[Vtigercrm-developers] Attachments - privileges

IT-Solutions4You info at its4you.sk
Thu Feb 25 09:57:54 GMT 2016


Yes it's a security hole, but web-user(apache, www-data) need create a 
directory, write (copy) files in storege directory.
I don't see diferents between
root:www-data chmod 775
www-data:www-data and chmod 775

www-data must have 7 atribute on directory and 6 on file(s).

Matus


Dňa 25. 2. 2016 o 5:43 Garry Brighton napísal(a):
> Stacey says that vtiger (mailconverter) creating folders and files where
> "owner" AND "user" is set to apache.
> Is it really OK?
>
> Garrry Brighton
>
> On Wed, Feb 24, 2016 at 11:37 PM, cryptic
> <mark at markcox.co.uk
> <mailto:mark at markcox.co.uk>> wrote:
>
>     If the owner was set root then it would not be able to create the
>     directory /
>     files as 755 and 644 as the user is www-data
>
>
>
>     --
>     View this message in context:
>     http://vtiger-crm.2324883.n4.nabble.com/Re-Attachments-privileges-tp18490p18504.html
>     Sent from the vtigercrm-developers mailing list archive at Nabble.com.
>     _______________________________________________
>     http://www.vtiger.com/
>
>
>
>
> _______________________________________________
> http://www.vtiger.com/
>




More information about the vtigercrm-developers mailing list