Results 1 to 2 of 2
  1. #1
    Join Date
    Dec 2004
    Posts
    21
    Plugin Contributions
    0

    Default File access permissions

    Recently my ISP started using suPHP. As a result I got error message that my configure.php is writable on the top of my web site. I changed permissions from 755 into
    511 and the message dissapeared. What is the minimal setting that I can set the permissions to?
    Are there any files that need to be writable at all times? Unless I am editing the site I would like to set everything in to 500 or 511. Would ZeCart work?

    Regards

    George

  2. #2
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: File access permissions

    Moving this thread to the Installation forum.


    For files, the minimum is really dependent on your server's configuration, and EVERY one is different.

    For files, 644 is common, 444 is usually used for tighter systems, and even 400 may work in limited cases.
    For files that need to be processed directly by the browser, they need to be at least 500 to work (the 5 means read and eXecute)

    Folders are typically 755 (most common), with 655 or 644 being next in line if your server dictates such a need.

    The only folders that would need to be 777 would be:
    - cache -- if using file-based sql/session caching
    - images/uploads -- if allowing customers to upload files
    - admin/images/graphs -- if you want the admin to generate graphs for banner-usage data
    All the other folders that our docs recommend 777 for are really only needed at 777 if you are editing or uploading files via the Admin area. If you use FTP instead, they can be set to lower values for better security.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

 

 

Similar Threads

  1. v150 an attempt was made to access a socket in a way forbidden by its access permissions.
    By inder_gwl in forum Installing on a Windows Server
    Replies: 0
    Last Post: 25 Mar 2012, 05:13 PM
  2. file permissions
    By wolfmoon in forum General Questions
    Replies: 1
    Last Post: 9 Sep 2009, 09:55 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR