Security hazard using chmod o+rw on webserver?

Security hazard using chmod o+rw on webserver?

Post by Robert Karlss » Wed, 27 Feb 2002 00:04:23



Hi,

I host a webserver and use PHP to enable people to upload work to my
server. I use Linux and is unsecure if I am a complete nutcase using
chmod o+rw to a catalogue (/uploaded) to let people store their PDF
files there.

If this is the wrong approach, how should I do (I am pretty new to
Linux, so go for the easy version...)

Thanks
Robert

 
 
 

Security hazard using chmod o+rw on webserver?

Post by nord » Wed, 27 Feb 2002 02:20:18



> Hi,

> I host a webserver and use PHP to enable people to upload work to my
> server. I use Linux and is unsecure if I am a complete nutcase using
> chmod o+rw to a catalogue (/uploaded) to let people store their PDF
> files there.
> If this is the wrong approach, how should I do (I am pretty new to
> Linux, so go for the easy version...)

You allow _all_ users to write to this directory. It would be better to put
them all in one group and then do a chmod g+rw for this dir. But this will
still allow people to delete other peoples files (because deleting means
changing the folder, not the file). If you don't want people to do this,
you need to set the sticky bit. Then you would get chmod g+rwt.

Hope this helps
nordi

--
"Computers are useless. They can only give you answers."
Pablo Picasso

 
 
 

1. chargen : security hazard ?

Hello,

Can anyone tell me if leaving harmless service port open is a security hazard
?

Regards,

 -----  Posted via NewsOne.Net: Free (anonymous) Usenet News via the Web  -----
  http://newsone.net/ -- Free reading and anonymous posting to 60,000+ groups
   NewsOne.Net prohibits users from posting spam.  If this or other posts

2. Intel EtherExpress Pro10+

3. Is syslogd a security hazard?

4. Sun 100BaseT adapter cards - any users

5. is /usr/bin/passwd as a shell a security-hazard?

6. Secure comms

7. (Almost) Every port closed; still a security hazard?

8. utils for reading syslog files?

9. chmod question; chmod a-x /bin/chmod?

10. I want FTP default to be -rwxrwxrwx files, NOT system default like -rw-rw-rw- files !

11. A SIMPLE SHELL PROGRAM CHANGE /etc/passwd mode to -rw-rw-rw-

12. File permission set to -rw-rw-rw-?by Apache/CGI?

13. flexlm on HPs requires rw-rw-rw- on /dev/lan0