Jump to content


Corporate Sponsors


Latest News: (loading..)

- - - - -

folder or file permittion 777


7 replies to this topic

#1 axioma

  • Community Member
  • 154 posts
  • Real Name:yesid borislov

Posted 15 October 2009, 13:10

you can find a lot of contributions that says " the folder x has to have 777 permission" it is true in most of the images contributions..... what can we do in these cases?.

is a 777 an open door for hackers, troyans etc??

#2 FIMBLE

  • Community Member
  • 6,557 posts
  • Real Name:Nic
  • Gender:Male

Posted 15 October 2009, 13:29

View Postaxioma, on 15 October 2009, 13:10, said:

you can find a lot of contributions that says " the folder x has to have 777 permission" it is true in most of the images contributions..... what can we do in these cases?.

is a 777 an open door for hackers, troyans etc??

You should not have any folder over 755 nor file over 666 (if it need to be written to) otherwise 644.
Its like locking your door and going out somewhere but leaving your keys still in the door.

If you need to set permissions to 777 for images folder youneed to talk to your host about it, as you say its not safe at all.

Nic





Sometimes you're the dog and sometimes the lamp post

My Contributions

#3 axioma

  • Community Member
  • 154 posts
  • Real Name:yesid borislov

Posted 20 October 2009, 20:12

IS THIS TRUE?

"This robots text file will also help you by removing one way for hackers to find your images folder as a lot of stores seem to get hacked via it. It will also help hide your admin from everyone but you, it is not that hard to figure out.

Cheers". comes from contribution 'robots.txt Sample File" link

MEANING USEFUL FOR FOLDERS 777 SUCH AS IMAGES FOLDER....

#4 peter222

  • Community Member
  • 106 posts
  • Real Name:Peter Grom

Posted 20 October 2009, 21:13

View Postaxioma, on 20 October 2009, 20:12, said:

IS THIS TRUE?

"This robots text file will also help you by removing one way for hackers to find your images folder as a lot of stores seem to get hacked via it. It will also help hide your admin from everyone but you, it is not that hard to figure out.

Cheers". comes from contribution 'robots.txt Sample File" link

MEANING USEFUL FOR FOLDERS 777 SUCH AS IMAGES FOLDER....
Just follow Nic's 'rules' and you will be fine

otherwise we'll probably see you back with a whole different kind of topic.. ;)

Edited by peter222, 20 October 2009, 21:14.


#5 Dan Cole

  • Community Member
  • 151 posts
  • Real Name:Dan Cole
  • Gender:Male
  • Location:Ontario, Canada

Posted 08 November 2009, 03:51

View PostFIMBLE, on 15 October 2009, 13:29, said:

If you need to set permissions to 777 for images folder youneed to talk to your host about it, as you say its not safe at all.

Nic

I'm really confused....is this really true?

With all the concern being expressed about "777" permissions I raised the matter with my ISP and was told that whether is was a risk or not depends on how the server is configured. I'm told that if the server is set up correctly that "the 777 gives global permissions to applications on the server and not to the world."

Not surprisingly I also found other threads on the web suggesting it's not an issue either providing your server is set up correctly. Maybe we should be advising folks to check with their ISP.

Dan

#6 germ

  • Community Member
  • 13,471 posts
  • Real Name:Jim
  • Gender:Male
  • Location:USA (GMT-6)

Posted 08 November 2009, 04:16

Most servers are NOT setup "correctly".

And what if the person you talk to concerning this doesn't know what they're talking about?
:unsure:

"777" isn't a good idea if you value your site and the time/effort/money you have invested in it.
If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

"Headers already sent" - The definitive help

"Cannot redeclare ..." - How to find/fix it

SSL Implementation Help

Like this post? "Like" it again over there >

#7 Dan Cole

  • Community Member
  • 151 posts
  • Real Name:Dan Cole
  • Gender:Male
  • Location:Ontario, Canada

Posted 09 November 2009, 02:46

View Postgerm, on 08 November 2009, 04:16, said:

Most servers are NOT setup "correctly".

And what if the person you talk to concerning this doesn't know what they're talking about?
:unsure:

"777" isn't a good idea if you value your site and the time/effort/money you have invested in it.

So you would agree...if the server is set up correctly it's a none issue?

Dan

#8 germ

  • Community Member
  • 13,471 posts
  • Real Name:Jim
  • Gender:Male
  • Location:USA (GMT-6)

Posted 09 November 2009, 02:53

View PostDan Cole, on 09 November 2009, 02:46, said:

So you would agree...if the server is set up correctly it's a none issue?

Dan
You'll never catch me with a "777" permissions folder.

What if they change the server setup that makes this a "non issue" and turns it into a hackers paradise and fail to inform you?
:unsure:

It's just not the thing to do (IMHO).

If you never do it, you never have to worry about it.
If I suggest you edit any file(s) make a backup first - I'm not perfect and neither are you.

"Headers already sent" - The definitive help

"Cannot redeclare ..." - How to find/fix it

SSL Implementation Help

Like this post? "Like" it again over there >