I find this FAQ to be very helpful as security tightening checklist. However, while it calls for the following directories to have world-readable permissions (777):
./cache
./pub
./images
./includes/languages/english/html_includes
./admin/backups
./admin/images/graphs
I discovered that in my web host's (shared) account they are all set to 755 - and Zen Cart works perfectly. My web host is using suPHP (note that this is neither SUEXEC nor PHPSUEXEC but rather a 3rd variant).
Does that mean the FAQ needs to be corrected?
I would say 'updated' as opposed to 'corrected'. The statement/FAQ was probably written at time when using any varient of 'suexe' for PHP was not as popular as it is now. It wasn't too long ago when running PHP as an Apache module was the norm. This also goes back to what I stated in Post #6 of this thread; regarding wide open permission and making hacking so easy. This is part of the reasoning behind running PHP as CGI. It is much more secure and a lot less hacking going on. :wink:
The problem though, with updating the FAQ you mentioned, is trying to explain to non-technical people how to figure out if PHP is run as CGI. I can only presume it will happen at some point.
What I intend to run is the following (in this exact sequence):
cd ~/public_html/<catalog>
find . -type d -exec chmod -R 755 {} ;
find . -type f -exec chmod 644 {} ;
chmod 444 ./includes/configure.php
chmod 444 ./admin/includes/configure.php
Do you notice any problem with the above?
As 'find' is recursive by nature, you do not need the -R switch.
Also, due to the sweeping nature of the 'find' command, many find using the full path helps to prevent errors.
Note; run these commands one at a time and wait till finished.
find /home/userID/public_html/zencartDir/ -type d -exec chmod 0755
find /home/userID/public_html/zencartDir/ -type f -exec chmod 0644
chmod 0444 /home/userID/public_html/zencartDir/includes/configure.php
chmod 0444 /home/userID/public_html/zencartDir/admin/includes/configure.php
It does make it easy as well when using the 'history' command and also saves having to jump all over the place from using using the 'cd' command -- at least from a Server Admin POV. :smile:
The learning is in the doing.
Potent Products