Commit 31b00e41 authored by Stephen Mustgrave's avatar Stephen Mustgrave
Browse files

Issue #2535944: patch Details for file permissions security review report

parent 62edf2a4
Loading
Loading
Loading
Loading
+30 −0
Changes for src/Checks/FilePermissions.php: 30 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -99,9 +99,39 @@ class FilePermissions extends Check {
   * {@inheritdoc}
   */
  public function help() {
    $markup = <<<HTML
In addition to inspecting existing directories,
      this test attempts to create and write to your file system. Look in
      your security_review module directory on the server for:
       <ul>
         <li>
           A file named: file_write_test.YYYYMMDDHHMMSS
           <ul>
             <li>
               If this file exists the web server can write files to the
             security_review module directory and perhaps to other directories.
             You should correct the file permissions on all code directories of
             your Drupal installation.
             </li>
          </ul>
         </li>
         <li>
           Open the file IGNOREME.txt.
           <ul>
             <li>
              If a timestamp is appended at the end of
              it.  That means the web server has permission to write to your files.
              This is insecure and the permissions should be corrected.
             </li>
           </ul>
         </li>
       </ul>
HTML;

    $paragraphs = [];
    $paragraphs[] = $this->t('It is dangerous to allow the web server to write to files inside the document root of your server. Doing so could allow Drupal to write files that could then be executed. An attacker might use such a vulnerability to take control of your site. An exception is the Drupal files, private files, and temporary directories which Drupal needs permission to write to in order to provide features like file attachments.');
    $paragraphs[] = $this->t('In addition to inspecting existing directories, this test attempts to create and write to your file system. Look in your security_review module directory on the server for files named file_write_test.YYYYMMDDHHMMSS and for a file called IGNOREME.txt which gets a timestamp appended to it if it is writeable.');
    $paragraphs[] = $this->t($markup);
    $paragraphs[] = new Link(
      $this->t('Read more about file system permissions in the handbooks.'),
      Url::fromUri('http://drupal.org/node/244924')