Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 7 of 7

This is a discussion on Permissions on www and public html folders? in the Shared & Semi-Dedicated forum
For best security, what should the permissions for these two folders be? I've been reading a lot about hacked sites lately, and decided it's time ...

  1. #1
    Aletia Club Member Automile's Avatar
    Join Date
    Oct 2002
    Posts
    192

    Permissions on www and public html folders?

    For best security, what should the permissions for these two folders be?

    I've been reading a lot about hacked sites lately, and decided it's time to take a closer look at my settings.

    Thanks,
    Andy

    Edit to add: I don't have anyone uploading anything to the site, just the normal page updates which I do with my html editor.
    Last edited by Automile; 02-03-2009 at 06:13 AM. Reason: Add more info

  2. #2
    JPC Dream Team
    Join Date
    May 2007
    Location
    JPC
    Posts
    635
    Do you have a cPanel account. The default permissions of public_html folder in cPanel setup is 750 which is recommended. All folders inside public_html should have permission set as 755, with regular files having 644. www is a symbolic link so you should not be worried about that. Please open a support ticket so that we can set the correct permissions for your entire account.
    Jawad A.
    JaguarPC
    Site Links:
    Knowledge Base | Network Status

  3. #3
    Aletia Club Member Automile's Avatar
    Join Date
    Oct 2002
    Posts
    192
    Thanks Jawad. Yes, I have a CPanel account, and the public_html folder is set for 750. The access-logs and www folders are 777, which concerned me and prompted my question.

    Other than those two, everything else is OK.

    Would it hurt anything to set www to 750 as well? How about the access-logs?

    Andy

  4. #4
    JPC Dream Team
    Join Date
    May 2007
    Location
    JPC
    Posts
    635
    Quote Originally Posted by Automile View Post
    Thanks Jawad. Yes, I have a CPanel account, and the public_html folder is set for 750. The access-logs and www folders are 777, which concerned me and prompted my question.

    Other than those two, everything else is OK.

    Would it hurt anything to set www to 750 as well? How about the access-logs?

    Andy
    Both access-logs and www are symbolic links and not actual folders, similar to a shortcut in Windows. You do not need to change their permissions.
    Jawad A.
    JaguarPC
    Site Links:
    Knowledge Base | Network Status

  5. #5
    Community Leader jason's Avatar
    Join Date
    Sep 2001
    Location
    Rochester, NY
    Posts
    6,003
    To add to this, cPanel accounts run in a chrooted environment (cP uses the term "JailShell"). This means that users can only see what the admins want them to see which, in this case, excludes other accounts on the server. Since all scripts in users' accounts run under the user id of the account owner and since that user can't see other accounts, JPC's setup makes it extremely difficult for a site to be compromised as the result of another account on the server being exploited.

    Its never a bad thing to be dilligent--even paranoid, perhaps--about server security, but you can also rest assured that JPC's setup is about as well protected as you can get on a shared server.

    --Jason
    Jason Pitoniak
    Interbrite Communications
    www.interbrite.com www.kodiakskorner.com

  6. #6
    JPC Member
    Join Date
    Feb 2009
    Posts
    1
    How it may possible to hacked a secure linux hosting network

  7. #7
    the Windlord Gwaihir's Avatar
    Join Date
    Jun 2002
    Posts
    2,562
    What makes you assume each account is secure?

    There are no doubt people who run software in their account that is not secure. In particular people who install something and then never update it for years, even though security flaws have been discovered and updates with fixes were made available. If you use a popular bulletin board, photo gallery, etc, etc, in your account, you must update it from time to time, as known holes will sooner or later be exploited.
    Regards,

    Wim Heemskerk
    ---
    Visit MeCCG.net - Cardgaming in J.R.R. Tolkien's Middle-earth
    And Gwaihir.net - The Middle-earth CCG store

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •