We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 14344
    • 16 Posts
    I am using MaxiGallery But ever time I upload images via maxigallery the images and gallery folders end up with 666 or 777 permission. This has now lead to my hosting account being hack and my server running phishing sites. Is there anyway of running maxigallery without giving such permissions?
      • 22303 MODX Staff
      • 10,725 Posts
      Quote from: jmurphy04 at Oct 06, 2009, 07:13 PM

      I am using MaxiGallery But ever time I upload images via maxigallery the images and gallery folders end up with 666 or 777 permission. This has now lead to my hosting account being hack and my server running phishing sites. Is there anyway of running maxigallery without giving such permissions?
      Can you explain how having these folders/files with world-writable permissions has lead to your account being hacked? Something else provided the attack vector on which this occurred. Just because they are writable does not make them the vector for attack.
        • 14344
        • 16 Posts
        That is what the hosting company told me. When I logged into my ftp I had a ton of files that weren’t mine and there was what looked to be a fake bank website running on my server.

        They ask that I do not have any files with such permission in the future. After changing everything over to 644 and 755 the old galleries still seem to work fine though. So why do all new files created with maxi gallery have 666 and 777 permission if it works fine with no world write? and if that wasn’t how it happened then how do most phishing sites gain access?
          • 22303 MODX Staff
          • 10,725 Posts
          Quote from: jmurphy04 at Oct 06, 2009, 08:33 PM

          That is what the hosting company told me. When I logged into my ftp I had a ton of files that weren’t mine and there was what looked to be a fake bank website running on my server.

          They ask that I do not have any files with such permission in the future. After changing everything over to 644 and 755 the old galleries still seem to work fine though. So why do all new files created with maxi gallery have 666 and 777 permission if it works fine with no world write? and if that wasn’t how it happened then how do most phishing sites gain access?
          That’s the easy answer for them so they don’t have to figure out what insecure script allowed the attacker to execute code remotely that gave them access to upload files to these writable folders. Some site configurations require these permissions for it to work, but it should allow you to configure what the permissions are for newly uploaded files because many newer hosting configurations will work fine without this. As to whether or not MaxiGallery does allow this to be configured, I do not know and will defer to the author or others familiar with this Add-On for MODx.

          BTW, can you still upload new files to the galleries with those permissions?
            • 14344
            • 16 Posts
            At this point I can still upload files with that permission.

            Thanks for your help!
              • 7923
              • 4,213 Posts
              There are parameters in MaxiGallery to set the permissions for new folders and files.. by default they are 666 / 777. See MaxiGallery wiki article for more info.


                "He can have a lollipop any time he wants to. That's what it means to be a programmer."
                • 14344
                • 16 Posts
                I have searched the Wiki an can’t find such a parameter. huh
                  • 7923
                  • 4,213 Posts
                  Hmm.. I can’t find them either.. smiley

                  Well, the parameters are: &chmod_folders and &chmod_files


                    "He can have a lollipop any time he wants to. That's what it means to be a programmer."