Joomla! Discussion Forums



It is currently Tue Nov 24, 2009 7:25 pm (All times are UTC )

 


Forum rules

Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Security Checklist
Forum Post Assistant - If you are serious about wanting help, you will use this tool to help you post.



Post new topic Reply to topic  [ 4 posts ] 
Author Message
Posted: Thu Nov 05, 2009 5:16 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Dec 18, 2008 2:53 am
Posts: 4
Hi everyone,

There's a group agreement that permissions be set as follows:
Code:
directories 755
files 644


The issue becomes that the daily-admin can't upload her photos.

If the perms are adjusted for the images dir to:
Code:
images/ -type d -exec chmod 775 {} \;


The daily-admin can upload but doesn't this mean that anyone from the web could potentially write to the dir as well?


Top
  E-mail  
 
Posted: Thu Nov 05, 2009 5:33 pm 
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Aug 05, 2009 1:42 pm
Posts: 483
Greetings:

The file and directory permissions (i.e. 644, 755, etc.) are not directly tied to Joomla user's; they refer directly to the Web site user and potentially the user/group of the web server.

777 permissions means anyone can access.

Thank you.

_________________
Peter M. Abraham
http://www.dynamicnet.net/ - Dynamic Net, Inc. - in business since June 1995; a PCI Compliant, managed hosting provider.


Top
  E-mail  
 
Posted: Thu Nov 05, 2009 5:52 pm 
Joomla! Fledgling
Joomla! Fledgling
Offline

Joined: Thu Dec 18, 2008 2:53 am
Posts: 4
Thanks for replying.

Yes, I understand that.

Hopefully I can clarify. If the images dir is:
Code:
drwxrwxr-x (775)   foo_owner    web_group    images


Doesn't this mean that anyone from the web_group could potentially write to the images directory as well since any web_visitor would be part of the web_group on the box?


Top
  E-mail  
 
Posted: Thu Nov 05, 2009 9:14 pm 
Joomla! Explorer
Joomla! Explorer
Offline

Joined: Wed Aug 05, 2009 1:42 pm
Posts: 483
Greetings:

Yes, anyone from webgrup could write to the image directory.

Thank you.

_________________
Peter M. Abraham
http://www.dynamicnet.net/ - Dynamic Net, Inc. - in business since June 1995; a PCI Compliant, managed hosting provider.


Top
  E-mail  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

Quick reply

 



Who is online

Users browsing this forum: adribabe, chetanmadaan, xalu and 42 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group