Results 1 to 2 of 2

777 permission files and folders hacked

This is a discussion on 777 permission files and folders hacked within the osCmax v2 Installation issues forums, part of the osCmax v2.0 Forums category; Dear all We have several osCMax sites all with the current security patches etc however there seems to be a ...

      
  1. #1
    New Member
    Join Date
    Dec 2004
    Posts
    6
    Rep Power
    0


    Default 777 permission files and folders hacked

    Dear all

    We have several osCMax sites all with the current security patches etc however there seems to be a problem with hackers exploiting any file or folder with 777 permission.

    They then place 3 files via a script which you can usually tell by the timestamp however they are not always named the same: eg guest.php. include.php and always .htaccess can be found in images folder (because of the 777 permission) The script then searches through 777 files and injects some code so that when your site loads it calls the other files it has placed on server. You may or may not even notice your site has been hacked until you physically look at the files.

    It does this in EVERY world writeable directory and file it can find on the site eg mainfile.php ,/tmp folder, /cache folder /temp folder. All of these files are required to run OsCmax correctly as I understand.

    My Question is this. Will these files / folder or osCMax in general work correctly if the 777 permission is changed to 755 permission allowing image uploads and EP etc to work correctly.

    Look forward to your response.

    Kind Regards
    Trap

  2. #2
    New Member deviantla's Avatar
    Join Date
    Jan 2006
    Posts
    28
    Rep Power
    0


    Default RE: 777 permission files and folders hacked

    After install I changed all my permissions back (folders to 755 & files to 644). Everything works fine for me.

Similar Threads

  1. changing permission on files
    By jschafer52 in forum osCommerce 2.2 Discussion
    Replies: 1
    Last Post: 09-26-2005, 10:13 PM
  2. Call for Mods : Have you hacked in a mod to your shop?
    By michael_s in forum osCMax v1.7 General Mods Discussion
    Replies: 14
    Last Post: 06-02-2005, 11:08 PM
  3. Quantity Tracking Pro - anyone hacked this into MS2 MAX ?
    By malcol27 in forum osCMax v1.7 General Mods Discussion
    Replies: 0
    Last Post: 02-20-2005, 08:10 AM
  4. What folders to secure?
    By PrettyWolfie in forum osCommerce 2.2 Modification Help
    Replies: 4
    Last Post: 08-01-2004, 03:51 AM
  5. Images folders
    By starview in forum osCommerce 2.2 Modification Help
    Replies: 2
    Last Post: 07-28-2004, 12:11 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •