Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > SUPPORT / INFORMATION > Pixelpost Help

Post Reply
 
Thread Tools
  #1  
Old 06-28-2007, 06:30 PM
Hans Offline
forum loafer
 
Join Date: Jun 2007
Location: Netherlands
Posts: 13
Folder permissions

How should the permissions of all folders be set in Pixelpost? I know that images and thumbnails must be set to 777, but how to set the others? Most others are set to 755, which seems too open..? (you may notice I am not an expert).

BTW Isn't 777 very risky? Can't other change my photo's because of that?

Thanks!
__________________
Hans @ http://www.okebaja.com/

Pixelpost version: 1.6.0
Reply With Quote
  #2  
Old 06-28-2007, 06:51 PM
Dennis's Avatar
Dennis+ Offline
Team Pixelpost
 
Join Date: Jul 2006
Posts: 2,394
Send a message via MSN to Dennis
The best way is to set all folders to 755. Try uploading an image now. If it does, then leave it.

If it doesn't change both the thumbnail and images folder to 775 and try again. If the file upload. Leave it. If it doesn't you need 777 on both the thumbnails and the image folders.

Please report your findings so we can help you further depending on the outcome.
__________________
My photoblog, powered by PixelPost 1.9 dev SVN | My Pixelpost Addons | My Cool Photoblog profile
Reply With Quote
  #3  
Old 06-28-2007, 07:44 PM
Hans Offline
forum loafer
 
Join Date: Jun 2007
Location: Netherlands
Posts: 13
Thanks for your suggestions. I have first changed permissions to 755, but were not able to upload images. At 775 it didn't work as well. Only 777 works. The same goes for the thumbnails folder.

Is this a security risk or am I too paranoid here?
__________________
Hans @ http://www.okebaja.com/

Pixelpost version: 1.6.0
Reply With Quote
  #4  
Old 06-28-2007, 08:05 PM
aat669 Offline
pp regular
 
Join Date: Mar 2006
Posts: 23
Hans, you're not being paranoid. My site was hacked 4 different times in a period of 6 months. I'm now running PP 1.6 (I recommend upgrading if you're running an older version) and I also installed Schonhose's FTP security addon which requires you to enter your password during the upload of your photo, temporarily sets your folder permission to 777 (to enable the upload) then it locks the folder back to 755 after you're finished. I also am careful to go to my Eleven2 Cpanel to double check and make sure my permissions are all set to 755 (secure).

Schonhose will probably remember the nightmare I had in getting my site back online. He and the Eleven folks helped me a lot, so from my experience I suggest doing what you can to make sure you're safe. Hackers completely took over my site each of the 4 times they got in. I'm just lucky that they didn't overwrite (or delete) all of my 300+ photos. :-)

Good luck!
Reply With Quote
  #5  
Old 06-28-2007, 08:24 PM
Hans Offline
forum loafer
 
Join Date: Jun 2007
Location: Netherlands
Posts: 13
Thanks for your extensive explanation. I am not very experienced in running websites, and that's exactly why I am concerned. My website is hosted at a professional webhoster, I didn't dare to run it from my home server.

It's good to know other people share my concerns. My photoblog is only online for 1 week or so, and so far I had no troubles. But I am making backups after each major change, just in case...

Thanks also for pointing out Schonhose's FTP add-on. I will immediately install it. Funny, I was checking out Pixelpost add-ons yesterday that might be interesting for me, but completely missed this one.
__________________
Hans @ http://www.okebaja.com/

Pixelpost version: 1.6.0
Reply With Quote
  #6  
Old 06-28-2007, 08:34 PM
Dennis's Avatar
Dennis+ Offline
Team Pixelpost
 
Join Date: Jul 2006
Posts: 2,394
Send a message via MSN to Dennis
aat669: there is no proof that your problems were caused by Pixelpost. If it was, a lot of other users would have the same problems you're having.

There are a lot of high-profile pixelpost sites out there attracting more visitors in a day than most of us in a month. We, as developers, have the current "beta" versions live on our blogs and we never have been hacked.

Please remember that. But nevertheless: try the FTP addon, read the documentation on how to set it up and contact me if you need any help.
__________________
My photoblog, powered by PixelPost 1.9 dev SVN | My Pixelpost Addons | My Cool Photoblog profile
Reply With Quote
  #7  
Old 06-28-2007, 08:46 PM
Hans Offline
forum loafer
 
Join Date: Jun 2007
Location: Netherlands
Posts: 13
Nothing bad about Pixelpost, I love the software.

I just installed your FTP add-on. When I click the 'Options' tab, my session hangs. Am I doing something wrong?
__________________
Hans @ http://www.okebaja.com/

Pixelpost version: 1.6.0
Reply With Quote
  #8  
Old 06-28-2007, 08:52 PM
Hans Offline
forum loafer
 
Join Date: Jun 2007
Location: Netherlands
Posts: 13
I have checked, and it's not the FTP add-on but the 'clickable tags' add-on that I installed at the same time that's causing this.

It says: Line 66, char 5: syntax error.

I removed the clickable tags add-on, Options page works as a charm including the FTP security tab.
__________________
Hans @ http://www.okebaja.com/

Pixelpost version: 1.6.0
Reply With Quote
  #9  
Old 06-28-2007, 09:01 PM
GeoS's Avatar
GeoS+ Offline
Team Pixelpost
 
Join Date: Apr 2005
Location: Warsaw, Poland
Posts: 3,613
Send a message via ICQ to GeoS Send a message via Skype™ to GeoS
From my point of view I know that the most of successful attacks are caused by mis-configurated boxes on which applications are running.
Adding to it bugs in software and behavior of users (unsafety) this gives much better enviroment for hackers to do their bussiness.

It was generally. We are trying to make Pixelpost as safe as it is possible but we cant be responsible for mistakes made by others.
__________________
photoblog | portfolio | addons | Donate
Reply With Quote
  #10  
Old 06-28-2007, 09:02 PM
aat669 Offline
pp regular
 
Join Date: Mar 2006
Posts: 23
Schon, I didn't say my hack problem was caused by Pixelpost. My post was only to help alert people to a potential security issue surrounding folder permissions. For people like myself who were not aware of the 777 versus 755 permission issue, I think it's only important to point that out. Which is the point for my reply to Hans.

And I'm aware that not everyone has been hacked, but doing a simple search on the forums returns several other people who had the exact problem I had. I won't include the links here, but I did find several that go back as far as Feb 2005. Whether it's a PP problem, host problem, or other, I don't know. That's not for me to say nor did I intend to imply anything in my previous post.
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 01:03 AM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. | Style Design: d3 designs