[support] www.mysite.net security hole for mysite.net?

dondi_2006 dondi_2006 at libero.it
Sat Jun 10 16:41:01 UTC 2006


> Make sure your .htaccess file is being read. Then make sure you have  
> the correct redirect command uncommented.

Thanks, but.. sorry, how do I check this? I REALLY need to understand
if what's happening is an error of mine and which one, or if it's a general
Drupa or LAMP issue/bug

> If you're trying to run your www. domain as a different site than the  
> non-www. domain, then I don't know -- I've never tried that.

No, that's not what I want. I want mysite.net and www.mysite.net to be the
same website. I just want to _advertise_ (when it will be ready) only the
shorter name.

Anyway: I have discovered two things:

1) If I click on "log out" in www.mysite.net then I don't see that
   hole anymore, but:

2) three days ago I had created (after the admin account) a second account,
   called My_First_Name with full powers (since I read somewhere it's good
   practice to use account #1 as seldom as possible). If I log in with this
   _second_ account, I still get the page:

############################################

Welcome to your new Drupal website!

Please follow these steps to set up and start using your website:

   1. Create your administrator account To begin, create the first account. This account will have full administration rights and will allow you to configure your website. 
###################################################################

if I click on "create the first account" I get an access denied page, so there seems to be nothing really dangerous going on, but this still seems
very confusing, if not potentially dangerous, to me.

Thanks in advance for any further feedback.

O.



More information about the support mailing list