Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I'm poking around my shiny new Wordpress 3.0 install while wiating for web hosting support to get back to me. I've got issues with the uploads folder not working again and I'm not setting permissions on anything to 777! So I had a brainwave and I'm wondering if this will be safe:

 

wp-content/uploads folder set to 766 (so Group and World can Read/Write and not Execute)

.htaccess restricting uploads to JPG, PNG, GIF and denying PHP, HTML, HTM, SHTML, PL, JS

 

Is that safe? I don't want people to randomly add files as happened to me before and a hacker's phising page got my last hosting account shut down a few years back. Not sure what I'd do for themes though?

 

Also no Shell access.

Posted
The execute permission on directories is equivalent to the "list folder contents" permission in Windows, so you'll be wanting that one for your httpd user. You also won't be able to control the permission set on files that uploaded through Wordpress on the fly, you'll have to go over them later.
Posted
Who's your host? A lot of hosts come with suPHP installed these days, which basically means that scripts are run as the owner of the file, so you don't actually need to change any permissions at all. Much better than leaving your files open to writing. Of course, if your host doesn't have suPHP enabled, then you'll have to stick to CHMODing, sadly. :(

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...