[wp-hackers] Backup, wp-content
Roy Schestowitz
r at schestowitz.com
Wed Dec 21 03:25:40 GMT 2005
_____/ On Tue 20 Dec 2005 23:03:55 GMT, [Matt Mullenweg] wrote : \_____
> Scott Merrill wrote:
>> This goes against the recommended file permissions defined in the
>> "Hardening WordPress" Codex guide (disclaimer: I wrote the recommended
>> file permissions for that page):
>> http://codex.wordpress.org/Hardening_WordPress#File_permissions
>
> wp-content was always intended to be completely writable.
I wonder if it's part of the installation process. The latest nightly
(21-12-2005) does not make it writable 'out of the box' (see below), but I
suspect that's to do with the tool I use to uncompress the archive. It ap-
pears to be drwxrwxrwx in the archive itself.
When somebody installs WordPress, s/he might be prompted to change permis-
sions in order to upload images. I had the same experience with 1.2 and 1.5.
roy at BAINE:~/Desktop/wp> ls -la
total 1
drwxr-xr-x 3 roy users 80 2005-12-21 03:13 .
drwx------ 4 roy student 280 2005-12-21 03:13 ..
drwxr-xr-x 5 roy users 816 2005-12-21 02:30 wordpress
roy at BAINE:~/Desktop/wp> ls -la wordpress/wp-con*
-rw-r--r-- 1 roy users 887 2005-08-03 01:46
wordpress/wp-config-sample.php
wordpress/wp-content:
total 5
drwxr-xr-x 4 roy users 128 2005-12-21 02:30 .
drwxr-xr-x 5 roy users 816 2005-12-21 02:30 ..
-rw-r--r-- 1 roy users 32 2005-11-18 23:18 index.php
drwxr-xr-x 3 roy users 136 2005-12-21 02:30 plugins
drwxr-xr-x 4 roy users 96 2005-12-21 02:30 themes
More information about the wp-hackers
mailing list