<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[PunBB Forums - pun_repository security]]></title>
	<link rel="self" href="http://punbb.informer.com/forums/feed/atom/topic/21766/"/>
	<updated>2009-06-25T12:35:12Z</updated>
	<generator>PunBB</generator>
	<id>http://punbb.informer.com/forums/topic/21766/punrepository-security/</id>
		<entry>
			<title type="html"><![CDATA[Re: pun_repository security]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/128672/#p128672"/>
			<content type="html"><![CDATA[<p>When we developed pun_repository we faced an issue. If a user has only FTP access he can&#039;t delete an extension directory created via pun_repository. We decided to set permissions to 0777 to avoid this issue.</p>]]></content>
			<author>
				<name><![CDATA[Parpalak]]></name>
				<uri>http://punbb.informer.com/forums/user/13581/</uri>
			</author>
			<updated>2009-06-25T12:35:12Z</updated>
			<id>http://punbb.informer.com/forums/post/128672/#p128672</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: pun_repository security]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/128670/#p128670"/>
			<content type="html"><![CDATA[<div class="quotebox"><cite>Parpalak wrote:</cite><blockquote><p>The permissions for the &quot;cache&quot; directory should be 0777 too. This directory contains executable PHP code. So pun_repository isn&#039;t less secure than the whole forum.</p></blockquote></div><p>Those directories only need to be writable for the httpd user, not everyone.</p>]]></content>
			<author>
				<name><![CDATA[MattF]]></name>
				<uri>http://punbb.informer.com/forums/user/9938/</uri>
			</author>
			<updated>2009-06-25T11:53:06Z</updated>
			<id>http://punbb.informer.com/forums/post/128670/#p128670</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: pun_repository security]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/128669/#p128669"/>
			<content type="html"><![CDATA[<p>The permissions for the &quot;cache&quot; directory should be 0777 too. This directory contains executable PHP code. So pun_repository isn&#039;t less secure than the whole forum.</p>]]></content>
			<author>
				<name><![CDATA[Parpalak]]></name>
				<uri>http://punbb.informer.com/forums/user/13581/</uri>
			</author>
			<updated>2009-06-25T11:23:27Z</updated>
			<id>http://punbb.informer.com/forums/post/128669/#p128669</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: pun_repository security]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/128471/#p128471"/>
			<content type="html"><![CDATA[<p>yeah, we should manualy chmod from cpanel,,, <img src="http://punbb.informer.com/forums/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /> , ,maybe it should automatic chmod after instalation of extension,,, <img src="http://punbb.informer.com/forums/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /></p>]]></content>
			<author>
				<name><![CDATA[bejo]]></name>
				<uri>http://punbb.informer.com/forums/user/15204/</uri>
			</author>
			<updated>2009-06-14T06:57:09Z</updated>
			<id>http://punbb.informer.com/forums/post/128471/#p128471</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[pun_repository security]]></title>
			<link rel="alternate" href="http://punbb.informer.com/forums/post/128466/#p128466"/>
			<content type="html"><![CDATA[<p>In my opinion the phrase...<br /></p><div class="quotebox"><blockquote><p>NOTE! Web server&#039;s system user will be set as an owner of the files and directories created while extension downloading and installation. Access mode for directories created will be set to 0777.</p></blockquote></div><p>...isn&#039;t secure enough. It would be better idea to set it to 0755 (system user can do read,write,execute and all others just read and execute)</p><p>The reason why I&#039;m asking this, is because i&#039;m getting attacked by outside world repeatedly and my outdated pun_pm got hijacked by somebody and that made me to worry about others: the reason was the nasty chmod 777.</p>]]></content>
			<author>
				<name><![CDATA[ingram]]></name>
				<uri>http://punbb.informer.com/forums/user/13728/</uri>
			</author>
			<updated>2009-06-13T20:16:17Z</updated>
			<id>http://punbb.informer.com/forums/post/128466/#p128466</id>
		</entry>
</feed>
