<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[PunBB Forums - pun_repository security]]></title>
		<link>http://punbb.informer.com/forums/topic/21766/punrepository-security/</link>
		<description><![CDATA[The most recent posts in pun_repository security.]]></description>
		<lastBuildDate>Thu, 25 Jun 2009 12:35:12 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: pun_repository security]]></title>
			<link>http://punbb.informer.com/forums/post/128672/#p128672</link>
			<description><![CDATA[<p>When we developed pun_repository we faced an issue. If a user has only FTP access he can&#039;t delete an extension directory created via pun_repository. We decided to set permissions to 0777 to avoid this issue.</p>]]></description>
			<author><![CDATA[dummy@example.com (Parpalak)]]></author>
			<pubDate>Thu, 25 Jun 2009 12:35:12 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/128672/#p128672</guid>
		</item>
		<item>
			<title><![CDATA[Re: pun_repository security]]></title>
			<link>http://punbb.informer.com/forums/post/128670/#p128670</link>
			<description><![CDATA[<div class="quotebox"><cite>Parpalak wrote:</cite><blockquote><p>The permissions for the &quot;cache&quot; directory should be 0777 too. This directory contains executable PHP code. So pun_repository isn&#039;t less secure than the whole forum.</p></blockquote></div><p>Those directories only need to be writable for the httpd user, not everyone.</p>]]></description>
			<author><![CDATA[dummy@example.com (MattF)]]></author>
			<pubDate>Thu, 25 Jun 2009 11:53:06 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/128670/#p128670</guid>
		</item>
		<item>
			<title><![CDATA[Re: pun_repository security]]></title>
			<link>http://punbb.informer.com/forums/post/128669/#p128669</link>
			<description><![CDATA[<p>The permissions for the &quot;cache&quot; directory should be 0777 too. This directory contains executable PHP code. So pun_repository isn&#039;t less secure than the whole forum.</p>]]></description>
			<author><![CDATA[dummy@example.com (Parpalak)]]></author>
			<pubDate>Thu, 25 Jun 2009 11:23:27 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/128669/#p128669</guid>
		</item>
		<item>
			<title><![CDATA[Re: pun_repository security]]></title>
			<link>http://punbb.informer.com/forums/post/128471/#p128471</link>
			<description><![CDATA[<p>yeah, we should manualy chmod from cpanel,,, <img src="http://punbb.informer.com/forums/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /> , ,maybe it should automatic chmod after instalation of extension,,, <img src="http://punbb.informer.com/forums/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /></p>]]></description>
			<author><![CDATA[dummy@example.com (bejo)]]></author>
			<pubDate>Sun, 14 Jun 2009 06:57:09 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/128471/#p128471</guid>
		</item>
		<item>
			<title><![CDATA[pun_repository security]]></title>
			<link>http://punbb.informer.com/forums/post/128466/#p128466</link>
			<description><![CDATA[<p>In my opinion the phrase...<br /></p><div class="quotebox"><blockquote><p>NOTE! Web server&#039;s system user will be set as an owner of the files and directories created while extension downloading and installation. Access mode for directories created will be set to 0777.</p></blockquote></div><p>...isn&#039;t secure enough. It would be better idea to set it to 0755 (system user can do read,write,execute and all others just read and execute)</p><p>The reason why I&#039;m asking this, is because i&#039;m getting attacked by outside world repeatedly and my outdated pun_pm got hijacked by somebody and that made me to worry about others: the reason was the nasty chmod 777.</p>]]></description>
			<author><![CDATA[dummy@example.com (ingram)]]></author>
			<pubDate>Sat, 13 Jun 2009 20:16:17 +0000</pubDate>
			<guid>http://punbb.informer.com/forums/post/128466/#p128466</guid>
		</item>
	</channel>
</rss>
