PHP Unserialize Remote Code Execution

PHP Unserialize Remote Code Execution

by Azmat Ullah -
Number of replies: 2
Picture of Plugin developers
Hi,

How we can to stop direct access of some Moodle files such as https://sandbox.moodledemo.net/admin/environment.xml

Thanks, Azmat
Average of ratings: -
In reply to Azmat Ullah

Re: PHP Unserialize Remote Code Execution

by Tim Hunt -
Picture of Core developers Picture of Documentation writers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers
If you wanted to, you could add a rule to your web server's .haccess file. However, it is a plain text file that can be freely found on github. Why do you need to block access to it?
In reply to Azmat Ullah

Re: PHP Unserialize Remote Code Execution

by Andreas Grabs -
Picture of Core developers Picture of Particularly helpful Moodlers Picture of Peer reviewers Picture of Plugin developers Picture of Translators
Hi Azmat,

If you want to prevent users from discovering your Moodle version, you won't be really successfull by hiding those files. There are a lot more files, such as javascript, which have to be accassible by the web browser. Even if you just allow the minified versions I believe it still is possible to get your moodle version by these files.

Best regards
Andreas