File Permissions – Why They’re Important…
Earlier this week I clicked my website, and to my horror, the browser displayed a warning message saying that my site was distrubiting malware, meaning all my links were stopped from displaying.
Now the little googlebot that found the malware was very quick to talk to the twitterbot, and suddenly I was both blogless and twitterless – do these words exist?
Thankfully the support guys at kiosk did a great job in finding the malware and deleting it. A few support tickets to google & twitter mean everything is back to normal now, but I want to share with the reason why the malware managed to get into my site.
When you add files to your webserver via ftp you have file permissions associated with your account. It turns out that I had some which allow other users to write, and this was how the malware got onto my site.
Moral of the story is that when you upload new files to your server be sure to check the file permissions. Folders should have 755 and individual files should have 644
I hope this advice helps to keep your site secure
Andrew







Thanks for the heads up. Webite hijack is becoming a bit of a nuisance