PhotoPost Photo Gallery Sales PhotoPost Sales Toll Free Phone Number
Mon-Fri 9am-4pm EST
  PhotoPost Photo Sharing Photo Gallery    Visualize community tm
| | | | | | | | |

Go Back   PhotoPost Community > PhotoPost Support > PhotoPost Pro Support Forums > Photopost Pro Installation & Upgrades

Photopost Pro Installation & Upgrades If you're having install or upgrade problems

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
Old January 15th, 2010, 08:00 PM   #1 (permalink)
Member
Verified Customer
 
Join Date: Sep 2005
Location: South Carolina, USA
Posts: 63
Send a message via AIM to DHewes
PhotoPost PHP Pro 7.01 Security Questions

I am brand new to Photopost. Just installed a new vBulletin 4.0.1 Full CMS website, purchased and am now installing PhotoPost PHP Pro 7.01. It does not appear to be a huge challenge (though I am just now FTPing the files) but the documentation is clearly written for a previous version. (At least it exists, most of the vB stuff doesn't yet). My question is about security. While there is mention in the online docs of what to CHMOD everything, there is very little mention of what files/folder can be deleted (or never uploaded). For example, there is no reason in the world that the documentation folder needs to be on the server., though this is never mentioned in the documentation. Has anyone complied a list of every file/folder that can just be deleted after a successful install? Any post-install CHMOD's to restrict access? Any folders that I can safely password protect that will not affect functionality?

I have been hit too hard too many times in the past and always due to a script (usually Subdreamer) that had a hole - and just doing everything I can this time to prevent that. I would greatly appreciate any advice anyone has.
DHewes is offline   Reply With Quote
Old January 15th, 2010, 08:24 PM   #2 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,680
You dont need to upload documentation sure but everything else as noted needs to be uploaded as in the install instructions.

I beleive the install documentation clearly defined the files you want to remove basically install.php and upgrade.php everything else stays.

PhotoPost PHP Photo Sharing Photo Gallery Installation Guide
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old January 15th, 2010, 08:37 PM   #3 (permalink)
Member
Verified Customer
 
Join Date: Sep 2005
Location: South Carolina, USA
Posts: 63
Send a message via AIM to DHewes
Also, in the configuration after the fact, can things like the upload directory be located ABOVE the web document root, like with the attachments directory in vB itself, to prevent access?
DHewes is offline   Reply With Quote
Old January 15th, 2010, 08:39 PM   #4 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,680
You can try that although personally I have never tried that since its merely a tmp directory that only houses files while they are being processed.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Old January 15th, 2010, 08:43 PM   #5 (permalink)
Member
Verified Customer
 
Join Date: Sep 2005
Location: South Carolina, USA
Posts: 63
Send a message via AIM to DHewes
Chuck - not a big deal, but actually there is no mention to remove the upgrade.php file when doing a clean install, nor is the documentation folder ever mentioned. Both of these were fairly obvious, but if you update your docs, its something to note. Also there is no note to change permissions back to 644 on teh config-inc.php and config-int.php files. I am assuming that there is no way in he** you want these left at 777 (change only if changing the settings).

However, I would like to note that the install was very easy and went very smoothly.
DHewes is offline   Reply With Quote
Old January 15th, 2010, 10:42 PM   #6 (permalink)
Photopost Developer
Verified Customer
 
Chuck S's Avatar
 
Join Date: Jun 2002
Location: Abingdon,MD
Posts: 71,680
Quote:
PhotoPost installation is now complete. Be sure you remove your install.php file (and the various upgradeXX.php/.sql)files) from your server's PhotoPost directory to prevent malicious users from altering your PhotoPost settings.
Interesting I see this right in the install page I linked you.

Actually the config files in the instructions state to make writable which is 666 not 777 and if you have any need to edit config settings in the admin panel you want these at 666 but otherwise 644 is fine.
__________________
Photopost Developer and Support Engineer

Please do not PM me for support or sales questions. Thank you for your understanding.
Chuck S is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Just purchased photopost pro - Questions sportsoutlaw General Discussion 3 July 2nd, 2006 04:22 PM
PhotoPost PHP Pro or PhotoPost vBGallery? Which one to choose for vB 3.5.x? pulsorock Before You Buy 22 March 8th, 2006 07:49 AM
Security Announcement: PhotoPost Immune from EXIF PHP Security Flaw Michael P General Discussion 0 December 22nd, 2004 08:10 AM
General questions about Photopost Pro text fields and words Johnny Doomo General Discussion 9 August 14th, 2004 04:22 AM


All times are GMT -5. The time now is 11:50 AM.

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0