PDA

View Full Version : Config.php security


kaeldaven
12-11-2007, 03:37 PM
I have version 3.2 but I'm pretty sure this has nothing to do with it so I'm posting it in general. I've finished with my site now, installed and everything seems to be working fine except I get a flashing red box in Admin that says that include/config.php still has writable attribs. I set it from 777, to 655 and even 555 after install but no matter what I do it still says it's writable and that it is a major security risk, I'm a little concerned at this point but I don't know what it is reading, is there anything I could POSSIBLY be missing that I"m just overlooking with my Red BULL High right now?

James
12-11-2007, 04:21 PM
Set it to 444 :)

kaeldaven
12-11-2007, 05:04 PM
Content visible to registered users only.

Unfortunately that doesn't do anything, and get this when I go back into the directory, somehow it's back to 655, its as if the problem is somehow changing it, BUT I did go to /admin and swtich the setting on to override security messages on your admin page. I'm still a little concerned but at least I don't have it glaring me in the face anymore.

David
12-11-2007, 05:16 PM
The ONLY way to set to 444 is through the file manager in cpanel.

kaeldaven
12-12-2007, 04:20 AM
Well let me ask this, is 644 really a security threat?

James
12-12-2007, 06:40 AM
nope but if you want the warning to go away you have to set it to 444 it is a Cpanel thing and that is just the way it is.