Hi,
I was just told by some user of mine that it was possible to cd into anyones public_html and read files.
After checking I found it was, the user even managed to get alot of sql passwords from config files etc.
I'm still trying to clean the mess up.
Anyway, to the point. After searching for the general area of permissions on here I noticed, http://www.directadmin.com/features.php?id=497.
It appears like default DA install uses apache_public_html=0, so I changed it and created a new account. Then I checked out if the same problem happened on the new user, oddly it didn't.
I went through and chowned and chmoded the public_html dirs to USER:apache and 750. It seems to have fixed it.
Not to sure why DA is using that as default if those permissions allow such open access.
I could be wrong, could someone please comment on this.
Thanks,
Adam
I was just told by some user of mine that it was possible to cd into anyones public_html and read files.
After checking I found it was, the user even managed to get alot of sql passwords from config files etc.
I'm still trying to clean the mess up.

Anyway, to the point. After searching for the general area of permissions on here I noticed, http://www.directadmin.com/features.php?id=497.
It appears like default DA install uses apache_public_html=0, so I changed it and created a new account. Then I checked out if the same problem happened on the new user, oddly it didn't.
I went through and chowned and chmoded the public_html dirs to USER:apache and 750. It seems to have fixed it.
Not to sure why DA is using that as default if those permissions allow such open access.
I could be wrong, could someone please comment on this.
Thanks,
Adam