Site Links
Home
Features
Documentation
Pricing & Order
Members Area
Support Options
Who's Online
1 registered (1 invisible), 20 Guests and 22 Spiders online.
Key: Admin, Global Mod, Mod
Featured Member
Registered: 02/13/08
Posts: 1
Top Posters (30 Days)
Ruben Rocha 103
Rick 81
Mark S 72
Thelockman 56
Gizmo 50
driv 35
Sirdude 30
ntdoc 30
packlite 24
AllenAyres 22
Latest Photos
bear test
Beach Barbie-Q
Sunset
Accept the challenge!
Trees
Topic Options
Rate This Topic
#92781 - 08/01/00 07:19 PM Security Question???
Anonymous
Unregistered


I have another question for you all. What should the file permission be for the files?? I know that the mod.file, forum whatever, ubtwhater should be 777, but what about all those other files on the server. Can I lock them all down so nobady can touch them? Basically i'm asking in a nut shell is what am I supost to leave open and what should I lock (make undeleteable). I use cuteftp if that matters. OH and by the way, thx again for helping out a newbie at this. SOmetimes I think i'm too paranoid about deleters and such.
About 3 months ago a guy hacked into my friends board and delelted EVERYTHING, that not helping my feeling now. His board was up for 6 months with 1000 users. He was devistated. So you can understand my feelings. THX Again...

Top
#92782 - 08/02/00 02:54 PM Re: Security Question???
Anonymous
Unregistered


The minimum permissions you can give is related to the exact setup of the server.

In an ideal situation, you could just set everything 700 and forget it, however the sheer majority of ISPs do *NOT* run CGIs as you, they run them as user nobody. That's why we ask that certain files be set up as 777. Files owned by you but accessed by nobody set to less than 666 would not be (reliably) usable. Nobody is a real pain. You can quote me on that.

Please, PLEASE do not change permissions on ANYTHING until you ask their host if they are running CGIWrap, suExec, or a similar CGI wrapper to ensure CGI scripts run as a user rather than nobody.

Also a little reminder - we can not officially support a board that's not using the permission settings we set forth in the installation instructions. If something goes wrong at your board, you may have to reset permissions on your files...

As for the hacking - three months ago, the UBB contained a nasty security hole that would have allowed something like what you describe. Current UBB versions don't contain the hole.

------------------
Charles Capps, Moderator, Post-Install Troubleshooting
PLEASE NOTE: Due to time limitations, I do not provide UBB support via email.

Top
#92783 - 11/28/00 03:22 PM Re: Security Question???
Anonymous
Unregistered


[snip by CC: Please do not me-too in this forum, it causes no end of support headaches. For all issues, start a NEW thread with your version and URL, as well as a concise description of your problem, including any and all error messages you may have received]

[This message has been edited by Charles Capps (edited 11-28-2000).]

Top


Moderator:  AllenAyres, Gizmo, Ian, Ron M 
Shout Box

Today's Birthdays
theregit
Recent Topics
New members don't get access and are not displayed in the config panel
by Yomar
Yesterday at 03:32 AM
How to Change Link Color / Underline in styles?
by ECNet
01/07/09 10:00 PM
Chaging the "max online" number and date
by wanted
01/07/09 02:22 PM
7.4.1. In Threaded Mode - "Mark All Read" Doesn't Work
by packlite
01/07/09 10:26 AM
Custom island with sql connection
by Robje01
01/07/09 09:13 AM
Forum Stats
4296 Members
33 Forums
30687 Topics
156017 Posts

Max Online: 978 @ 06/24/07 08:19 PM