g2data file permissions and changing

gregasss

Joined: 2007-04-23
Posts: 3
Posted: Sat, 2009-02-14 02:40

Hi, I'm having security issues where my website is being "hacked" and made to host fraudulent websites, phishing content etc. Currently g2data and all directories and files under it are set to 777.

My understanding is PHP does not run as my user account; I've acted on the instructions from http://codex.gallery2.org/Gallery2:Security as best I can.

Firstly, can someone confirm the recommended file permissions for g2data? One forum post recommended "g2data should be 777 and then Apache/PHP will create the other directories and files as 755/644 (respectively)"

Secondly, how can I change the permissions (currently all 777)? I can't seem to do it via FTP (tried a few programs), cpanel has an ftp app but can only change one file at a time, /lib/support/index.php?chmod just gives me errors. Do I have to ask my webhost to do this for me?

Cheers for any help!


Gallery version: 2.2.6
PHP version (e.g. 5.2.6):
PHPInfo Link: http://gregas.net/photos/info.php
Webserver: Apache 2.2.10 (Unix)
Database: MySql 4.1.22-standard-log
Activated toolkits: Ffmpeg, GD, Imagemagick
Operating system: Linux
Browser: N/A