Welcome, Guest. Please Login or Register.
May 18, 2025, 03:25:44 AM
Home Help Search Log in Register
News: If you are still using YaBB SE, please consider upgrading to SMF as soon as possible.

YaBB SE Community  |  English User Help  |  English Help  |  Most secure chmod settings? « previous next »
Pages: [1] Reply Ignore Print
Author Topic: Most secure chmod settings?  (Read 736 times)
Greg Robson
Training to be like Joseph
YaBB SE Developer
YaBB God
*****
Posts: 1459


Hello!

ICQ - 81390136 WWW
Most secure chmod settings?
« on: December 26, 2001, 09:42:05 PM »
Reply with quote

Having just installed the board to see how it works and I realised that I hadn't chmod'ed any of the folders from their original 777.

I was wondering what the most secure chmod settings were considering that the board still has to run!

I'm assuming everyone needs read, but what about write and execute? Does write get handled by the mySQL database so the PHP part can have write access removed?

Many thanks,
someone who is using the coolest damn board in the world!
Logged

You can't have everything... where would you put it? -- Steve Wright
Joseph Fung
Global Moderator
YaBB God
*****
Posts: 4512


Keep smiling: it makes others nervous.

WWW
Re:Most secure chmod settings?
« Reply #1 on: December 27, 2001, 07:50:08 AM »
Reply with quote

Really, you should only have to give write access to Settings.php and settings.bak

Everything else *should* be ok with read-only access.
Logged

barnaby
Noobie
*
Posts: 5


I love YaBB SE!

Re:Most secure chmod settings?
« Reply #2 on: December 28, 2001, 09:38:40 PM »
Reply with quote

What are the default settings given to it when it uploads?  Or is it dependant on the FTP software?

And we need to leave the folder we created to put everything into as 777 for it to work, right?

Logged
Mark
Guest
Re:Most secure chmod settings?
« Reply #3 on: December 28, 2001, 09:54:40 PM »
Reply with quote

Default is like this:

Default is like this:

.ReadWriteExecute
OwnerOOX
GroupOXX
All UsersOXX
Logged
adams
Jr. Member
**
Posts: 80


http://outersurf.com http://jadz.com

WWW
Re:Most secure chmod settings?
« Reply #4 on: December 28, 2001, 11:32:49 PM »
Reply with quote

Quote from: adams on December 27, 2001, 08:59:41 PMhrm........ Is there not a workaround for this (I'm thinking for YaBBSE not for my paticular case) for example couldn't the mod updater chmod all the files to 666 when it was modding and then revert it back when it was finished. It doesn't seem like a good idea to always let everyone modify the source.
Logged

Zef Hemel
Advisor
YaBB God
*****
Posts: 1182


Me too

ICQ - 61109769 WWW
Re:Most secure chmod settings?
« Reply #5 on: December 29, 2001, 09:37:52 AM »
Reply with quote

Quote from: Joseph Fung on December 27, 2001, 07:50:08 AMReally, you should only have to give write access to Settings.php and settings.bak

Everything else *should* be ok with read-only access.
Until you try to install packages
Logged

Greg Robson
Training to be like Joseph
YaBB SE Developer
YaBB God
*****
Posts: 1459


Hello!

ICQ - 81390136 WWW
Would it be better if....
« Reply #6 on: December 29, 2001, 10:00:00 AM »
Reply with quote

I get the impression that it would be best to keep removing access rights unitil the board doesn't work! Then add the last access right you removed! :D
Logged

You can't have everything... where would you put it? -- Steve Wright
Peter Duggan
Llama Chameleon
Global Moderator
YaBB God
*****
Posts: 1793


You come and go...

WWW
Re:Most secure chmod settings?
« Reply #7 on: January 20, 2002, 02:44:07 PM »
Reply with quote

Having searched this site for 'Settings.bak' after having problems with my Forum Preferences and Settings, I did what was recommended by Joseph and others, created it and chmoded it to 777. So it works like that, but it's not secure! Anyone can call it up from their browser and check my database password etc. So I've chmoded it back to 700 for now, which isn't quite so handy.

Any advice?
« Last Edit: January 20, 2002, 02:45:41 PM by Peter Duggan » Logged

Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:Most secure chmod settings?
« Reply #8 on: January 20, 2002, 04:55:29 PM »
Reply with quote

1.1.0 is using Settings.bak.php.  So in your admin section you can look for the code that is making the backup (search for Settings.bak) and change it to Settings.bak.php

That way it can't be read from the web...
Logged

Peter Duggan
Llama Chameleon
Global Moderator
YaBB God
*****
Posts: 1793


You come and go...

WWW
Re:Most secure chmod settings?
« Reply #9 on: January 20, 2002, 11:12:16 PM »
Reply with quote

Thanks Jeff

I'd downloaded and installed 1.0.0 because of all the warnings about feeling comfortable with PHP/MySQL and all that (so I know HTML pretty well but PHP/MySQL is new territory!), but your answer seems to be recommending the upgrade anyway and I've bookmarked your thread on upgrading from 1.0.0 to 1.1.0 to study ASAP. In the meantime (probably just for a few days), is there any reason why I shouldn't manually edit the settings files if chmoding my existing .bak to 777 isn't safe. And, if that's OK, do I need to do both .php and .bak or should I ditch .bak and just edit .php?

One more thing (probably for a different thread, but I was already posting here) is that my board seems to be crawling half the time compared to this one, with a number of server hangups when trying to access index.php or save admin settings. My new host's facilities should obviously be capable of coping with me testing the board (I didn't sign up with them lightly, and they've turned out to be running PHP 4.0.6 after all), but I've read somewhere here (searched the whole site for 'slow'!) about speed problems with 1.0.0 and index.php. So have I missed a fix or something, or can anyone make any suggestions? As soon as my DNS changes go through, I can give you all a URL for the board and get it registered, but that seems pointless at the moment with the DNS changes imminent!

Thanks again
P

PS 'Pointless' because I've got it running at a temporary sub-domain, so the URL will be changing!
« Last Edit: January 20, 2002, 11:18:32 PM by Peter Duggan » Logged

sydney078
Sr. Member
****
Posts: 279


WWW
Re:Most secure chmod settings?
« Reply #10 on: January 21, 2002, 05:09:06 AM »
Reply with quote

So, all of our Yabb SE Folders dont need to be at 777??  ??? What should they be at?  I have the first verision of SE if that helps
« Last Edit: January 21, 2002, 05:10:08 AM by sydney078 » Logged

Peter Duggan
Llama Chameleon
Global Moderator
YaBB God
*****
Posts: 1793


You come and go...

WWW
Re:Most secure chmod settings?
« Reply #11 on: January 21, 2002, 07:53:05 AM »
Reply with quote

Quote from: Peter Duggan on January 20, 2002, 11:12:16 PMyour answer seems to be recommending the upgrade anyway

Or perhaps I've missed the point and you're suggesting I edit the admin code of 1.0.0 to use Settings.bak.php! :)
Logged

Jeff Lewis
Global Moderator
YaBB God
*****
Posts: 10149


I'm a llama!

WWW
Re:Most secure chmod settings?
« Reply #12 on: January 21, 2002, 01:33:59 PM »
Reply with quote

Peter, that is what I am suggesting ;)  Also, where did you read that there are speed issues?
Logged

Peter Duggan
Llama Chameleon
Global Moderator
YaBB God
*****
Posts: 1793


You come and go...

WWW
Re:Most secure chmod settings?
« Reply #13 on: January 21, 2002, 04:15:32 PM »
Reply with quote

Quote from: Jeff Lewis on January 21, 2002, 01:33:59 PMPeter, that is what I am suggesting ;)  Also, where did you read that there are speed issues?

An old post of Joseph Fung's. Just something I turned up on a search... but I've since discovered (on following it up) that he must have been referring to a pre-release version and not 1.0.0. Sorry if I seemed to be implying anything more (I know this board is fast), but I was only trying to help myself by searching before asking!

Have to check out one or two things with my host (my board seemed to be running better late last night) and will post a URL as soon as it's permanent (which should be as soon as the temporary sub-domain is replaced by the DNS redirection).
Logged

Pages: [1] Reply Ignore Print 
YaBB SE Community  |  English User Help  |  English Help  |  Most secure chmod settings? « previous - next »
 


Powered by MySQL Powered by PHP YaBB SE Community | Powered by YaBB SE
© 2001-2003, YaBB SE Dev Team. All Rights Reserved.
SMF 2.1.4 © 2023, Simple Machines
Valid XHTML 1.0! Valid CSS

Page created in 0.053 seconds with 21 queries.