.htaccess permissions

Discussion in 'Apache' started by Ozzie2008, Oct 20, 2009.

  1. #1
    I've just installed a php/mysql link cloaker script. The script requires the .htaccess file to be set to 766. Is there a security issue here? If yes, can I keep the .htaccess permissions set at 766 and add something to close any potential security holes that it might create? Thanks.
     
    Ozzie2008, Oct 20, 2009 IP
  2. szalinski

    szalinski Peon

    Messages:
    341
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #2
    does the script documentation explain why it needs your htaccess to be chmodded like so? since it doesn't make sense why you would need to go to such extremes to cloak links. normally the htaccess should be chmodded 644 by default, so even though i can't tell you what the security issues would be, there is a possibility.
     
    szalinski, Oct 21, 2009 IP
  3. joebert

    joebert Well-Known Member

    Messages:
    2,150
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    145
    #3
    It depends on the environment really. 766 is usually something you should just never do with a system connected to the Internet because it gives anyone on the system read and write access to the file.

    If your environment is jailing users to their own home directory it really doesn't make any difference though.
     
    joebert, Oct 25, 2009 IP