/includes/configure.php
  4. Right-click the configure.php file, and click Change Permissions.
  5. In the change permissions window, change them to 4-4-4, then click the Change Permissions button.
  6. Now login to the osCommerce Admin section, and you will see the "Security risk" message is gone, and has been replaced by "This is a properly configured installation of osCommerce Online Merchant!"

Congratulations, now the configure.php file for your osCommerce is protected from a potential security risk!
Was this article helpful?
Continued Education in Course 203: Adding security to osCommerce
You are viewing Section 1: How to Secure the configure.php File for osCommerce
Section 2: How to Secure Your osCommerce Site with the htaccess/htpasswd

Related Questions

Here are a few questions related to this article that our customers have asked:
Ooops! It looks like there are no questions about this page.
Would you like to ask a question about this page? If so, click the button below!
Ask a Question

Forum Login

You are NOT logged in. You can still browse our Support Center.

To participate within our Community Support Forum:

n/a Points
2014-06-15 5:41 am

Very usefull THANKS!

Post a Comment

Email Address:
Phone Number:

Please note: Your name and comment will be displayed, but we will not show your email address.

1 Questions & Comments

Post a comment

Back to first comment | top

Need more Help?


Ask the Community!

Get help with your questions from our community of like-minded hosting users and InMotion Hosting Staff.

Current Customers

Chat: Click to Chat Now E-mail:
Call: 888-321-HOST (4678) Ticket: Submit a Support Ticket

Not a Customer?

Get web hosting from a company that is here to help. Sign up today!