Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
Who's Online
1 registered (1 invisible), 21 Guests and 26 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 11/22/07
Posts: 61
Top Posters (30 Days)
Ruben Rocha 187
Gizmo 108
Rick 100
Thelockman 83
driv 41
AllenAyres 35
ntdoc 28
Sirdude 27
Ian 24
Wordz 18
Latest Photos
My Home System
test photo gallery
Bernese Mountain Dogs
My Daimler
Dorado and shark
Topic Options
Rate This Topic
#165994 - 10/13/06 10:12 AM What happens when I CHMod a file to 444 (read/read/read)?
Conrad Offline
enthusiast

Registered: 08/04/04
Posts: 361
This is part of a banner rotation script. Would it make the site safer? Would I still be able to overright the file by ftp?

Top
#166013 - 10/13/06 01:58 PM Re: What happens when I CHMod a file to 444 (read/read/read)? [Re: Conrad]
David Dreezer Offline
Pooh-Bah
*****

Registered: 07/21/06
Posts: 1792
would it make the site safer? There's a heck of a lot more to making a site safe than changing permissions on a single file, but it can't hurt. Just don't oversell the significance in your mind, it's a part of making it safer, just a part.

Can you overwrite it by FTP? No. You set it to read: owner, group, other. I don't see write in there, do you?
_________________________
What do you mean "You're the bomb, run away?"

Top
#166015 - 10/13/06 03:12 PM Re: What happens when I CHMod a file to 444 (read/read/read)? [Re: David Dreezer]
Conrad Offline
enthusiast

Registered: 08/04/04
Posts: 361
Dave, a banner rotation script that I want to implement uses a simple text file to pull banner codes from. I just don't want someone to be able to change that file to then inject funny code into the header.

Just wondering what I should chmod that file to. Or maybe leave it at 644?

So what happens if I make it 444? Will I still be able to erase the file using ftp?

Top
#166029 - 10/13/06 04:16 PM Re: What happens when I CHMod a file to 444 (read/read/read)? [Re: Conrad]
David Dreezer Offline
Pooh-Bah
*****

Registered: 07/21/06
Posts: 1792
644 is owner write, group and other read.

You will be able to edit or overwrite it via FTP.

As for the question of whether someone else, namely the web server, can overwrite the file and inject code into it, is a touch question to answer.

Are you running Apache? is php a compiled into Apache or running as a cgi? Is Apache running as the same user as the account your asking about? There are probably as many questions to ask you fi you're on a MS server, but I don't have a very good handle on IIS anymore.
_________________________
What do you mean "You're the bomb, run away?"

Top


Shout Box

Today's Birthdays
kimteague_5@msn.com, Trekkie, Trixie
Recent Topics
Issue mass-emailing
by Mitch P.
Today at 12:55 PM
Inclusion of Locked/Closed thread capabilities
by QSS Tim
Today at 11:17 AM
Contact Page Problem
by David DelMonte
Today at 09:05 AM
FAQ bug,
by BreeOge
Today at 08:36 AM
I'm the Admin but.....
by David DelMonte
Yesterday at 11:12 AM
Forum Stats
4261 Members
33 Forums
30539 Topics
155014 Posts

Max Online: 978 @ 06/24/07 08:19 PM