Unwriteable? Should they be Writable?

Discussion regarding Joomla! 1.5 security issues.
Joomla! Vulnerable Extensions: http://feeds.joomla.org/JoomlaSecurityV ... Extensions

Moderator: General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.
Locked
FSJM1
Joomla! Apprentice
Joomla! Apprentice
Posts: 12
Joined: Fri Jan 16, 2009 6:40 pm

Unwriteable? Should they be Writable?

Post by FSJM1 » Mon Jan 19, 2009 3:20 am

I am new to Joomla and was curious to know what permissions you all leave your folders and files as? Do you leave them as 644 CHMOD which makes them unwritable to the system? Or do you 755 or even 777 them?

I currently switch them to 777, then change them back. Is it ok to leave them like this? Is there another permission that you leave all of the files at so you can easily upload without having to constantly adjust CHMOD rules without the worry of being hacked?

User avatar
musiczineguy
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 200
Joined: Sat Nov 11, 2006 5:01 am
Location: East Greenbush, NY
Contact:

Re: Unwriteable? Should they be Writable?

Post by musiczineguy » Mon Jan 19, 2009 3:29 am

FSJM1 wrote:I am new to Joomla and was curious to know what permissions you all leave your folders and files as? Do you leave them as 644 CHMOD which makes them unwritable to the system? Or do you 755 or even 777 them?

I currently switch them to 777, then change them back. Is it ok to leave them like this? Is there another permission that you leave all of the files at so you can easily upload without having to constantly adjust CHMOD rules without the worry of being hacked?
The general consensus is that Folders should be set at 755 and files at 644. There are various times when you need to change these permissions, depending on your hosting situation, but the 755/folder 644/file scheme is a good rule of thumb.

I also set configuration.php to 444 .. Joomla 1.5.x seems to be able to change the permissions, overwrite and then reset the permissions on this very important file.

FSJM1
Joomla! Apprentice
Joomla! Apprentice
Posts: 12
Joined: Fri Jan 16, 2009 6:40 pm

Re: Unwriteable? Should they be Writable?

Post by FSJM1 » Mon Jan 19, 2009 3:46 am

I tested 755, and then went to Admin>Sys Info> Directory Permissions and they stay as unwritable. Any ideas why?

User avatar
twcmex
Joomla! Guru
Joomla! Guru
Posts: 551
Joined: Sat Dec 16, 2006 10:35 pm
Location: Durango, Mexico

Re: Unwriteable? Should they be Writable?

Post by twcmex » Tue Jan 20, 2009 2:39 am

This may help explain what is happening:

http://community.joomla.org/blogs/leade ... -time.html

(point #2)
-Joe


Locked

Return to “Security in Joomla! 1.5”