Pages: [1]   Go Down
  Print  
Author Topic: Locking your site settings  (Read 1770 times)
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« on: July 06, 2010, 03:49:29 AM »

Hello all,

There is a very simple way to lock your site settings to prevent possible hackers that get into your site from actually changing your site settings (i.e. your payment address, email settings, click rates, payout amounts, etc).

Once you have all your site settings the way you want them, go to this file and set the permissions to 0644. This will completely lock the site settings so that they can not be changed.

includes/settings.php

Now, if you later decide to change one or more of your settings, you will need to go back into your cpanel and change the permission to 0777, change the setting, and then change the permission for this file back to 0644. This is a nice preventive measure.
Logged

Upgrade to an SDR 3
Addons
Full Member
***
Offline Offline

Posts: 158


View Profile
« Reply #1 on: July 09, 2010, 07:03:33 AM »

Great Option to prevent from cheater
Logged

bprasetio
Global Moderator
Hero Member
*****
Offline Offline

Posts: 834


View Profile
« Reply #2 on: November 04, 2010, 10:50:47 PM »

its more complicated when Daily Click Bonus is activated.

when daily click bonus feature is active, the cron job will update the setting file, this may lead a failed update when the given permission is not 777. But in other hand, leave it to 777 is not good practice.

change the permission manually is also a pain.

So any suggestions?
Logged

Presenting MyGPT Group:

[WTS] Task Summary Addon
757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #3 on: November 06, 2010, 04:58:06 PM »

no not yet
Logged

bprasetio
Global Moderator
Hero Member
*****
Offline Offline

Posts: 834


View Profile
« Reply #4 on: December 05, 2010, 10:02:34 PM »

its more complicated when Daily Click Bonus is activated.

when daily click bonus feature is active, the cron job will update the setting file, this may lead a failed update when the given permission is not 777. But in other hand, leave it to 777 is not good practice.

change the permission manually is also a pain.

So any suggestions?

I made fix on my way, I separated the related click bonus settings to other file and merge it when load setting function is loaded.

so its a middle way between security and functionality, although the click bonus setting file permission set to 666 or 777.

I also have tried to save it directly to DB, but seems more complicated code in order to work properly.

Logged

Presenting MyGPT Group:

[WTS] Task Summary Addon
Arbolus
Newbie
*
Offline Offline

Posts: 5


View Profile
« Reply #5 on: February 23, 2011, 09:39:04 AM »

Great preventive fix  Smiley
Logged
WebSuccess4You
Jr. Member
**
Offline Offline

Posts: 60


Standing at Romania-Ukraine border at Danube River


View Profile WWW
« Reply #6 on: March 04, 2011, 10:17:26 PM »

    Thank you. I just checked finally and everything was 0644 .
However, how do you actually do the writing when you change code in one of those files, for instance.
What I did for the Home.php  is to save it my website name folder on my laptop and then upload it
to my PTC-PTR directory in my major website and look at it from there. Host4Profit uses a WebePanel
which is much easier than a CPanel to negotiate. Then I would upload the changed code to a slightly
differently named file and see what it looks like.
Logged

757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #7 on: March 06, 2011, 03:11:24 PM »

I usually almost always code on the cpanel itself, I just find it easier that way.
Logged

johnlennon9687
Newbie
*
Offline Offline

Posts: 1


View Profile WWW
« Reply #8 on: July 06, 2011, 04:31:28 AM »

nice tip
Logged

757jterrell
Administrator
Hero Member
*****
Offline Offline

Posts: 1637



View Profile WWW
« Reply #9 on: July 07, 2011, 03:06:40 PM »

This is probably one of the most important things you can do to protect your site when you begin, that and making sure the config.php file has permission 0644 also.
Logged

Get a SDR 3 NOW at http://ptcfactory.info

The best and most up to date Aurora script in the market!!
Pages: [1]   Go Up
  Print  
 
Jump to: