I presume I need to chmod something... ?# Serendipity ships world-writeable (777) to make installation easier.
# After the install is complete, you should change those base permissions to allow only your web-server user (e.g. nobody) to access the serendipity directory. All subdirectories should be writeable for the web-server user, all the files should be 644, unless otherwise contained in our installation archive.
security help..
security help..
Could someone explain this in a little more detail?
-
garvinhicking
- Core Developer
- Posts: 30022
- Joined: Tue Sep 16, 2003 9:45 pm
- Location: Cologne, Germany
- Contact:
Re: security help..
Yes, you should basically change the permissions so that only the webserver and your FTP user can read files.
The core directory serendipity/, the uploads/ folder, the templates_c/ folder and the files .htaccess and serendipity_config_local.inc.php must also be WRITABLE for the webserver user. Other files do NOT need to be writable for PHP/Webserver. Depending on your setup this would be 644 for most files, and only 664 or 666 for other files (744, 777 for directories).
If you plan to use Spartacus plugin, your plugins/ folder also needs to be writable.
Regards,
Garvin
The core directory serendipity/, the uploads/ folder, the templates_c/ folder and the files .htaccess and serendipity_config_local.inc.php must also be WRITABLE for the webserver user. Other files do NOT need to be writable for PHP/Webserver. Depending on your setup this would be 644 for most files, and only 664 or 666 for other files (744, 777 for directories).
If you plan to use Spartacus plugin, your plugins/ folder also needs to be writable.
Regards,
Garvin
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/