Welcome! Log In Create A New Profile

Advanced

Re: [security advisory] http://wiki.nginx.org/Redmine

Edho Arief
March 09, 2015 10:50AM
On Mon, Mar 9, 2015 at 11:44 PM, Gena Makhomed <gmm@csdoc.com> wrote:
> On 08.03.2015 22:50, Francis Daly wrote:
>
>>> webpage http://wiki.nginx.org/Redmine has some security problems:
>>>
>>> 1. All redmine config files are available for anybody in internet,
>>> for example: https://redmine.example.com/config/database.yml
>>> contains in plain text login and password for database connection.
>>
>>
>> I don't think that one is an nginx problem.
>>
>
> Yes, this is not nginx problem. This is nginx configuration problem,
> which provided at wiki.nginx.org as "drop in configuration" for redmine.
>
>> From reading the redmine docs, it looks like the contents of the "root"
>> directive directory should be whatever is in the distributed redmine
>> public/ directory; not the entire installation including configuration.
>

It's a public wiki, not some official documentation. If there's error
you can just go ahead and change it.

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

[security advisory] http://wiki.nginx.org/Redmine

Gena Makhomed March 08, 2015 10:58AM

Re: [security advisory] http://wiki.nginx.org/Redmine

Francis Daly March 08, 2015 04:52PM

Re: [security advisory] http://wiki.nginx.org/Redmine

Gena Makhomed March 09, 2015 10:46AM

Re: [security advisory] http://wiki.nginx.org/Redmine

Edho Arief March 09, 2015 10:50AM

Re: [security advisory] http://wiki.nginx.org/Redmine

Gena Makhomed March 09, 2015 11:24AM

Re: [security advisory] http://wiki.nginx.org/Redmine

sarahnovotny March 09, 2015 11:52AM

Re: [security advisory] http://wiki.nginx.org/Redmine

Francis Daly March 09, 2015 01:26PM

Re: [security advisory] http://wiki.nginx.org/Redmine

Gena Makhomed March 09, 2015 02:26PM

Re: [security advisory] http://wiki.nginx.org/Redmine

Francis Daly March 09, 2015 06:52PM

Re: [security advisory] http://wiki.nginx.org/Redmine

Gena Makhomed March 09, 2015 08:38PM

[security advisory] $http_host vs $host

Gena Makhomed March 09, 2015 02:58PM

Re: [security advisory] $http_host vs $host

B.R. March 10, 2015 06:04AM

Re: [security advisory] $http_host vs $host

Francis Daly March 10, 2015 05:10PM

Re: [security advisory] $http_host vs $host

Gena Makhomed March 10, 2015 06:30PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 103
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready