Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Coding Forum


You are currently viewing our Coding Forum as a guest. Please register to participate.
Login



Reply
chmod html files to 666 - risks ?
Old 11-18-2002, 09:16 AM chmod html files to 666 - risks ?
Novice Talker

Posts: 5
Trades: 0
What exactly are the risks involved in making HTML files world writeable ?

I have a CGI script which allows a user to edit an html file after they enter a password. For this purpose, the file must be CHMOD'ed to 666. The password only protects access to use the script and there is no .htaccess type password protection on the file or directory at all.

Can anyone tell me what security risks this poses ? Could someone make changes to the files or delete them ?

Thanks.
tcuk is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 11-18-2002, 10:22 AM
conkermaniac's Avatar
The Nutty Moderator

Posts: 1,012
Location: China
Trades: 0
Hi tcuk,

I do not know what specific risks this poses, but I certainly would not try to CHMOD any HTML file to 666. I am pretty sure that the results could be devastating. I would only recommend doing so if the file is a script, but in this case, my suggestion: don't do it.
__________________

Please login or register to view this content. Registration is FREE
- Affordable feature-packed remotely hosted message boards!
conkermaniac is offline
Reply With Quote
View Public Profile
 
Old 11-18-2002, 10:31 AM
Novice Talker

Posts: 5
Trades: 0
Thanks for your reply. I could do with a more detailed explanation from someone if possible.
tcuk is offline
Reply With Quote
View Public Profile
 
Old 11-19-2002, 02:58 AM
Mo Money's Avatar
Extreme Talker

Posts: 229
Location: Cali
Trades: 0
oh ****, Ive been doing 666 and 777 all the time!?!?!?1 AAAAAAA why is this a danger??
__________________

Please login or register to view this content. Registration is FREE
- Free Internet Games!
Mo Money is offline
Reply With Quote
View Public Profile
 
Old 11-19-2002, 09:12 AM
Novice Talker

Posts: 5
Trades: 0
Its not a danger. Ive posted this question in a few other places and the answer is...

666 is fine. The only way you can gain write access to the file is if you have ftp / shell access (admin) to the server or you are using a script that runs from the server itself.

I'm using a script which is password protected.

Even though 666 allows write permissions to all - you still have to have direct access to the file on the server to make changes to it.

So 666 is ok.

It's worth mentioning that there is no point in making any files writeable unless a process / script requires it.
tcuk is offline
Reply With Quote
View Public Profile
 
Old 11-21-2002, 04:58 PM
Novice Talker

Posts: 12
Location: Kenya, Africa
Trades: 0
Just do not do it because with the way technology is going you may never know who hacks to it. So stay away from granting such a permission.
wambui is offline
Reply With Quote
View Public Profile
 
Old 11-21-2002, 05:22 PM
Novice Talker

Posts: 5
Trades: 0
I have added some code to my script which changes the permissions of the file after it is saved so its more secure now.
tcuk is offline
Reply With Quote
View Public Profile
 
Old 11-21-2002, 05:27 PM
Novice Talker

Posts: 12
Location: Kenya, Africa
Trades: 0
good for you.
wambui is offline
Reply With Quote
View Public Profile
 
Old 11-22-2002, 09:52 AM
conkermaniac's Avatar
The Nutty Moderator

Posts: 1,012
Location: China
Trades: 0
Hi,

Thanks for the info, tcuk, but I would still agree with wambui. You never know what determined hackers might do - especially if they have read this post and know that you have such permissions set.
__________________

Please login or register to view this content. Registration is FREE
- Affordable feature-packed remotely hosted message boards!
conkermaniac is offline
Reply With Quote
View Public Profile
 
Old 11-22-2002, 11:30 AM
Novice Talker

Posts: 5
Trades: 0
They would have to know what domains I'm using and tbh it would take a very very highly skilled hacker to do this.
My domains are not worth anything to a hacker of that calibre...

NASA on the other hand, is a different story.
tcuk is offline
Reply With Quote
View Public Profile
 
Old 11-22-2002, 01:33 PM
Novice Talker

Posts: 12
Location: Kenya, Africa
Trades: 0
I agree they have to know the domain but people find things all the time though. And you may never know when they hacked so to be very save do not grant such pemissions.
wambui is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to chmod html files to 666 - risks ?
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.69610 seconds with 12 queries