My host flagged the cache folder as a security risk?

Get help with installation and running phpBB 3.1.x here. Please do not post bug reports, feature requests, or extension related questions here.
Anti-Spam Guide
Forum rules
READ: phpBB.com Board-Wide Rules and Regulations

NOTE: phpBB 3.1.x is at its End of Life stage and support will NOT be provided after July 1st, 2018.
Locked
User avatar
dpaanlka
Registered User
Posts: 286
Joined: Wed May 10, 2006 6:48 pm
Location: Chicago, USA
Contact:

My host flagged the cache folder as a security risk?

Post by dpaanlka » Thu Sep 01, 2016 12:21 pm

I installed a brand new, clean 3.1.2 board last week. Today I got the following message from my host (DreamHost):
Unfortunately, we found some potential indications that your website(s) *may* be compromised.

The following files/directories had insecure permissions (777), which
have been remediated.

/info-mac.org/cache
Later I spoke with support and they said the cache directory permissions were the only problem identified by their automated system. The directory's permissions are now 755. I looked around a little bit on the server and don't see anything else that is 777. Visiting my board, it also seems to be unaffected.

My question is, does this look like anything I should be alarmed about? What are the default permissions for cache/ supposed to be?

Thanks!
phpBB user and evangelist since 2005.
My boards: Info-Mac | System 7 Today

User avatar
JimA
Community Team Leader
Community Team Leader
Posts: 7620
Joined: Thu Jul 31, 2008 5:54 am
Location: The Netherlands
Name: Jim Mossing Holsteyn
Contact:

Re: My host flagged the cache folder as a security risk?

Post by JimA » Thu Sep 01, 2016 12:33 pm

No, having cache (amongst some other folders) at 777 is normal and a requirement for running phpBB.
Have a read of this article and direct your host to it if necessary: KB - phpBB3 Chmod Permissions
Image Jim Mossing Holsteyn - Community Team Leader
Knowledge Base | Documentation | Board rules

If you're having any questions about the rules/customs of this website, feel free to drop me a PM.

User avatar
dpaanlka
Registered User
Posts: 286
Joined: Wed May 10, 2006 6:48 pm
Location: Chicago, USA
Contact:

Re: My host flagged the cache folder as a security risk?

Post by dpaanlka » Thu Sep 01, 2016 1:09 pm

Thank you so much for your quick response. I will pass this information along to them.
phpBB user and evangelist since 2005.
My boards: Info-Mac | System 7 Today

User avatar
Brf
Support Team Member
Support Team Member
Posts: 51785
Joined: Tue May 10, 2005 7:47 pm
Location: {postrow.POSTER_FROM}
Contact:

Re: My host flagged the cache folder as a security risk?

Post by Brf » Thu Sep 01, 2016 1:16 pm

JimA wrote:No, having cache (amongst some other folders) at 777 is normal and a requirement for running phpBB.
Actually, 755 should work fine if the Anonymous Internet user is the owner of the folders that are normally set to 777. That should be something your host can arrange if they are concerned with the 777 permissions.

Locked

Return to “[3.1.x] Support Forum”