Irish SEO,  Marketing & Webmaster Discussion

 

cache: 777 vs 775 - security?

This is a discussion on cache: 777 vs 775 - security? within the Server / Technical Administration Tips and Queries forums, part of the Webmaster Help category; Using Magpie RSS yoke to do some feed display on a site... it needs a cache folder, but I'm unclear ...


Go Back   Irish SEO, Marketing & Webmaster Discussion > Webmaster Help > Server / Technical Administration Tips and Queries

Register Forum Rules FAQDonate Members List Calendar Search Today's Posts Mark Forums Read


Notices

Reply

 

LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 19-03-2007, 06:40 PM
Coder
 
Join Date: Jan 2006
Posts: 43
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
frankp will become famous soon enough
Default cache: 777 vs 775 - security?

Using Magpie RSS yoke to do some feed display on a site... it needs a cache folder, but I'm unclear on the permissions issues for the cache folder.

I thought 775 was what it required but that doesn't work.

777 works fine of course, but I'm unclear whether it is a security risk to have the cache folder set to 777.

It's ONLY the cache folder would be set to 777, every other folder in the directory is 755.

thanks for any help.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2 (permalink)  
Old 23-03-2007, 12:23 AM
niall's Avatar
Hosting Caretaker
 
Join Date: Jan 2007
Location: Carlow
Posts: 58
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
niall will become famous soon enough
Send a message via ICQ to niall Send a message via MSN to niall
Default

Quote:
Originally Posted by frankp View Post
It's ONLY the cache folder would be set to 777, every other folder in the directory is 755.

thanks for any help.
On most servers the apache server will run as the www-data or similar user. To give the apache user access to the cache directory you have to give it permissions of 777. While theoretically this can be a security hole, it's only really a security risk if you have other holes in your code which gives a script kiddie a method to execute something which he has managed to put in there.

There is also risk of another user on the same server having fun in the directory, but that's easier to track.

Just after doing a check on a multi-user server I help admin outside of work, the amount of 777 directories is impressive
__________________
Blog
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3 (permalink)  
Old 23-03-2007, 03:48 AM
Coder
 
Join Date: Jan 2006
Posts: 43
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
frankp will become famous soon enough
Default

thanks Niall!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Tags
775, 777, cache, security

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT +1. The time now is 05:59 PM.


Powered by: vBulletin Version 3.7.3, Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Hosted in Ireland by Blacknight - Test your ISP |Irish Hosting Directory| Armchair.ie|Logo by Eden Web Design|Avatars by Afterglow |Latest Blog Entries | VPS HostingAd Management by RedTyger

Search Engine Friendly URLs by vBSEO 3.2.0