Uutiset:

Bored?  Looking to kill some time?  Want to chat with other SMF users?  Join us in IRC chat or Discord

Main Menu
Advertisement:

Best Practice Security modifications after install.

Aloittaja setuptips, joulukuu 09, 2007, 04:13:19 AP

« edellinen - seuraava »

setuptips

Hi

I was wondering if anyone had some tips on best practice security modifications to make to a SMF install ?

eg.  recommended .htaccess changes,   etc etc.

H

Once you've installed any themes / mods I'd recommend you make everything read-only (chmod 666) except for the attachments folder :)
-H
Former Support Team Lead
                              I recommend:
Namecheap (domains)
Fastmail (e-mail)
Linode (VPS)
                             

青山 素子

Motoko-chan
Director, Simple Machines

Note: Unless otherwise stated, my posts are not representative of any official position or opinion of Simple Machines.


H

-H
Former Support Team Lead
                              I recommend:
Namecheap (domains)
Fastmail (e-mail)
Linode (VPS)
                             

青山 素子

That would work fine as well, but I recommend not setting execute on files. If the host has Apache's XBit Hack enabled, there is a slight chance of a possible security issue.

Execute on directories is required, as having that set means you can go into them.
Motoko-chan
Director, Simple Machines

Note: Unless otherwise stated, my posts are not representative of any official position or opinion of Simple Machines.


Ben_S

Simplest option is to use the feature built into the package manager.

Admin > Packages > Options > Cleanup Permissions > Change all file permissions throughout the forum such that: The minimum files are writable.
Liverpool FC Forum with 14 million+ posts.

Advertisement: