CHMOD Permissions with attachments folder

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • MadK
    Member
    • Feb 2008
    • 99
    • 3.7.x

    [Forum] CHMOD Permissions with attachments folder

    Hey there everybody, I hope you're doing great!

    I'm sending you this message because when I am moving my attachments from my database to the filesystem, it seems like my attachments folder, which is set to 0777 CHMOD is easily accessible by anyone who types it in in the URL bar.

    I have tried setting the permissions to 711, but no to avail.

    I thought that I could set it to 750, would that fix it?

    Thank you very much for your help and have an awesome day!
  • Andy
    Senior Member
    • Jan 2002
    • 5886
    • 4.1.x

    #2
    If you are moving attachments into the file system, it is recommended that you do *not* place the folder under your web root (usually named public_html or www or www_root) because people will be able to bypass vBulletin's permission system and download them.

    Comment

    • reefland
      Senior Member
      • Sep 2000
      • 1131

      #3
      What is the concern with directly accessing the directory or files within it?
      sigpic
      Nation of Blue - Kentucky Wildcats Sports


      Some CMS Goodness: Add Avatar to Article

      Comment

      • MadK
        Member
        • Feb 2008
        • 99
        • 3.7.x

        #4
        Originally posted by Andy
        If you are moving attachments into the file system, it is recommended that you do *not* place the folder under your web root (usually named public_html or www or www_root) because people will be able to bypass vBulletin's permission system and download them.
        Is there a way however that I can have the attachments folder in the web root with the appropriate CHMOD permissions? Maybe with .htaccess?

        Originally posted by reefland
        What is the concern with directly accessing the directory or files within it?
        Having private forums where attachments are saved for instance, as to avoid any permission bypass like Andy mentioned.

        Comment

        • Ponydaddy
          New Member
          • Aug 2011
          • 13
          • 4.1.x

          #5
          Originally posted by MadK
          Hey there everybody, I hope you're doing great!

          I'm sending you this message because when I am moving my attachments from my database to the filesystem, it seems like my attachments folder, which is set to 0777 CHMOD is easily accessible by anyone who types it in in the URL bar.

          I have tried setting the permissions to 711, but no to avail.

          I thought that I could set it to 750, would that fix it?

          Thank you very much for your help and have an awesome day!
          can you tell me what i should type to see if it works on my forums want to make sure it cant be accessed
          Last edited by Ponydaddy; Thu 4 Aug '11, 7:26pm.

          Comment

          • MadK
            Member
            • Feb 2008
            • 99
            • 3.7.x

            #6
            Originally posted by Ponydaddy
            can you tell me what i should type to see if it works on my forums what to make sure it cant be accessed
            Sorry man, this forum is still in development stage and as such I would like to keep it private!

            Comment

            • Andy
              Senior Member
              • Jan 2002
              • 5886
              • 4.1.x

              #7
              Originally posted by MadK
              Is there a way however that I can have the attachments folder in the web root with the appropriate CHMOD permissions? Maybe with .htaccess?
              Not that I'm aware of. Why not just put the folder above under your web root as suggested?

              Comment

              • Ponydaddy
                New Member
                • Aug 2011
                • 13
                • 4.1.x

                #8
                Originally posted by MadK
                Sorry man, this forum is still in development stage and as such I would like to keep it private!
                Was not talking about your fourms read what I posted

                Comment

                widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
                Working...