Major hacking problems with chmod 777 experienced
Posted: Thu Jul 05, 2007 11:38 pm
I know there have been several threads posted about this, and from what I can tell from Ted and Calguy it's something we have to live with, but it's becoming a major problem at least for me.
I just received panicky emails from a client that their site has been hacked. This is the fourth different client (each on a different server) that I have had this happen to. This time it was a php file installed in the modules directory. Twice I've had a folder with a complete cgi and associated files installed in one of the images directories and once had a folder with cgi and files installed in the tmp cache directory. I couldn't even remove any of the files via ftp as I was not the owner, I had to do it through my hosting provider's control panel.
It seems that I can't run the sites at all unless tmp/cache and tmp/templates_c are both anything but 777 and if I take 777 off of the uploads directory my clients can't run their own sites with CMSMS. FTP is NOT an option for ANY of my clients. Removing 777 from modules is not a problem since i don't want clients messing with those directories anyway.
I've used CMSMS now since version 0.8, for at least 20 client sites and now I'm not sure I'll be able to use it anymore. Did I miss a thread with the solution? Is there one? I read Calguy's very detailed sticky about umask and permissions, and do understand changing permissions via ftp and through the web control panel but the rest of it was totally greek. I, like most designers (that's DESIGNER not PROGRAMMER) do not run my own server. All of my clients are on shared servers at hosting providers.
As always (except for this problem) CMSMS totally rocks. Thanks for any help or insight in advance.
Glenn
I just received panicky emails from a client that their site has been hacked. This is the fourth different client (each on a different server) that I have had this happen to. This time it was a php file installed in the modules directory. Twice I've had a folder with a complete cgi and associated files installed in one of the images directories and once had a folder with cgi and files installed in the tmp cache directory. I couldn't even remove any of the files via ftp as I was not the owner, I had to do it through my hosting provider's control panel.
It seems that I can't run the sites at all unless tmp/cache and tmp/templates_c are both anything but 777 and if I take 777 off of the uploads directory my clients can't run their own sites with CMSMS. FTP is NOT an option for ANY of my clients. Removing 777 from modules is not a problem since i don't want clients messing with those directories anyway.
I've used CMSMS now since version 0.8, for at least 20 client sites and now I'm not sure I'll be able to use it anymore. Did I miss a thread with the solution? Is there one? I read Calguy's very detailed sticky about umask and permissions, and do understand changing permissions via ftp and through the web control panel but the rest of it was totally greek. I, like most designers (that's DESIGNER not PROGRAMMER) do not run my own server. All of my clients are on shared servers at hosting providers.
As always (except for this problem) CMSMS totally rocks. Thanks for any help or insight in advance.
Glenn