Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 24, 2012, 10:06:55 AM

Pages: [1]   Go Down
  Print  
Author Topic: Yet another dumb newbie question 777  (Read 585 times)
QB-161
Pong! (the videogame) Master
*****
Offline Offline

Posts: 27


WWW
« on: May 18, 2003, 11:21:30 PM »

Hi there Smile

I am pretty new to the level of hosting service at Lunarpages and know very little about server side stuff, though I am learning pretty fast lol.

My question/s are rather simple really. A mod for the lunarpages phpbb that a friend wants me to install requires that certain folder/s permissions are set to 777. The mod is to allow files to be uploaded as attachments to forum messages (the mod is File Attachment Mod v2).

I have read elsewhere in the forums that this should be avoided if possible.
Is this a security risk?
If so how big a risk does it pose?
Logged

~~~~~~~~~~~~~~~~~~
               QB-161
~~~~~~~~~~~~~~~~~~
http://QB-161.com
~~~~~~~~~~~~~~~~~~
stephan
Guest
« Reply #1 on: May 19, 2003, 12:30:44 AM »

Don't worry, the way our servers are set up, it is ok.
Logged
TWebMan
Quantum Encyclopedia Writer
*****
Offline Offline

Posts: 3112



WWW
« Reply #2 on: May 19, 2003, 04:30:28 AM »

As Stephan said, there's not a whole lot to worry about.

If a car thief really wants a car, he's probably going to get it eventually.

If a hacker really wants access, it's the same thing.  Most hackers (especially the ones that would cause the most damage) know there's nothing to be gained by hacking into most people's websites.  The Justice dept site, well that's another story.

setting 777 for 1 or 2 folders is no big deal, (because of what Stephan said) for things like attachments, or temp files that are promptly deleted.

If you need a writeable place to store more sensitive information, don't make it in your publicly accessible website.  Put it NEXT TO your public_html directory, and that way though scripts on your site can write to it, it's not part of your website that the server is just waiting to serve up to the public.  The full path to this folder would be:
/home/youraccountname/foldername

Although it would be very difficult for somebody without your password to access that folder, the car thief rule above always applies.  It would just take them longer.
Logged

"Computers cause people to make more mistakes than any other invention in history, with the possible exception of handguns and tequila."  - Unknown
"Liberty of any kind is seldom lost all at once." - D. Hume
Every day is an Ode to Joy
The planet will be fine... and so will your site
stephan
Guest
« Reply #3 on: May 19, 2003, 05:13:15 AM »

Just to clarify to people reading this, lunarpages is very secure.

I think what TWebMan meant, is that in a world where even the FBI website can be comprimised, we have to make every effort to keep secure.
Logged
QB-161
Pong! (the videogame) Master
*****
Offline Offline

Posts: 27


WWW
« Reply #4 on: May 19, 2003, 10:05:16 AM »

Thanks Stephan and Twebman a very complete and very detailed answer  Very Happy

Gotta love these Lunapages Forums.

Now all thats left is all the fun of the fair installing the MOD (not the best choice for my 1st try LOL)

You guys are sooooooo helpful.

Anyway I hope that this helps someone else with a similar question searching for "777" like I did Wink
Logged

~~~~~~~~~~~~~~~~~~
               QB-161
~~~~~~~~~~~~~~~~~~
http://QB-161.com
~~~~~~~~~~~~~~~~~~
Pages: [1]   Go Up
  Print  
 
Jump to: