SnippetMaster Support Forums
Return to main website
 
November 06, 2009, 02:28:33 PM
* Show unread posts since last visit.
* Show new replies to your posts.
Welcome, Guest. Please login or register.
Did you miss your activation email?
November 06, 2009, 02:28:33 PM

Login with username, password and session length
Search:  
Advanced search
* Home Help Search Login Register
SnippetMaster Support Forums  |  General  |  General Discussion & Support  |  Topic: Spam Issues « previous next »
Pages: [1] Print
Author Topic: Spam Issues  (Read 130 times)
mooresites

Posts: 5


[-] Spam Issues
« on: September 22, 2009, 06:06:45 AM »

I have recently been bombarded with issues of spammers rewriting files that are intended for Snippetmaster. I use your service for several clients (love it), but recently it's become quite a hassle. In all instances, the folder (usually uploads) that has been chmod 777 is infiltrated with spam pages that generate spam. Also, files that are CHMOD 646 (for writability) are being affected as well. What am I doing wrong? Thanks!
Report to moderator   Logged
admin
Forum Administrator
*
Posts: 2722

SnippetMaster Author


WWW
[-] Re: Spam Issues
« Reply #1 on: September 22, 2009, 06:52:54 AM »

Hello,

Hmm.. can you make sure that you are using the most recent version?  There was a security problem with one of the older version of Snippetmaster a while ago (last February 2009), so it might be that your server is insecure and the hacker was able to use snippetmaster to get in.

If you are running the latest version of Snippetmaster then you should be safe.

Here are upgrade instructions:

1. Go to http://www.snippetmaster.com/download
2. Follow the "auto installer" instructions to install.
3. The installer will detect that this is an upgrade, so all your existing configuration settings will be saved.

Let me know how that goes.

Report to moderator   Logged
mooresites

Posts: 5


[-] Re: Spam Issues
« Reply #2 on: September 22, 2009, 07:14:04 AM »

Sure am . . . updated back in February with the new release. What happened is there was a file that was 646 CHMOD (what I use for all SMaster related files). All of a sudden, today, this file was altered (it was a test file to set up the system). I can't see how they modified that file when it's in the root and SMaster is two directories deep (and is set not to see the root) . . . any ideas? Also, is 646 the best setting for updateable files? Thanks!
Report to moderator   Logged
admin
Forum Administrator
*
Posts: 2722

SnippetMaster Author


WWW
[-] Re: Spam Issues
« Reply #3 on: September 22, 2009, 08:06:57 AM »

The file permissions that are needed are totally dependent on your web hosting provider's setup of your server.

For example, on my server where snippetmaster runs, only normal permissions are needed and no "write" permissions for any user except the owner.  (No "777" permissions are needed.)

However, for other hosting providers.. they might run their servers differently so they may require permissions of 777 or something in order to allow Snippetmaster to write to the files.

The only thing I can suggest is to upgrade to the latest version (v2.2.3.2) and see if that helps.  It should be secure now if you upgraded in February, but doesn't hurt to have the latest.  Other then that.. confirm with your hosting provider what file permissions are needed and you should be ok.

(Only the flies you want to be editable with Snippetmaster need to have "write" permissions. Everything else (Snippetmaster program files, etc) should only have "read" permissions.)

Let me know how things go.
Report to moderator   Logged
davert

Posts: 23


[-] Re: Spam Issues
« Reply #4 on: October 13, 2009, 06:06:00 AM »

Just to clarify, under a typical cpanel installation, you may find that the group you need is nobody or your username -- one or the other depending on whehter they use suexec (I think).

I use suexec and for me, nobody is the group Snippetmaster needs files to be assigned to. At that point you can chmod 765 (775 if that doesn't work). Then Apache has access to the file, but "world" does not.

777 should usually be totally unnecessary BUT you must chgroup (or chown) properly.
Report to moderator   Logged
Pages: [1] Print 
SnippetMaster Support Forums  |  General  |  General Discussion & Support  |  Topic: Spam Issues « previous next »
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!