[Security question] folder permissions

General project discussion. NOT for help questions.
Post Reply
andre_designer
Forum Members
Forum Members
Posts: 233
Joined: Sat Apr 10, 2010 4:26 am

[Security question] folder permissions

Post by andre_designer »

i've using cms made simple for a few tear for a several websites and i like cms made simple on the way you build websites with it. it is relative easy to build website with it.

But i have security question for a while!! by installing cms ms you mustgive certain folders permissons to 0777 .

what i read and i know about it is that folder permissions 777 are dangerous. everyone can read and write to that folder. My question is: can it be otherwise regulated with less folder permissions (for example maximal 755) is that uber hold possible
Wishbone
Power Poster
Power Poster
Posts: 1368
Joined: Tue Dec 23, 2008 8:39 pm

Re: [Security question] folder permissions

Post by Wishbone »

Depends on your host. Some, like Arvixe only need 755, as the web account is running as you. Other hosts that I've been on require 777 as the web account isn't you. If you have SSH access, try to go to another user's home directory.. If you can't, then it's relatively safe to have the permissions set to 777 as other processes can't modify your files.
andre_designer
Forum Members
Forum Members
Posts: 233
Joined: Sat Apr 10, 2010 4:26 am

Re: [Security question] folder permissions

Post by andre_designer »

but in general what is wise to do. i sitting by shared hosting. to match persmissions they can write anything to that certain folder to less i as webmaster can not write to that certain folder. So again what is in general wise to do??perticulair on shared hosting and users from the outsite the website.
reneh
Dev Team Member
Dev Team Member
Posts: 446
Joined: Tue Nov 28, 2006 8:39 pm

Re: [Security question] folder permissions

Post by reneh »

Its not one general answer to that as all depends on how the security is set up on the shared host.
I.e. my main host let me have permission 0700 on almost all files and just a few files/folders need read right by public.

Main rule is to give out as little permissions as possible and rise only for a few files and folders. Its some sort of try and fail to get it tightened down....
ReneH 8-)
A search will save you hours waiting for an answer! Image
Post Reply

Return to “General Discussion”