Re: Uploading with PHP Script and permissions
| From: | Floyd Baker | Date: | Mon, 08 Jan 2001 23:17:54 +0000 |
| Subject: | Re: Uploading with PHP Script and permissions | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-5724@lists.php.net to get a copy of this message | ||
On Thu, 14 Dec 2000 14:53:49 -0500, you wrote:
>Hello,
>I am trying to create an upload/admin script for authorized
>users to add (and manage) files that are viewed by others.
>The scripts for managing this are stored in one subdirectory,
>the files are stored in another subdirectory.
>
>- Why do I have to set 777 permission for the file directory
>to upload? Specifically why do I have to give execute
>permission to write files? And is this dangerous, since
>if there is a security hole on uploading, someone could
>upload and execute a malicious script? I really want to
>set read and write permission to that directory, and restrict
>write permission to authorized users.
>
>- Is setting 777 dangerous for directories that users
>have access to? What restriction should I have here?
>The internet security faqs seem to focus a lot on firewall
>theory and I can't find a specific answer to this.
>
>Thanks,
>Scott at scott@lynn.net
If you mean 'write' files being the text files, make them '.txt' files.
Put and get can deal with them and you can 777 each .txt filename you will be
writing to.
--