Thanks for the info.
I always use IE to enter the FTP area.
Then I rightclick ...Properties...and that gives me the permissions which can be changed at the same time.
For the mainfile.php:
Well, its still there but I have removed all its content.
Then I have defined a XOOPS_TRUST_PATH which is outside of the public_html area.
The data from inside the mainfile are in a different file inside the XOOPS_TRUST_PATH and are included when the mainfile.php is included.
Now, if someone hacks into my public_html, there are nowhere passwords or database names to be found.