Cold Fusion Write permissions

Public web servers need to be as secure as possible so permissions on folders within public web areas need to be set so that it is difficult for ftp users to write content to other users directories and guests can't upload and execute scripts.

This is particualy important with CFMX due to the way it runs (as a global user) so write and delete permissions are non standard permissions and need to be requested and set up specifically via the CFMX administrator.

Obviously we need to ensure that only the web site owner/administrator is the person making the request and also that any security questions we ask are done so over a secure connection. As a result please follow the following steps to request this.

---------------------------------------------------------------

1. Raise a ticket requesting the permissions via:

www.host-it.co.uk/tickets
(The Dept will be Virtual Hosting and Priority should be low or medium).

Include the full physical path to the folder and also let us know if you wish any sub folders to inherit the same settings. Also include the permissions you need set up.

2. We will open the ticket and ask you one or more security questions (at this point the ticket system is viewed via a secure connection ie SSL) and once authorized make the changes and update the ticket to let you know.

---------------------------------------------------------------

Tip:
It may be an idea to designate a folder for all files which need non standard permissions.

As CFMX can set permissions to cascade down automatically you can then create sub folders for files without having to contact us each time.

For example if you were a car dealer and sold cars and vans and needed to upload pictures via a web browser the structure may look like this:

We could have originally set up write and delete permissions on the folder called 'uploadedpictures2355' and set this to include sub folders so all the folders below this could be used without having to contact us each time and if (for example) they started selling motorbikes this new folder could be added without having to contact us again.

{end}