[Vtigercrm-developers] VT61 Module installer *still* using 777

Prasad prasad at vtiger.com
Thu Jul 31 11:41:25 GMT 2014


Alan,

I agree - will dive into this any pointer if you have identified would be
helpful to fix it.

*Connect with us on: *Twitter <http://twitter.com/vtigercrm> *I* Facebook
<http://www.facebook.com/pages/vtiger/226866697333578?sk=wall> *I* Blog
<https://blogs.vtiger.com/>* I* Wiki
<http://wiki.vtiger.com/index.php/Main_Page> *I *Forums
<https://discussions.vtiger.com>*I* Website <https://www.vtiger.com/>


On Thu, Jul 31, 2014 at 4:17 PM, Alan Lord <alanslists at gmail.com> wrote:

> I don't know how many times I need to say this but *nothing* in the vtiger
> source tree needs to be rwxrwxrwx - this is just bad practice and
> potentially dangerous.
>
> As a matter of fact I do not think any files in the source tree need to be
> executable at all. (vtigercron.sh potentially could be but it isn't
> actually necessary).
>
> The config.inc.php file should really only be readable by the web server
> user as it contains the username & password for the database (so 600 or
> 640).
>
> Everything else (excluding the logs) should probably just be 644 for files
> and 755 for directories.
>
> Al
>
> _______________________________________________
> http://www.vtiger.com/
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.vtigercrm.com/pipermail/vtigercrm-developers/attachments/20140731/672ebad8/attachment.html>


More information about the vtigercrm-developers mailing list