Elevated, Reverting Permissions - Joomla! Forum - community, help and support
host configuration :: os: linux | os version: 2.6.18-308.8.2.el5 | technology: i686 | web server: apache | encoding: gzip,deflate,sdch | | system tmp writable: yes
php configuration :: version: 5.2.17 | php api: apache2handler | session path writable: unknown | display errors: | error reporting: 6143 | log errors to: /usr/local/zend/var/log/php.log | last known error: 29th november 2012 14:59:37. | register globals: | magic quotes: | safe mode: | open base: | uploads: 1 | max. upload size: 32m | max. post size: 40m | max. input time: 60 | max. execution time: 30 | memory limit: 128m
mysql configuration :: version: 5.1.41-community (client:5.1.41) | host: --protected-- (--protected--) | collation: utf8_general_ci (character set: utf8) | database size: 2.38 mib | #of tables: 140[/size][/quote]
hello,
i have been attempting take old site here @ university straight html/css onto cms platform, joomla 2.5.8 installed , running. however, server environment here not behave have dealt on outside, 3rd party hosting. university's recommends 750 on dir , 640 on files, have been told 770 acceptable well. permission renders of necessary joomla directories appropriately writeable on backend. use backend however, such upload image or module/component, directory reverts 777. attempt change 770, , few minutes later shows 777 again. true 755. if put 750 on it, backend functionality no longer works. there these directories have "group" writable in order work.
i not server expert in way. have apache2handler? because area site @ college can hosted on (in order have appropriate .edu extension) implication of this? i'm afraid may mean cannot or should not use joomla in environment. know 777 major no-no, implication site extremely vulnerable malicious activity? give me resolving appreciated...
php configuration :: version: 5.2.17 | php api: apache2handler | session path writable: unknown | display errors: | error reporting: 6143 | log errors to: /usr/local/zend/var/log/php.log | last known error: 29th november 2012 14:59:37. | register globals: | magic quotes: | safe mode: | open base: | uploads: 1 | max. upload size: 32m | max. post size: 40m | max. input time: 60 | max. execution time: 30 | memory limit: 128m
mysql configuration :: version: 5.1.41-community (client:5.1.41) | host: --protected-- (--protected--) | collation: utf8_general_ci (character set: utf8) | database size: 2.38 mib | #of tables: 140[/size][/quote]
detailed environment :: wrote:php extensions :: date (5.2.17) | libxml () | openssl () | pcre () | zlib (1.1) | dom (20031129) | filter (0.11.0) | hash (1.0) | iconv () | simplexml (0.1) | spl (0.2) | pdo (1.0.4dev) | reflection (0.1) | session () | pdo_sqlite (1.0.1) | standard (5.2.17) | xml () | xmlreader (0.1) | xmlwriter (0.1) | apache2handler () | bcmath () | bz2 () | calendar () | ctype () | curl () | exif (1.4 $id: exif.c 293036 2010-01-03 09:23:27z sebastian $) | ftp () | gd () | gettext () | imap () | intl (1.1.2) | json (1.2.1) | ldap () | mbstring () | mcrypt () | mhash () | mime_magic (0.1) | mysql (1.0) | mysqli (0.1) | oci8 (1.4.6) | pdo_mysql (1.0.2) | pdo_oci (1.0.1) | pdo_pgsql (1.0.2) | pgsql () | posix () | soap () | sockets () | sqlite (2.0-dev) | tidy (2.0) | tokenizer (0.1) | xsl (0.1) | zip (1.8.11) | zend data cache () | apc () | zend job queue (4.0) | zend session clustering () | zend utils () | zend debugger () | zend engine (2.2.0) |
potential missing extensions :: suhosin |
color=#000000]elevated permissions (first 10) :: [/color]administrator/ (770) | administrator/cache/ (777) | administrator/components/ (777) | administrator/components/com_admin/ (770) | administrator/components/com_admin/controllers/ (770) | administrator/components/com_admin/helpers/ (770) | administrator/components/com_admin/helpers/html/ (770) | administrator/components/com_admin/models/ (770) | administrator/components/com_admin/models/forms/ (770) | administrator/components/com_admin/sql/ (770) |
[/quote]templates discovered :: wrote:templates :: site :: atomic (2.5.0) | beez5 (2.5.0) | beez_20 (2.5.0) | jb high line (2.2.1) |
templates :: admin :: bluestork (2.5.0) | hathor (2.5.0) |
hello,
i have been attempting take old site here @ university straight html/css onto cms platform, joomla 2.5.8 installed , running. however, server environment here not behave have dealt on outside, 3rd party hosting. university's recommends 750 on dir , 640 on files, have been told 770 acceptable well. permission renders of necessary joomla directories appropriately writeable on backend. use backend however, such upload image or module/component, directory reverts 777. attempt change 770, , few minutes later shows 777 again. true 755. if put 750 on it, backend functionality no longer works. there these directories have "group" writable in order work.
i not server expert in way. have apache2handler? because area site @ college can hosted on (in order have appropriate .edu extension) implication of this? i'm afraid may mean cannot or should not use joomla in environment. know 777 major no-no, implication site extremely vulnerable malicious activity? give me resolving appreciated...
not sure got partial fpa info from, looks partially broken. viewtopic.php?f=621&t=582860
the use of apache2handler instead of cgi-fcgi suexec or equivalent can cause ownership issues lead permissions issues seeing when can not write directories @ 750 can @ 770.
from descriptions, server not set , sounds if permissions mask set improperly since server seems setting 777 permissions. possibility is hacked.
640 (files) , 750 (directories) acceptable (normal 644 , 755) if server keep settings apparently not.
for better understanding of permissions read "how unix file permissions work?" , "how phpsuexec file permissions work?" articles linked in document:
http://docs.joomla.org/security_checkli ... issions%3f
the use of apache2handler instead of cgi-fcgi suexec or equivalent can cause ownership issues lead permissions issues seeing when can not write directories @ 750 can @ 770.
from descriptions, server not set , sounds if permissions mask set improperly since server seems setting 777 permissions. possibility is hacked.
640 (files) , 750 (directories) acceptable (normal 644 , 755) if server keep settings apparently not.
for better understanding of permissions read "how unix file permissions work?" , "how phpsuexec file permissions work?" articles linked in document:
http://docs.joomla.org/security_checkli ... issions%3f
Comments
Post a Comment