Results 1 to 5 of 5
  1. #1
    Join Date
    Aug 2006
    Posts
    20
    Plugin Contributions
    0

    Default Permissions on site

    Hi,

    once i have the site as is, what are the most secure permissions to use on each folder?

    would 444 be the best for files with a few exceptions? what exception will they be?

    my site does not have any uploads or downloads, i will upload images via ssh/sftp, so will give myself the correct permissions as i need them.

    can i get away with 400 for both configure.php files?

    is there anything else i can do on a file level that will aid the security of my site?


    is there anything database level i need to consider?

    I'm just thinking about this as i want to minimise the attack surface of my site.

    Many Thanks

    Alan

  2. #2
    Join Date
    Oct 2006
    Location
    Alberta, Canada
    Posts
    4,571
    Plugin Contributions
    1

    Default Re: Permissions on site

    755 for directories
    644 for files

    As you will be changing permissions as needed at the time, you can use the above for most anything. Very secure and no problems for Visitors accessing what they need.

    For yourself when working in the Admin section and/or using the Template overrides, you will definitely need to change permissions but in some areas, you can leave permissions a little bit more open. Visit this thread for more info, Template overrides clarification.

  3. #3
    Join Date
    Aug 2006
    Posts
    20
    Plugin Contributions
    0

    Default Re: Permissions on site

    wouldn't having 644 open me up to potential attacks? as the files will be writeable by the owner (my account)

    just thinking about any theoretical apache attacks

    Alan

  4. #4
    Join Date
    Oct 2005
    Posts
    115
    Plugin Contributions
    0

    Default Re: Permissions on site

    Just an advice for who is using linux or unix servers= with my experience i would recomend to use only windows if youre using zen or cubecart ,, for oscommerce its ok because i was first using windows without problem but wen i changed to a linux server i get all type of permission dinied error but some only fix wen i use 077 permisions while some will only apcept 777 and some 644 and belive it or not= some i have not yet managed to fix

  5. #5
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: Permissions on site

    NOTE: You have much less control on windows servers than on unix servers ...

    Zen Cart is best used on unix servers, not on windows servers ...
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today: v1.5.5]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

 

 

Similar Threads

  1. v151 Permissions
    By jfuller in forum Installing on a Linux/Unix Server
    Replies: 3
    Last Post: 22 Jan 2013, 04:16 PM
  2. permissions
    By neilowens in forum Installing on a Windows Server
    Replies: 2
    Last Post: 9 Jul 2007, 05:39 PM
  3. permissions
    By wwwben in forum General Questions
    Replies: 2
    Last Post: 15 Mar 2007, 05:10 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR