hmmm...
Not sure how a txt file could execute - regardless I must confess that Im no expert on that subject. I thought they would still need ftp access to your site to write into the directory. GAS has the ability to limit what content can be uploaded (by extension) to prevent executables being uploaded.
Ill see what I can find out but in the meantime you can try:
1- Turn off the ability to upload their own images - just use the gallery side of things. Then you can chmod to normal permissions.
2- I havent tried this, but in theory: only Apache needs write access so maybe try making the owner of the gab/images folder (and sub directories) Apache, and give the apache user write permissions and the group read/execute.
Im open to any other suggestions.
|