LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-06-2006, 08:04 AM   #1
bmzink
LQ Newbie
 
Registered: Feb 2006
Posts: 4

Rep: Reputation: 0
Writeable web content - permissions/membership


Hello,

I have some web content purchased from a vendor who designs e-commerce solutions. When the development was done they sent me the content on a CD.

There are 3 directories that need to be writeable by the webserver. What is the proper way to set these permissions so that this site is secure but still functional.

Please be detailed as far as group membership ideas as well.

Thank you,

Brett
 
Old 03-08-2006, 03:10 AM   #2
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49
Quote:
Originally Posted by bmzink
Hello,

I have some web content purchased from a vendor who designs e-commerce solutions. When the development was done they sent me the content on a CD.

There are 3 directories that need to be writeable by the webserver. What is the proper way to set these permissions so that this site is secure but still functional.

Please be detailed as far as group membership ideas as well.

Thank you,

Brett
Any developer worth his salt should have given you the necessary info on what is required on this issue. If the system is a php/mysql based package I strongly recommend that you implement mod-security into your apache server. Details available at www.modsecurity.org . Personally I would be very cautious with implementation of effectively untried and untested packages with little or no security track record because anything that is not secure will make you very vulnerable.
 
Old 03-08-2006, 06:57 AM   #3
bmzink
LQ Newbie
 
Registered: Feb 2006
Posts: 4

Original Poster
Rep: Reputation: 0
Thank you for the reply, I'm looking into modsecurity right now.

You're right the developers should be providing me with these details but they haven't been. When I asked them I was told that the subject was beyond the scope of technical support. Needless to say I haven't been happy with them ever since we paid the bill.

If anyone else has any input on this it would be greatly appreciated.

Thank you,
Brett
 
Old 03-08-2006, 03:51 PM   #4
TigerOC
Senior Member
 
Registered: Jan 2003
Location: Devon, UK
Distribution: Debian Etc/kernel 2.6.18-4K7
Posts: 2,380

Rep: Reputation: 49
I am no expert on this and have only one such program running on my system but the files that are written to are outside the document root and have 777 permissions. In this scenario you would need to set the configuration files so that they know where to find the files. Having them outside the document root (/var/www) means they are not exposed to or searchable by visitors and those with evil intent. Ownership would be assigned to the apache user.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
help with web content filtering/proxies Trio3b Linux - Security 2 02-08-2006 08:07 PM
copy content between 2 web sites jim656 Linux - Networking 5 11-08-2005 10:11 AM
web content filters paul_mat Linux - Software 2 10-11-2005 07:14 PM
world writeable files will not stay world writeable antken Mandriva 1 03-02-2004 05:04 PM
A couple of ?? about Web content filtering Blitzkrieg Linux - Software 1 11-25-2002 07:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:20 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration