coppermine-gallery.com/forum

Support => cpg1.4.x Support => Older/other versions => cpg1.4 upgrading => Topic started by: Eric Chadwick on January 26, 2008, 06:35:44 PM

Title: versioncheck says 755 is an unnecessary risk?
Post by: Eric Chadwick on January 26, 2008, 06:35:44 PM
After upgrading from 1.4.12 to 1.4.14, I ran update.php and it finished without errors.

Then I ran versioncheck.php and everything was good except some folders have this warning:

Folder writable
The folder "bridge" is writable. This is an unnecessary risk, coppermine only needs read/execute access.


The offending folders are set 755, so does this mean Owner Write permission is considered a risk? If I changed them to 555 (read/execute only), wouldn't that also prevent the admin (me) from editing these folders?
Title: Re: versioncheck says 755 is an unnecessary risk?
Post by: Nibbler on January 26, 2008, 06:40:23 PM
You don't need to edit them normally. If you do you can just change the permissions temporarily.
Title: Re: versioncheck says 755 is an unnecessary risk?
Post by: Eric Chadwick on January 27, 2008, 07:25:07 PM
Thanks Nibbler.

Hmm, it seems my host is forcing them back to 755. I'll check this out with them, but I'm curious how much of a risk these folders might be?

Title: Re: versioncheck says 755 is an unnecessary risk?
Post by: Joachim Müller on January 28, 2008, 09:31:51 AM
Don't worry: the risk is small. If your webhost has made his homeworks and set up the server properly, shielding the presences on the server against each other, then there is no security risk at all.
Read up Why chmod 777 is NOT a security risk (http://www.simplemachines.org/community/index.php?topic=2987.0)