<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2009/06/security-linked-files.html" />
  <link rel="self" type="application/atom+xml" href="http://forums.movabletype.org/atom.xml" />
  <id>tag:forums.movabletype.org,2011://24/tag:forums.movabletype.org,2009://24.15741-</id>
  <updated>2011-09-20T23:20:05Z</updated>
  <title>Comments for Security: linked files</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.292</generator>
  <entry>
    <id>tag:forums.movabletype.org,2009://24.15741</id>
    <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2009/06/security-linked-files.html" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.movabletype.org/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=24/entry_id=15741" title="Security: linked files" />
    <published>2009-06-26T15:55:47Z</published>
    <updated>2009-06-29T05:11:27Z</updated>
    <title>Security: linked files</title>
    <summary>The template options allow you to link to external files, which reside in a directoy of your choice under Site Root. These linked files are obviously valuable in the sense that they contain the product of your design work, and...</summary>
    <author>
      <name>Alex E. Schneider</name>
      <uri>http://www.alexome.com</uri>
    </author>
    
    <category term="General" />
    
    <content type="html" xml:lang="en" xml:base="http://forums.movabletype.org/">
      <![CDATA[<p>The template options allow you to link to external files, which reside in a directoy of your choice under Site Root. These linked files are obviously valuable in the sense that they contain the product of your design work, and reflect your ability to use Movable Type's templating language.</p>

<p>Is it necessary at all, as a user/administrator of your MT installation, to take any steps to secure (password-protect) a directory with such files on the server?</p>]]>
      
    </content>
  </entry>

  <entry>
    <id>tag:forums.movabletype.org,2009://24.15741-comment:25759</id>
    <thr:in-reply-to ref="tag:forums.movabletype.org,2009://24.15741" type="text/html" href="http://forums.movabletype.org/2009/06/security-linked-files.html"/>
    <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2009/06/security-linked-files.html#c25759" />
    <title>Comment from Alex E. Schneider on 2009-06-28</title>
    <author>
        <name>Alex E. Schneider</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Let's put it differently: If somebody were about to somehow get all files on your server, how much time would it take - 2 years, or 2 minutes - a degree in computer science or a free tool and some curiosity?</p>

<p>Does Six Apart offer a word on this topic?</p>]]>
    </content>
    <published>2009-06-28T13:25:27Z</published>
  </entry>

  <entry>
    <id>tag:forums.movabletype.org,2009://24.15741-comment:25775</id>
    <thr:in-reply-to ref="tag:forums.movabletype.org,2009://24.15741" type="text/html" href="http://forums.movabletype.org/2009/06/security-linked-files.html"/>
    <link rel="alternate" type="text/html" href="http://forums.movabletype.org/2009/06/security-linked-files.html#c25775" />
    <title>Comment from Jay Allen on 2009-06-28</title>
    <author>
        <name>Jay Allen</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>It would be a good idea to password protect the directory if you has sensitive information in your templates.  Only you can know that for sure, but the default templates, for example, are completely harmless.  There's nothing in those that is sensitive.</p>

<p>All of that said, why link the files underneath the web-accessible part of your server?  You can link them anywhere on the entire server?  The whole question is rendered moot if you just link them elsewhere.</p>]]>
    </content>
    <published>2009-06-29T05:11:27Z</published>
  </entry>

</feed>

