Announcement

Collapse
No announcement yet.

Directory and file permission

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Directory and file permission

    Hi All.

    I run a number on web sites for a different companies. Over the last few weeks I have suffered hacking, so much so my hosting provider has stated that if it happens again they will turn the account off.

    Two of the sites I manage run Actinic V7.

    The server is virtual web space on a shared server.

    Under the sharded area (which only I have access, (we think)) there are a number of directories containing the web sites we look after.

    The two site which run Actinic have the following directory permissions:-

    site root = 701 (owner=rwx, group=none, public=none )
    acatalog = 777 (owner=rwx, group=rwx, public=rwx)
    cgi-bin = 705 (owner=rwx, group=none, public=r x )

    Our worry is that if the acatalog directory has all permissions for everyone will this allow hackers to upload files to that directory.

    We need some good advice on this question please.

    HELP.

    Many thanks in advance.

    Dereck

    #2
    From the Actinic documentation
    The effective user ID of the Web server must have read permissions. Depending on the set up,
    the permissions could be 700, 760, 764, 746, or 706. 700 and 760 are probably the most
    common.

    If you encounter problems with permissions when trying to upload your store for the first time, try
    setting the permissions on the effective user ID of the web server to '777'. Once your store is
    uploaded, progressively tighten up the permissions on the web server to one of the settings
    recommended above, or until your store no longer functions.
    hth
    Bill
    www.egyptianwonders.co.uk
    Text directoryWorldwide Actinic(TM) shops
    BC Ness Solutions Support services, custom software
    Registered Microsoft™ Partner (ISV)
    VoIP UK: 0131 208 0605
    Located: Alexandria, EGYPT

    Comment


      #3
      Hi wjcampbe,

      Thanks for your reply. I have set the permissions on the acatalog directory to 701 and the cgi-bin to 701. All looks as if it is working O.K.

      Do you think this will be O.K.

      Many thanks.

      Dereck

      Comment


        #4
        The settings are normally only changed for acatalog, with cgi-bin fixed at 755. I have not personally experimented with changing cgi permissions.

        If you are still able to navigate to the website and place orders from another computer with the settings you now have, then I would try them for a day or so.
        Bill
        www.egyptianwonders.co.uk
        Text directoryWorldwide Actinic(TM) shops
        BC Ness Solutions Support services, custom software
        Registered Microsoft™ Partner (ISV)
        VoIP UK: 0131 208 0605
        Located: Alexandria, EGYPT

        Comment

        Working...
        X