Security Permissions after install
-
Casual Pligger
Security Permissions after install
Hello.
For increased security purposes, can any of the permissions be changed from 'writeable' after installation e.g. 'config.php' and 'settings.php' to '644'? If so, anything else e.g. templates or templates_c, et.al.?
Is there a point when the permissions need to be set back to writeable when changing something in the admin interface?
Thanks in advance.
-
Pligg Donor
Actually your installer would have advised on the settings or your can find this info in the readme file.
set all to 644, now change the cache and templates_c to 777 - this will do (if you want to use admin panel modify language - then you will need to have lang.conf to 777 same applies to settings.php - till you consigure your site have it as 644 and once all configuration done - change to 644)
-
Casual Pligger
Thanks for your reply.
The instructions did not mention to change 'settings.php' nor 'config.php' nor 'lang.conf' after the installation. I set them to 644 after for security purposes after figuring out what they controlled.
The only question I have left now is whether the subdirectories, 'templates', 'templates_c', 'cache', 'backup' need to remain 777 or can any be changed conditionally?
Thanks.
-
Pligg Donor
'settings.php' nor 'config.php' nor 'lang.conf' are required to be in 777 during config - after than revert them back to 644
-
Casual Pligger
Thanks again.
I take it the subdirectories, 'templates', 'templates_c', 'cache', 'backup' need to remain 777 always?
Thanks.
-
Pligg Donor
yes, they will be written by Pligg frequently
-
Casual Pligger
-
New Pligger
so there isnt a way to protect urself? with these permissions everyone can explore ur site via ftp and get ur templates files?
-
New Pligger
Fundamental security issues
This is a very important question. I have just installed Pligg on a shared server, and after reading this post now am very concerned about a Pligg-powered site's security & permissions ...are they adequate to prevent hacking?
Another recent user reported that his/her version-6.8 site was hacked. Nonetheless, having read that post and without knowing the specific cause, I'd like a forum moderator or developer answer this post with some specific prevention measures. Their recommendations for prevention and security go beyond alleviating fears and in fact will go further - this information should encourage more adoption & use of the Pligg software.
I'm looking forward to suggestions & feedback from administrators and knowledgeable Pliggsters!!
Regards,
John
-
Casual Pligger
If you go to configure pligg in admin it does not work without the settings file being writble public
Similar Threads
-
By sonicbuddha in forum Questions & Comments
Replies: 1
Last Post: 09-10-2007, 05:30 PM
-
By nef in forum Questions & Comments
Replies: 0
Last Post: 08-17-2007, 01:26 PM
-
By satsui in forum Questions & Comments
Replies: 1
Last Post: 01-28-2007, 02:49 AM
-
By renep in forum Questions & Comments
Replies: 0
Last Post: 12-19-2006, 06:35 AM
-
By Peter in forum Questions & Comments
Replies: 8
Last Post: 10-21-2006, 12:35 PM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules