I just upgraded to 1.4.1 and cleared the security test (cf
topic 72502[*1] ), but in the server weblog the paths are not the same as my paths. My url is of the type www.example.com/~username/geeklog (i.e. I have ~/public_html/geeklog as document root), but the paths in the weblog are of the type www.example.com/~username (/config.php, /logs/error.log, /plugins/staticpages/functions.inc, /system/lib-security.php, /backups/test.txt, /data/test.txt), so the right files were actually never checked.
It seems as if the function urlToCheck in sectest.php cuts off the geeklog part somewhere. (My geeklog root is ~/www/geeklog.)