Hi AMDbuilder, This is where info gets really confusing. I just read some notes about the core/packages directory has to be writable... So obviously, to change that folder to "read-only" would break it. The 644/755 permissions are my default values. However when things don't work some folders have gotten changed to 777. I just want to make sure that the wrong ones are not writable, and no one seems to have anything to say on the subject beyond mention of one or two folders per discussion and seldom the same folders mentioned in different posts... So, info out of context becomes confusing. In the end, which ones MUST be writable? There are a lot of folders! Some of these may be obvious, but I want to make sure before I assume things are OK...
As to security, this is an advanced install with a relocated core, manager and connectors on a sub-domain, and various folder names changed, etc. Per info on
http://www.sepiariver.ca/blog/modx-web/benefits-of-the-modx-advanced-installation
Others disagree with your statement, "Beyond that MODX is fairly secure out of the box, provided you stay up to date."
My site will be subject to the kinds of prodding and poking typical of some folks with too much knowledge and too much time on their hands. So, a standard install would leave me wide open to attacks... with less security than is possible with the advanced install.
Just looked at suPHP... That's intended to "replace" PHP on the host server, and apparently it can be used on a shared host, but it involves virtual servers and such that I don't have access to. Possibly a solution, but very involved... Thanks for the suggestion though. Always learning new things.
[ed. note: larrybqd last edited this post 14 years, 2 months ago.]