The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
.
google unix.com



UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Bastille: classic Linux and Unix security - Help Net Security iBot UNIX and Linux RSS News 0 10-09-2007 08:40 AM
One Question about security tayyabq8 Security 9 05-22-2006 10:56 AM
security question blanks UNIX for Dummies Questions & Answers 0 03-01-2005 01:33 PM
PostFix security question fundidor UNIX for Dummies Questions & Answers 3 06-06-2004 11:46 PM
Unix Security DuttO UNIX Desktop for Dummies Questions & Answers 1 03-22-2002 12:41 PM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 08-09-2004
OBCCBIP OBCCBIP is offline
Registered User
  
 

Join Date: Nov 2003
Posts: 2
UNIX Security Question

Can other users delete / replace this file if the directory and file have the following permissions

/test drwxrwxrwx

/test/file _rw_r__r__

I guess what I really want to know is what the security riskis of having teh directory completely open when the access to a particular file is restricted.

Any help would be much appreciated.
Thanks
  #2 (permalink)  
Old 08-09-2004
RTM's Avatar
RTM RTM is offline Forum Advisor  
Hog Hunter
  
 

Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
Yes - see this post about directory permissions.
  #3 (permalink)  
Old 08-09-2004
OBCCBIP OBCCBIP is offline
Registered User
  
 

Join Date: Nov 2003
Posts: 2
Thanks,
this really helps!

Are there any known security restrictions that would prevent anyone from deleting the etc/passwd file and replacing it with one where the root password would be known if the permissions on the /etc directory were 777 or drwxrwxrwx ?
Given your response to the previous question I would suspect that one could get away with this if the permissions were not set correctly.

I want to lock down the permissions on the etc directory but cannot because there are scripts that run and require etc to have these permissions. I need to convince my manager that we need to be given time and budget to change this around, but I don't want to try and delete the passwd file just to prove my point to him.
  #4 (permalink)  
Old 08-09-2004
RTM's Avatar
RTM RTM is offline Forum Advisor  
Hog Hunter
  
 

Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
What OS and version are you using?

On Solaris, /etc should be 755 - allowing users to run scripts but not write or delete in the directory.
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 01:33 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0