SnippetMaster Support Forums

General => General Discussion & Support => Topic started by: kezing on September 10, 2002, 01:08:45 PM



Title: Security question
Post by: kezing on September 10, 2002, 01:08:45 PM
I have a working snippetmaster at  my site. I changes permission for all nercassary files so everything works fine.
Since I dont like open up all files e.g the ones I have adjusted for snippetmaster, for user "nobody" = others, I have tried to followin aproach.

In the file/files I want to use snippetmaster, I have removed all code/text between snippet-tags and put them in a separate file. In the original file I instead use the include statement.
I tried this and it works fine.
My intention was to put all "include-files" in a seperate directory which I then give the appropiate permission and leaving the rest of my files/site with limited rights.
But have I really gained any more security this way?


Title: Security question
Post by: admin on September 10, 2002, 05:18:29 PM
What you have done is the "method 2" for SnippetMaster installation: http://www.snippetmaster.com/install.html

I wouldn't say it's any more secure, except that the only thing public is the actual code snippets, instead of the whole page.

Unfortunately, there's absolutely no way to have a script access your user files unless:

1. The script is running as your user.  (Your web host may be able to make this work using something called "suexec".)

2. The file has read/write permissions for whatever user is running the scripts for your website.  Typically, this is a user called "nobody" or "web".. and is part of the "public" group.  This is why you have to give permissions of 777.

Hope that helps to at least explain what is going on..

Cheers!


Title: Re: Security question
Post by: adamcole on November 27, 2017, 02:23:25 AM
You can do it by requesting the permission for your user account or you already have permission to access that script file. I have done several scripting changes for my assignment help (http://www.primeassignment.com/) website and i got approval from the server from day one.


Title: Re: Security question
Post by: adamcole on November 27, 2017, 02:24:19 AM
testing


Title: your zip cut long are quickly tempting these When Hiking
Post by: Ronaldei on December 08, 2017, 01:01:26 PM
{kyrie 3|kyrie irving shoes|kyrie 4|kyrie shoes|kyrie 3 shoes} (http://www.kyrie4shoes.org)
{yeezy boost 350|yeezy boost 350 v2|yeezy v2} (http://www.yeezy350boost-v2.us.com)
{nike air max 2017|nike air max 2018|air max 2017|vapormax|nike vapor max} (http://www.airmaxs2018.us.com)
{timberland boots|timberland outlet|timberland outlet stores|timberland boots outlet} (http://www.timberlandbootsoutletstore.us.com)
{nike hyperdunk|hyperdunk 2017|nike hyperdunk 2017|hyperdunk} (http://www.hyperdunk2017.us)
{louboutin shoes|christian louboutin shoes|christian louboutin outlet|louboutin outlet} (http://www.louboutinshoes-outlet.us.com)
{yeezy boost|yeezy boost 350|yeezy boost 350 v2} (http://www.yeezyboost-350.it)
{nike air max 2017|nike air max 2018|air max 2017|vapormax|nike vapor max} (http://www.max2017.us.com)
{yeezy boost 350 v2|yeezy boost 350|yeezy boost 350 v2 zebra} (http://www.yeezyboost350-v2s.us.com)
{salomon shoes|salomon speedcross} (http://www.salomon-speedcross.us.com)
{birkenstock sandals|birkenstock outlet|birkenstock outlet stores} (http://www.birkenstocksandalsoutlet.us)
{skechers shoes|skechers outlet} (http://www.skechersoutletshoes.us.com)
{kobe shoes|kobe ad|kobe 11|kobe 9|kobe 12} (http://www.kobe-12.us.com)
{louboutin shoes|christian louboutin shoes|christian louboutin outlet|louboutin outlet} (http://www.christianlouboutinshoes2017.us.com)
{nike air max 2017|air max 2017|nike air max} (http://www.airmax-2017.org)
{nike air max 2017|nike air vapor max|vapor max|air max 2017} (http://www.nikeairmaxvapor.us.com)
{north face jackets|north face outlet|north face jackets clearance} (http://www.northfaceoutlet-jackets.us)
{yeezy boost 350|yeezy boost 350 v2|yeezy v2} (http://www.yeezyboost350-v2.us)
{fit flops|fitflops sale clearance|fitflops sale|fitflop shoes} (http://www.fitflopsshoessale.us)
{kd 10|kd shoes|kd 9|nike kd} (http://www.kd-10.us.com)
{louboutin shoes|christian louboutin shoes|christian louboutin outlet|louboutin outlet} (http://www.christianlouboutinshoes-outlet.us)
{yeezy boost 350 v2|yeezy boost 350|yeezy boost 350 v2 zebra} (http://www.yeezyboosts350v2.us.com)
{kate spade handbags|kate spade outlet|kate spade outlet online} (http://www.katespadeoutlethandbags.us.com)
{james harden shoes|harden shoes|harden vol 1|james harden vol 1} (http://www.jameshardenvol1.us.com)
{adidas eqt|adidas eqt support|adidas eqt support adv} (http://www.adidaseqtsupport.us.com)
{timberland boots|timberland outlet|timberland outlet stores|timberland boots outlet} (http://www.timberlandoutletstores.us)
{vapor max|nike air vapor max|nike vapor max|nike vapor max flyknit] (http://www.air-vapormax.us.com)
{adidas shoes|adidas outlet|adidas outlet store|adidas outlet online} (http://www.adidasoutletshoes.us)
{hogan outlet|hogan outlet online|hogan online saldi 70} (http://www.hoganscarpeoutletonline.it)
{nike air max 2017|nike air vapor max|vapor max|air max 2017} (http://www.airmax2017shoes.us)


Title: Re: Security question
Post by: lucysharpe on January 05, 2018, 10:40:18 PM
You can do it by demanding the approval for your user account or you now have permission to contact that script file. I have complete several scripting changes for my UK Essay Help – fullessayhelp   (https://fullessayhelp.co.uk/)website and i got authorization from the server from day one.


Title: Re: Security question
Post by: lucysharpe on January 05, 2018, 10:41:12 PM
You can do it by demanding the approval for your user account or you now have permission to contact that script file. I have complete several scripting changes for my UK Essay Help – fullessayhelp   (https://fullessayhelp.co.uk/)website and i got authorization from the server from day one.


Title: Re: Security question
Post by: lisaware on January 17, 2018, 10:49:02 PM
I was almost done this it's very good for security reason and very good for all security reasons.and also we deliver UK Essay Writing UK (http://expertessayhelp.co.uk) for full of professionals working and our service is available for any time and anywhere as you need.