Pixelpost

Authentic Photoblog Flavour


Go Back   Pixelpost Forum > SUPPORT / INFORMATION > Pixelpost Help

Post Reply
 
Thread Tools
  #11  
Old 06-28-2007, 09:12 PM
Hans Offline
forum loafer
 
Join Date: Jun 2007
Location: Netherlands
Posts: 13
Whatever is causing the security holes (hardware, software, bad set up etc) is not important. What is important is to be aware of the risks, and try to minimize that as much as possible. I am not a html, security or apache pro, which makes it even more important to realise that. For me, that's a reason to host my site with a professional hoster in stead of from my home. I tested it, it works from my home but I just don't have enough experience to make sure everything is safe.

Pixelpost is excellent software. For me, it blew new life into an old hobby.

I just wasn't sure about the folder settings, and my feeling appeared to be correct. Schonhose, thanks a lot for this FTP add-on, it makes me sleep better!
__________________
Hans @ http://www.okebaja.com/

Pixelpost version: 1.6.0
Reply With Quote
  #12  
Old 06-30-2007, 01:37 PM
GeoS's Avatar
GeoS+ Offline
Team Pixelpost
 
Join Date: Apr 2005
Location: Warsaw, Poland
Posts: 3,613
Send a message via ICQ to GeoS Send a message via Skype™ to GeoS
My suggestion for devs (hehe, for myself too) is to add warning somewhere in admin panel about risk of using 777 when there is no limitation where the scripts can be executed. Making it cleaner - hoster can limit enviroment of script to account of user (using one directive in config files of webenv) and when there isnt such solution and user has got folders with permissions 777 then there should be a warining.

Few of this php enviroment settings are:
open_basedir
user_dir
upload_tmp_dir
safe_mode_exec_dir
safe_mode_include_dir
__________________
photoblog | portfolio | addons | Donate
Reply With Quote
Post Reply


Thread Tools




All times are GMT. The time now is 07:25 PM.

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd. | Style Design: d3 designs