Results 1 to 5 of 5
  1. #1
    Join Date
    Feb 2006
    Posts
    130
    Plugin Contributions
    0

    Default Images Folder Permissions

    I recently upgraded to the latest version and am having some proiblems with the images folder re scuring it.

    My main images directory is laid out like this: whatever.com/store/images

    The admin folder is laid out thusly whatever.com/store/admin/ but with a different name per security instructions. The parameters for the different admin folder name have been set in the required files and everything is working fine other than the following:

    When I changed the images folder permissions to read only for for all (also tried just for group and public), as instructed in one of the files that talks about securing the site, none of the images would show up in the store to the customers.

    When I set permissions to read / write for public and read / write / execute for group, they still would not show up. I had to set permissions to 777 read / write / execute for admin group and public to get them to show.

    I am assuming this is BAD to leave it like that. How do I get the images to show up to the customer yet protect this folder from hacking?
    Last edited by LRS; 1 Jul 2007 at 03:32 AM.

  2. #2
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: Images Folder Permissions

    If you cannot set the directories to 755 ... speak to your host ...
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today!]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

  3. #3
    Join Date
    Feb 2006
    Posts
    130
    Plugin Contributions
    0

    Default Re: Images Folder Permissions

    Quote Originally Posted by Ajeh View Post
    If you cannot set the directories to 755 ... speak to your host ...
    The instructions on securing the site say to set the image folder to 644 --- not 755 -- Can I assume that is a typo and should read set the images FOLDER to 755 and the image FILES to 644?

    The images show up fine with the folder at 755 and the files at 644, but not with the folder at 644 or 744
    -------------------------------------

    https://www.zen-cart.com/tutorials/index.php?article=73

    "9. Protect your "images" and other folders
    During initial installation, you are advised to set your images folder to read/write, so that you can use the Admin interface to upload product/category images without having to use FTP for each one. Similar recommendations are made to other files for various reasons.

    However, leaving the images (or any other) folder in read/write mode means that hackers might be able to put malicious files in this (or other) folder(s) and thus create access points from which to attempt nasty exploits.

    Thus, once your site is built and your images have been created/loaded, you should drop the security down from read/write to read. ie: change from CHMOD 777 down to 644. "
    Last edited by LRS; 2 Jul 2007 at 05:30 AM.

  4. #4
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: Images Folder Permissions

    Quote Originally Posted by LRS View Post
    The instructions on securing the site say to set the image folder to 644 --- not 755 -- Can I assume that is a typo and should read set the images FOLDER to 755 and the image FILES to 644?
    You are correct, it is a typo and 755 permissions on any directory is strongly recommended. All files should work with permissions of 644.

    Note: some Mods require different settings so make sure to read any documentation within the Mod being used.

  5. #5
    Join Date
    Feb 2006
    Posts
    130
    Plugin Contributions
    0

    Default Re: Images Folder Permissions

    Thanks for the help to both of you!

 

 

Similar Threads

  1. Why do I need to change folder permissions 777 on the folder before install?
    By zhshji in forum Installing on a Linux/Unix Server
    Replies: 2
    Last Post: 5 Feb 2010, 01:04 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg