UK WEB HOSTING FORUM FOR DISCUSSION ON WEB HOSTING SERVICE AND SUPPORT
LINUX HOSTING WINDOWS HOSTING PACKAGES SHOPPING CART OSCOMMERCE ZEN CART AGORA
ECOMMERCE HOSTING ASP MSSQL FRONTPAGE HOSTING PHP MYSQL HOSTING DISCUSSION FORUM
CPANEL RESELLER HOSTING DEDICATED SERVER VPS HOSTING PLESK VIRTUOZZO
Quick Search
Your forum announcement here!

  UK Web Hosting | Dedicated Server Windows and Linux VPS Forum > Web Hosting and Domains > PHP Hosting

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 18-05-2006, 20:21
Junior Member
 
Join Date: May 2006
Posts: 2
Send a message via ICQ to Yukko
Default PHP+cpanel+file permissions problems

Guys, I'm little unhappy with the serivce! other web hosting companies in my country (Ukraine) works but they are not stable than yours one. I will ask excuses here if someone proves that I'm wrong:
- first of all I noticed that some changes took place in file permissions in home directories. Our CMS written on php NEEDS to write to files, I change it back with cpanel, so, it started to work once again.
- then I noticed that some couple of times I cannot access dynamic pages. I have an error that something is misconfigured on Apache.
- after upgrade or something on your web hosting server which caused the errors described above that I again noticed that file permissions were completely wrong. I tried to change it with my scripts where I had negative results, I tried to change it with cpanel and have no success.

Even more! I'm not happy with PHP security features configured: open base directoty restrictions. Webhosters know how to give people absolute freedom inside their home directories, but don't give them access to the files owned by other people or system files owned by system users.

The website of my client is hosted on server6.specialservers.com
Reply With Quote
  #2 (permalink)  
Old 19-05-2006, 23:35
eUKhost.com's Avatar
Chief Marketing Officer
 
Join Date: Sep 2005
Posts: 4,294
Send a message via AIM to eUKhost.com Send a message via MSN to eUKhost.com
Default

Your application is creating pages with ownership of nobody in the directories that have permission 777 and you cannot modify permission of pages with ownership of nobody. We change permission on directories with permission of 777 if some spamming scripts or outbound attack scripts get uploaded in those directories as the directories are writable for world and anyone can easily upload bad content in those directories.

We have recently implemented pre.php and mod_security on our servers which wont allow anyone to upload abusive scripts in the directories with 777 permission. You wont face the same problem again in future which you had in past as the recent installation of pre.php and mod_security will take care of banning upload of abusive scripts.

If you come across similar problem in future then please contact our support staff from our helpdesk located at http://support.eukhost.com/
Reply With Quote
  #3 (permalink)  
Old 20-05-2006, 17:51
Junior Member
 
Join Date: May 2006
Posts: 2
Send a message via ICQ to Yukko
Default

Quote:
We change permission on directories with permission of 777
Now I get it! You tell to my client that you never change the permissions of the users' files:
Quote:
as we do not play around with clients files
You tell me that you do. where is the truth? Or I don't understand anything?

Quote:
are writable for world
What do you mean by "writable for world"? 777 means that it is writtable by User Group or Other. The permissions 777 can be used for unauthorized writing of the possibly unsecure content only in 2 cases:
1. when upload script doesn't control things, which it handles;
2. when owners of co-hosted on the same webserver websites know the username of the client and have access to File system functions and are not restricted to "jump out" from their home directories. So, they can try to construct direct path to the needed folder or file and try to write to it.
The first case is a completely problem of the client and his software and it should be written in TOS.
The second case is a problem of hoster and it can be solved 100%. When it is solved, then accourding to the point above it is a user's own funeral if somebody hacked his website.

Quote:
We have recently implemented pre.php and mod_security on our servers which wont allow anyone to upload abusive scripts in the directories with 777 permission.
Nice! But I don't think that clients want to know which additional modules you've implemented, they want to have their hosting working. Me and my client also join this club.

BTW
This message I see already for the whole day today, when I try to get dynamic content:
Quote:
Internal Server Error
The server encountered an internal error or misconfiguration and was unable to complete your request.

Please contact the server administrator, webmaster@mydomain.co.uk and inform them of the time the error occurred, and anything you might have done that may have caused the error.

More information about this error may be available in the server error log.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
My client started to suspect, that I write bad software, I also already started to doubt, but basically, I understood that not only me writes bad software. The authors of phpmyadmin scripts also:
Quote:
Internal Server Error

Unable to open engine binary (php) at cpsrvd.pl line 1182
main::dodoc_cpaneld() called at cpsrvd.pl line 518
main::dodoc() called at cpsrvd.pl line 429
Reply With Quote
  #4 (permalink)  
Old 26-06-2006, 15:12
Member
 
Join Date: Nov 2005
Posts: 56
Default

Hiya

Just out of interest I have currently been using phpMyAdmin 2-7-0-pl2 on my local server and it is plagued with errors. PhpMyAdmin then quickly released a newer version.

The problem with using PHPMyAdmin is that, like any other open source software, it can have bugs within.

Thankfully, I've noticed that the eUKhost people dont use that version. But I have been careful with phpmyadmin ever since.

Just thought it would be useful to know.

Cheers,
LD
__________________
LD
------------------------------------------------------
Webmaster of DeanRichardson.Com
Web: http://www.deanrichardson.com/
Forum: http://www.deanrichardson.com/forum/
!!! AVE IT !!!
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 11:17.

 

Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by Web Hosting 3.1.0
Copyright © 2001-2008, eUKhost.com. All rights reserved.

 
Site Map

VPS Hosting
VPS Hosting plans

Dedicated Server Hosting
Dedicated Server plans

Business Web Hosting
100% uptime Hosting

Cpanel Hosting
cPanel Shared Hosting

Reseller Hosting
Reseller Web Hosting

Windows Hosting
Windows Shared Hosting

Windows VPS

Windows VPS Hosting

Semi Dedicated Servers
Semi-Dedicated Hosting

Dedicated Server Mirroring
Dedicated Server Mirroring

Webhosting Knowledgebase
Frequently asked Questions

Web Hosting Blog
eUKhost Blog

Web Hosting Support
Support Helpdesk

UK Data Center
eUKhost Datacenter

Web Hosting Forum
eUKhost Forum

Support Tutorials
Online Flash Tutorials

Offsite Back-up Plans
Remote Backup Service

Customer Testimonials
eUK Customer Testimonials


knowledgebase articles

eUKhost.com Services

Pre-Sales Questions
Pre-sales FAQ's

Domain Names
Domain registration FAQ's

cPanel Hosting
cPanel Hosting FAQ's

Windows Web Hosting
Plesk Control Panel

Reseller Hosting
Reseller Hosting FAQ's

VPS Hosting
Virtual Private Server

Semi-Dedicated Servers
Semi-Dedicated FAQ's

Dedicated Servers
Dedicated Server Hosting


popular blog categories


Web Hosting
Website Hosting articles

UK Web Hosting
UK Hosting articles

Dedicated Server Hosting
Dedicated Server guidelines

VPS Hosting
VPS hosting articles

cPanel Hosting
cPanel Hosting articles

Linux Operating System
Linux Operating techniques

Windows Web Hosting
Windows plesk articles