We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 39712
    • 31 Posts
    Just got an advanced install of MODX 2.2.4 running. On Apache/Linux/MySql/
    During the install process, I read so much conflicting information about folder permissions, I shotgunned the install routine with "write" permissions everywhere...

    Now I need to make sure I've got critical folders reset to "read only"...

    Does anyone have a comprehensive listing of a Revo 2.2 site relative to which folders have to remain writable? I want to make sure of security but don't want to break things in the attempt. The config is in a read only folder.

    Thanks!

      • 1343 ☆ A M B ☆
      • 2,213 Posts
      Hello,

      In reality the answer is based on your server configuration, and for most sites I would recommend suPHP be used, so 644/755 is your default permission which is fine. Placing the core folder above the web root is recommend for added security (or rename the ht.access to .htaccess within the folder). Beyond that MODX is fairly secure out of the box, provided you stay up to date.

      So my suggestion, install/use suPHP, and then default permissions are fine.
        Patrick | Server Wrangler
        About Me: Website | Tweets |  MODX Hosting
        • 39712
        • 31 Posts
        Hi AMDbuilder, This is where info gets really confusing. I just read some notes about the core/packages directory has to be writable... So obviously, to change that folder to "read-only" would break it. The 644/755 permissions are my default values. However when things don't work some folders have gotten changed to 777. I just want to make sure that the wrong ones are not writable, and no one seems to have anything to say on the subject beyond mention of one or two folders per discussion and seldom the same folders mentioned in different posts... So, info out of context becomes confusing. In the end, which ones MUST be writable? There are a lot of folders! Some of these may be obvious, but I want to make sure before I assume things are OK...

        As to security, this is an advanced install with a relocated core, manager and connectors on a sub-domain, and various folder names changed, etc. Per info on http://www.sepiariver.ca/blog/modx-web/benefits-of-the-modx-advanced-installation

        Others disagree with your statement, "Beyond that MODX is fairly secure out of the box, provided you stay up to date."

        My site will be subject to the kinds of prodding and poking typical of some folks with too much knowledge and too much time on their hands. So, a standard install would leave me wide open to attacks... with less security than is possible with the advanced install.

        Just looked at suPHP... That's intended to "replace" PHP on the host server, and apparently it can be used on a shared host, but it involves virtual servers and such that I don't have access to. Possibly a solution, but very involved... Thanks for the suggestion though. Always learning new things. [ed. note: larrybqd last edited this post 14 years, 2 months ago.]
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          There is an apache module for this if your php is an apache module. Otherwise, PHP is a stand-alone interpreter (CGI or FastCGI) with one of several suexec applications.

          http://boomshadow.net/tech/php-handlers/
            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 1343 ☆ A M B ☆
            • 2,213 Posts
            Quote from: larrybqd at Jul 05, 2012, 01:24 PM

            Others disagree with your statement, "Beyond that MODX is fairly secure out of the box, provided you stay up to date."

            I would love to hear more about those who disagree, to my knowledge no MODX Revolution sites running the current version, on a properly configured server have been hacked. I know there are a few hacks for MODX Evolution, if you aren't running a current version.

            In regards to the original question, suPHP can be more involved to setup, but when done properly scripts are run as the account owner, which is important for making things function properly. You can't for example have MODX run on a server using DSO, without the use of MOD_RUID2 for example.

              Patrick | Server Wrangler
              About Me: Website | Tweets |  MODX Hosting