One of my sites on a shared hosting environment was recently defaced. The CI apps i had on the server seemed to hold up pretty well against intrusion except one where i was using simplepie and a cache folder with permissions set to 777.
It looks like the intruders were able to gain access to the shared server then just went thru and looked for any files or folders in all accounts on the server with permissions set to 777 and then had all sorts of fun in those areas.
So, does anybody know how to get simplepie to work without having a cache folder set to 777? As every time i set the cache folder to anything other than 777 i get i nice warning appearing at the top of my pages:
Severity: User Warning
Message: /home/mysite/public_html/application/cache/e126761e8ae74b6192cbf9ea2b46b1eb.spc is not writeable
Filename: libraries/simplepie.php
Line Number: 1773