educational

CGI, Permissions, and Your Host

One year ago this month, Stephen wrote an article concerning the basics of setting UNIX file permissions in order for a CGI (Common Gateway Interface) script to perform properly. If you are unsure in the least of what I'm talking about, make sure you read his article.

Almost every CGI script you come across, and there are thousands out there, will have a reference in their "readme" or install files pertaining to making a particular file or folder 'world writeable' or chmod 777. From a simplicity standpoint, the 777 permissions basically say that anyone that gains access to the file, can read, write, and execute the script. In today's advanced society, where hacking is commonplace, hosts are becoming very leery or not allowing it at all due to security issues. With web hosts becoming stricter and not allowing world writeable files, this brings most CGI and even some php scripts to a screaming halt; or does it?

Unfortunately for many of us, knowing nothing more than basic FTP uploading and the setting of file permissions for a script is the extent of our knowledge. With many hosts not allowing the 777 permissions, and more doing so every day, it doesn't necessarily mean that our use of scripts is extinct. If and only if your host has set-up the server properly, and we're only talking about UNIX based machines here, a world directory or file does not need to be world writeable. Some coders and even hosts will disagree with this but we personally use a host of this nature, and we use a multitude of scripts.

Web hosts are more advanced today than they were even just a year ago; the days of having to telnet into your account to add an .htaccess file are almost gone, and it won't be too long before having to set your file's permissions will be too. The proliferations of hosts now or already having implemented such programs like web based control panels, phpMyAdmin, and SBOX only verify these facts. As in the case of our host, even the main path to perl doesn't need to be changed; it recognizes the script and automatically determines the path for it; and our sendmail path too.

Our biggest hurdle with these advancements (remember, we're talking about hosts that do not allow 777 permissions) is when we encounter some sort of internal server error, such as 500 errors, 403, and so on. Again, if the host has the knowledge and has set-up the server correctly, we usually find the script to be of the problem in one form or another; which is the case with either type of host. The majority of the time we have not set a variable or path correctly. In some of the more advanced cases where some of us are more adept at modifying a script (hack as they call it) for HTML or other purposes, we may have deleted a variable or added something as simple as a quotation mark. The last option is the fact that the script itself may be the problem and no matter what you or the server does, it just isn't going to work.

In either of the former instances, we need to look at the error logs before thinking the server or your permission is the culprit. I don't want to get into troubleshooting scripts as it is too diverse of a subject but at least you understand what basic steps to take when using a host such as this. Don't get me wrong here, you do need to set permissions, it's the files needing to be set world writeable that we're talking about. What calls for a 777 permission, can be used just fine with 755 permissions. What calls for a 777 ... can be used just fine with 755 permissions.

When you incorporate scripts, you'll need to ask your host or prospective host a few questions. The first and foremost question being "do they allow world writeable files and directories (folders)?" if not, how does the server handle it? (If they allow CGI at all). You truly don't need to know the specifics; you just don't want to be banging your head against a wall because that custom script isn't working. This also includes some php scripts as well; which we recently encountered a problem with. In the end, we found the problem with how it was coded and not a permissions setting (it called for 777 settings). Here is where your selection of scripts is a very important point, if you select a script that has minimal or no support (particularly free ones), then you're asking for trouble and you will possibly wind up spending money for the hosts support personnel to help locate and solve the problem. Which again, can happen with any host whether they allow 777 permissions or not.

While all this sounds troublesome, the true fact is, it makes your scripts much more secure. Making a file world writeable is similar to leaving your image directory completely open for access. With the help of good support technicians, your scripting problems are less than that of what you would encounter normally. It's been drilled into us as users that world writeable permissions are needed, and today it is not so with the proper host. The argument over using programs that "help" or determine how scripts execute are resource intensive and slow servers or even that they're costly, is moot. With properly maintained hardware, good Net connections, and systems that are not overloaded, you will never see a difference in how your site is served.

That's what a good host is supposed to be anyway, one that provides knowledgeable support, uptime, and looks out for its clients security as well as it's own. In choosing a host for a site that incorporates scripts, no matter whether it's only a link submission form or a full bore personals site, all parties security especially sensitive data, should be considered.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

opinion

Inside the OCC's Debanking Review and Its Impact on the Adult Industry

For years, adult performers, creators, producers and adjacent businesses have routinely had their access to basic financial services curtailed — not because they are inherently higher-risk customers, but because a whole category of lawful work has long been treated as unacceptable.

Corey Silverstein ·
opinion

How to Build Operational Resilience Into Your Payment Ecosystem

Over the past year, we’ve watched adult merchants weather a variety of disruptions and speedbumps. Some even lost entire revenue streams overnight — simply because they relied too heavily on a single cloud provider that suffered an outage, lacked sufficient redundancy and failover, or otherwise fell short when it came to making sure their business was protected in case of unwelcome surprises.

Cathy Beardsley ·
opinion

Building a Stronger Strategy Against Card-Testing Bots

It’s a scenario every high-risk merchant dreads. You wake up one morning, check your dashboard and see a massive spike in transaction volume. For a fleeting moment, you’re excited at the premise that something went viral — but then reality sets in. You find thousands of transactions, all for $0.50 and all declined.

Jonathan Corona ·
opinion

A Creator's Guide to Starting the Year With Strong Financial Habits

Every January brings that familiar rush of new ideas and big goals. Creators feel ready to overhaul their content, commit to new posting schedules and jump on fresh opportunities.

Megan Stokes ·
opinion

Pornnhub's Jade Talks Trust and Community

If you’ve ever interacted with Jade at Pornhub, you already know one thing to be true: Whether you’re coordinating an event, confirming deliverables or simply trying to get an answer quickly, things move more smoothly when she’s involved. Emails get answered. Details are confirmed. Deadlines don’t drift. And through it all, her tone remains warm, friendly and grounded.

Women In Adult ·
opinion

Outlook 2026: Industry Execs Weigh In on Strategy, Monetization and Risk

The adult industry enters 2026 at a moment of concentrated change. Over the past year, the sector’s evolution has accelerated. Creators have become full-scale businesses, managing branding, compliance, distribution and community under intensifying competition. Studios and platforms are refining production and business models in response to pressures ranging from regulatory mandates to shifting consumer preferences.

Jackie Backman ·
opinion

How Platforms Can Tap AI to Moderate Content at Scale

Every day, billions of posts, images and videos are uploaded to platforms like Facebook, Instagram, TikTok and X. As social media has grown, so has the amount of content that must be reviewed — including hate speech, misinformation, deepfakes, violent material and coordinated manipulation campaigns.

Christoph Hermes ·
opinion

What DSA and GDPR Enforcement Means for Adult Platforms

Adult platforms have never been more visible to regulators than they are right now. For years, the industry operated in a gray zone: enormous traffic, massive data volume and minimal oversight. Those days are over.

Corey D. Silverstein ·
opinion

Making the Case for Network Tokens in Recurring Billing

A declined transaction isn’t just a technical error; it’s lost revenue you fought hard to earn. But here’s some good news for adult merchants: The same technology that helps the world’s largest subscription services smoothly process millions of monthly subscriptions is now available to you as well.

Jonathan Corona ·
opinion

Navigating Age Verification Laws Without Disrupting Revenue

With age verification laws now firmly in place across multiple markets, merchants are asking practical questions: How is this affecting traffic? What happens during onboarding? Which approaches are proving workable in real payment flows?

Cathy Beardsley ·
Show More