Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Is it safe to CHMOD?  (Read 2396 times)

0 Members and 1 Guest are viewing this topic.

benseth

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Posts: 50
Is it safe to CHMOD?
« on: May 07, 2007, 11:02:02 pm »

Is it safe to chmod the uploads file to 777?

Recently, I have been hacked through a 777 in wordpress which costed me an extra 20$ and 100$ for my sever.  I was not aware of this until my webhost notified me this, this folder was chmoded 777 which allowed worldwide access.  I was wondering if it was safe to make all the album folders 777 in coppermine, or is that a security risk?
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Is it safe to CHMOD?
« Reply #1 on: May 08, 2007, 07:56:08 am »

Read SMF: Why chmod 777 is NOT a security risk. Wether 777 is a security risk or not depends on your webserver setup. If your webhost suggests not applying 777, then you should do so. Ask them what permissions are needed on your webserver to grant the webserver (and subsequently the legitimate scripts on it) to have write access. Usually, the following rule of thumb applies: try CHMODing 755 - if this works fine, that's great. If it doesn't work as expected, you'll need 777. As suggested: your webhost needs to come with a final suggestion. Quite frankly though: I would shy away from webhosting that allows the end user to set permissions in an unsecure manner. If 777 is a security risk on your server, then your webhost should make precautions that you can't CHMOD to 777. That's what my webhost does. That's what all good webhosts do.
Logged
Pages: [1]   Go Up
 

Page created in 0.018 seconds with 15 queries.