Hi, I was reading
Administrator's Security Checklist page and came across this concern:
Quote:
Ensure that all configurable paths to writable directories (document repositories, image galleries, caches) are outside of public_html. Check third party extensions, such as DOCMan and Gallery2, for editable path settings to such directories. There is currently no easy way to move the Joomla! /image and /media directories. Best plan is to make sure open_basedir is properly set for all the user accounts on your server. Check with your host if unsure.
I've since read up a little on open_basedir and its function... however, one thing I don't understand is how it applies to protecting my /image and /media directories? Am I supposed to assume that I should include every directory except those two in my open_basedir directive? Would that even be desirable?
Thanks in advance for any help in this matter.
~j.