SnippetMaster Support Forums
Return to main website
 
August 16, 2009, 09:26:55 AM
* Show unread posts since last visit.
* Show new replies to your posts.
Welcome, Guest. Please login or register.
Did you miss your activation email?
August 16, 2009, 09:26:55 AM

Login with username, password and session length
Search:  
Advanced search
* Home Help Search Login Register
SnippetMaster Support Forums  |  General  |  General Discussion & Support  |  Topic: 777 Permissions Hackable? « previous next »
Pages: [1] Print
Author Topic: 777 Permissions Hackable?  (Read 769 times)
mooresites

Posts: 3


[-] 777 Permissions Hackable?
« on: November 04, 2007, 05:09:36 AM »

I found a brief message on this topic, but it didn't answer my question. I had two clients on my server trying out the snippetmaster lite version. In each case, the snippet files that I changed to 777 CHMOD were hacked (boz_wolf hacker). Am I missing something? Is there a way I can secure my server further to prevent this? I'm loving the snippetmaster (am starting to purchas PRO versions), but need this aspect resolved before I can commit. Thanks for the great program!
Report to moderator   Logged
Jenkinhill
Beta Tester

Posts: 382



[-] Re: 777 Permissions Hackable?
« Reply #1 on: November 04, 2007, 06:56:34 AM »

I doubt if you need 777. The required permissions do depend on the server, but assuming that the SnippetMaster files are owned by the site owner then 644 should be all that is needed. I did have one server that required 664 but never 777.
Report to moderator   Logged

Kelvyn
mooresites

Posts: 3


[-] Re: 777 Permissions Hackable?
« Reply #2 on: November 04, 2007, 07:23:28 PM »

I tried 646 and that worked . . . however, wouldn't the hacker be able to do the same thing to my files? Or is the "executable" aspect an issue?
Report to moderator   Logged
Jenkinhill
Beta Tester

Posts: 382



[-] Re: 777 Permissions Hackable?
« Reply #3 on: November 05, 2007, 01:30:30 AM »

No, it is the writable by all that opens the door. Having said that it is not easy to do and I believe it is usually perpetrated by hacking some other vulnerable script on the server, such as an outdated phpNuke, phpBB or whatever. On many shared server configurations the vulnerable script may not even be within your own website.

It is best to avoid 777 except for directories that need full read/write/execute permissions.
Report to moderator   Logged

Kelvyn
mooresites

Posts: 3


[-] Re: 777 Permissions Hackable?
« Reply #4 on: November 05, 2007, 06:41:24 AM »

Gotcha . . . I had several sites that were affected. All were Snippetmaster related with 777 permissions. Talk about a lesson learned! Thanks for your help. Oh, just in case any more light can be shed, I'm on an Apache server (VPS). I run several sites on that one VPS (shared IP). Some that were affected had the new PHPBB3 beta, but some didn't . . .
Report to moderator   Logged
Pages: [1] Print 
SnippetMaster Support Forums  |  General  |  General Discussion & Support  |  Topic: 777 Permissions Hackable? « previous next »
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.9 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!