The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
Google UNIX.COM


UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Bastille: classic Linux and Unix security - Help Net Security iBot UNIX and Linux RSS News 0 10-09-2007 05:40 AM
One Question about security tayyabq8 Security 9 05-22-2006 07:56 AM
security question blanks UNIX for Dummies Questions & Answers 0 03-01-2005 10:33 AM
PostFix security question fundidor UNIX for Dummies Questions & Answers 3 06-06-2004 08:46 PM
Unix Security DuttO UNIX Desktop for Dummies Questions & Answers 1 03-22-2002 09:41 AM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 08-09-2004
Registered User
 

Join Date: Nov 2003
Posts: 2
UNIX Security Question

Can other users delete / replace this file if the directory and file have the following permissions

/test drwxrwxrwx

/test/file _rw_r__r__

I guess what I really want to know is what the security riskis of having teh directory completely open when the access to a particular file is restricted.

Any help would be much appreciated.
Thanks
Reply With Quote
Forum Sponsor
  #2  
Old 08-09-2004
RTM's Avatar
RTM RTM is offline
Hog Hunter
 
Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
Yes - see this post about directory permissions.
Reply With Quote
  #3  
Old 08-09-2004
Registered User
 

Join Date: Nov 2003
Posts: 2
Thanks,
this really helps!

Are there any known security restrictions that would prevent anyone from deleting the etc/passwd file and replacing it with one where the root password would be known if the permissions on the /etc directory were 777 or drwxrwxrwx ?
Given your response to the previous question I would suspect that one could get away with this if the permissions were not set correctly.

I want to lock down the permissions on the etc directory but cannot because there are scripts that run and require etc to have these permissions. I need to convince my manager that we need to be given time and budget to change this around, but I don't want to try and delete the passwd file just to prove my point to him.
Reply With Quote
  #4  
Old 08-09-2004
RTM's Avatar
RTM RTM is offline
Hog Hunter
 
Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
What OS and version are you using?

On Solaris, /etc should be 755 - allowing users to run scripts but not write or delete in the directory.
Reply With Quote
Google The UNIX and Linux Forums
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 11:53 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0