View Full Version : security risk
theost.com
08-10-2008, 10:05 AM
Hi all ...
I just install the free PHPLD. but i have a problem i cant solve it and i dont know why it come ...
in the admin area
:::::
Configuration file is still writeable by the user the webserver runs under. This poses a major security risk, please drop writing permissions for include/config.php file immediately! ::::
I gave a 111 & 755 & 644 to config.php and i still have this ...
Why ???
Plz Help me ....
James
08-10-2008, 03:26 PM
It has been posted so many times not funny.
set it to 444 in the control panel doing it via ftp will not work.
murko
08-10-2008, 04:35 PM
I actually always makes changes like that after uploadig, via FTP. Why shouldnt that work?
Not meaning to bring up an issue here though =), I completely support your answer above *hehe*, just curious about the fact that changing reading/writing-rights via FTP direct in the remote folder would not work?
Content visible to registered users only.
David
08-10-2008, 07:19 PM
It's just a peculiar thing about cpanel. :)
bruleo
08-10-2008, 08:09 PM
Content visible to registered users only.
Not just cPanel. I use a different control panel (eXtend) and have the same issues. I seem to be able to change file permissions, but not folders. No big deal for me as I always change permissions from with my hosting control panel anyway as I can directly see what each file permissions are set at.
I believe it to be a security protocol that prevents the changing of file permissions from anything other than a direct log-in environment (or as direct as possible, where the internet is concerned). At my time working in various data centres, we had the similar protocols on certain set-ups (unix mainly) that meant remote users could do anything except change permissions, even though they had the power to do almost anything else. For those that are wondering, it has nothing to do with the phpLD script.
Bruce.
fredg61
08-15-2008, 01:16 PM
Content visible to registered users only.
I just manually changed my setting to 444 and it worked like a charm. Thank you.[bt]
vBulletin® v3.8.0, Copyright ©2000-2012, Jelsoft Enterprises Ltd.