FRIHOSTFORUMSSEARCHFAQTOSBLOGSDIRECTORY
You are invited to Log in or Register a Frihost Account!

php CMS require some 777 permissions?

 


Crinoid
Hi, can you clarify:
Until now I was sure that 777 (whole world writable) permissions for files or folders are a big no-no, a security hole.

After I started looking for an easy (way easier than Drupal) CMS, that will allow to add content without linking new pages manually in the old pages (download-edit-upload each time), it seems that there is an unadvertised feature common if not for all, then for many of php CMS: absolute must of 777 permissions for some files, otherwise the system will not work.

No matter how to call 777: whole world writable or server writable.
Much more people are on shared hosting than having a personal server, equally much more with only basic knowledge, just enough to create and manage hobby or interests website. Helping me here, you help many others just like me.

I spend insane amount of time on try before install website for open source Content Management Systems, selecting the easier and very secure systems, according to feedbacks, only to find few days later that any of them requires 777 level of permissions.

Am I mistaken or any CMS, php based, will require at least one 777 for operating?
If this is still a big security hole, how people work around this problem?

Thanks.
rvec
most of the time they need this at installation so they can safe the database settings to a settings file. You can set it back to 755 or something like that when you're done.
riccopt
777 means that ANY USER THAT IS LOGGED ON THE SERVER CAN WRITE ON THE DIRECTORY...
not really a security whole unless the person knows some user/pass on your server...
but if the guy knows that your site most likely will be taken down or hacked... even if it is 755 or 000...
Crinoid
Thank you!
Hogwarts
riccopt wrote:
777 means that ANY USER THAT IS LOGGED ON THE SERVER CAN WRITE ON THE DIRECTORY...
not really a security whole unless the person knows some user/pass on your server...
but if the guy knows that your site most likely will be taken down or hacked... even if it is 755 or 000...

The Frihost servers restrict the access, so it's unlikely that even if the files are chmodded to 777 that anything bad will happen anyway.
Related topics

a good php cms
Server 3, 777 Permissions, and frih.org domain recovery.
403 Forbidden Error
Joomla! - Installation Tutorial
php Frameworks, or PHP CMS ?!

Joomla Support
CMS Use
Most intuitive CMS.
FRIH$ 250 for answers - secure administr of dynamic website
Phpbb Forum Site Transfer, How to do it, step by step instru

500 Internal Server Error
PHP CMS code
Fix for deleting files/directories owned by apache
PHP Memory on Server 2
php mkdir issue
Reply to topic    Frihost Forum Index -> Scripting -> Website Software

FRIHOST HOME | FAQ | TOS | ABOUT US | CONTACT US | SITE MAP
© 2005-2007 Frihost, forums powered by phpBB.