nrep
Well-known member
I've been reading the XF installation documents and it mentions that the "IUSR_xxxx" account needs "Full Control" on the data / internal_data directories to function.
However, I thought that allowing full control was always a bad idea - as the execute permission isn't required, and could be used as an exploit vector.
Is it possible to just allow read/write permission for the IUSR account instead? Surely the tighter the ACL, the more secure things could be.
However, I thought that allowing full control was always a bad idea - as the execute permission isn't required, and could be used as an exploit vector.
Is it possible to just allow read/write permission for the IUSR account instead? Surely the tighter the ACL, the more secure things could be.