Page 1 of 2 12 LastLast
Results 1 to 10 of 11
  1. #1
    Casual Pligger newsome's Avatar
    Joined
    Aug 2007
    Posts
    45

    Security Permissions after install

    Hello.

    For increased security purposes, can any of the permissions be changed from 'writeable' after installation e.g. 'config.php' and 'settings.php' to '644'? If so, anything else e.g. templates or templates_c, et.al.?

    Is there a point when the permissions need to be set back to writeable when changing something in the admin interface?


    Thanks in advance.

  2. #2
    Pligg Donor dollars5's Avatar
    Joined
    Dec 2006
    Posts
    1,960
    Actually your installer would have advised on the settings or your can find this info in the readme file.

    set all to 644, now change the cache and templates_c to 777 - this will do (if you want to use admin panel modify language - then you will need to have lang.conf to 777 same applies to settings.php - till you consigure your site have it as 644 and once all configuration done - change to 644)

  3. #3
    Casual Pligger newsome's Avatar
    Joined
    Aug 2007
    Posts
    45

    Question

    Thanks for your reply.

    The instructions did not mention to change 'settings.php' nor 'config.php' nor 'lang.conf' after the installation. I set them to 644 after for security purposes after figuring out what they controlled.

    The only question I have left now is whether the subdirectories, 'templates', 'templates_c', 'cache', 'backup' need to remain 777 or can any be changed conditionally?


    Thanks.

  4. #4
    Pligg Donor dollars5's Avatar
    Joined
    Dec 2006
    Posts
    1,960
    'settings.php' nor 'config.php' nor 'lang.conf' are required to be in 777 during config - after than revert them back to 644

  5. #5
    Casual Pligger newsome's Avatar
    Joined
    Aug 2007
    Posts
    45

    Question

    Thanks again.

    I take it the subdirectories, 'templates', 'templates_c', 'cache', 'backup' need to remain 777 always?

    Thanks.

  6. #6
    Pligg Donor dollars5's Avatar
    Joined
    Dec 2006
    Posts
    1,960
    yes, they will be written by Pligg frequently

  7. #7
    Casual Pligger newsome's Avatar
    Joined
    Aug 2007
    Posts
    45
    Thanks for the info.

  8. #8
    New Pligger floweroflove's Avatar
    Joined
    Aug 2007
    Posts
    7

    Unhappy

    so there isnt a way to protect urself? with these permissions everyone can explore ur site via ftp and get ur templates files?

  9. #9
    New Pligger mangoman's Avatar
    Joined
    Sep 2007
    Posts
    1

    Exclamation Fundamental security issues

    This is a very important question. I have just installed Pligg on a shared server, and after reading this post now am very concerned about a Pligg-powered site's security & permissions ...are they adequate to prevent hacking?

    Another recent user reported that his/her version-6.8 site was hacked. Nonetheless, having read that post and without knowing the specific cause, I'd like a forum moderator or developer answer this post with some specific prevention measures. Their recommendations for prevention and security go beyond alleviating fears and in fact will go further - this information should encourage more adoption & use of the Pligg software.

    I'm looking forward to suggestions & feedback from administrators and knowledgeable Pliggsters!!

    Regards,
    John

  10. #10
    eon
    eon is offline
    Casual Pligger eon's Avatar
    Joined
    May 2007
    Posts
    38
    If you go to configure pligg in admin it does not work without the settings file being writble public

Page 1 of 2 12 LastLast

Similar Threads

  1. Page access permissions
    By sonicbuddha in forum Questions & Comments
    Replies: 1
    Last Post: 09-10-2007, 05:30 PM
  2. Permissions problems to backup
    By nef in forum Questions & Comments
    Replies: 0
    Last Post: 08-17-2007, 01:26 PM
  3. Permissions
    By satsui in forum Questions & Comments
    Replies: 1
    Last Post: 01-28-2007, 02:49 AM
  4. Wrong instructions for permissions
    By renep in forum Questions & Comments
    Replies: 0
    Last Post: 12-19-2006, 06:35 AM
  5. Permissions, directories and urls
    By Peter in forum Questions & Comments
    Replies: 8
    Last Post: 10-21-2006, 12:35 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Pligg Modules and Pligg Templates from Pligg Pro Donate to Pligg CMS Dreamhost Web Hosting Host Gator Web Hosting