11-23-2006
The point we are making is this:
With chmod 777, you are giving all rights on all the files to ANY user.
Lets say a hacker managed to find an exploit which allows him to gain some kind of access to your server through a vulnerable service, which allows him to execute code as the user of the service.
If the last 6/7 is there it means he can change your files regardless of which user he gets access as. (The keys are in the car)
With the second 6/7 if means that anyone in the group can change the files. (You given someone the valet key to the car)
With only the first 6/7 you (the owner) only can make the changes. ( the key to the car is in your pocket)
So as you can see, someone malicious has more to do in each case, before they can change your files.
7 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
I've got 100 directories that each have 2 directories with in them.
Structered like this:
/home/domains/domain1/
through to
/home/domains/domain100/
and those 2 directories mentioned above are here:
/home/domains/domain1/directory1/
/home/domains/domain1/directory2/
through to... (7 Replies)
Discussion started by: Neko
7 Replies
2. Solaris
Hello Everyone:
One of our admins here accidently ran chmod -R 777 in the /usr folder on a V440 running Solaris 9. After that no one could run any command and could not login. I fixed most of the things by re-restricting some rights and applying the correct rights. Now there is a problem... (3 Replies)
Discussion started by: muntaser_zaheer
3 Replies
3. UNIX for Dummies Questions & Answers
I can belive I really did this... chmod 777 /home :eek:
I have my /home directory synced to another machine.
Can anyone tell me how to get the permissions from
back up server /home to production server /home
It's important that I dont over write the files on the... (1 Reply)
Discussion started by: shunter63
1 Replies
4. Cybersecurity
User usrA creates dirA directory and runs chmod 777 on the directory. Can usrB issue another 777 on dirA? It appears the answer is no even if the usrA and usrB are part of the same group. I know this is a rare scenario but I just ran across it and found out that usrB receives an error when... (4 Replies)
Discussion started by: zlek131
4 Replies
5. UNIX and Linux Applications
i think it is the same in both... Iam i right? (1 Reply)
Discussion started by: sumaiya
1 Replies
6. Windows & DOS: Issues & Discussions
Hello,
I use windows XP on a small server. Lately I downloaded a software (hydrological computation) which asked me to install as well the software ‘cygwin' (kind of linux in windows environment) and then to perform in cygwin window the command: ‘chmod -R 777 *' in order to give writings... (2 Replies)
Discussion started by: Cedalise
2 Replies
7. UNIX for Dummies Questions & Answers
Hey everyone. I have 2 different linux servers (each one is through a different web hosting company). On both servers I have the exact same PHP file upload script that allows users to upload a file or image to the server (everything on both servers is identical).
On server #1 the "attachments"... (5 Replies)
Discussion started by: Mr.Canuck
5 Replies
LEARN ABOUT DEBIAN
mrtg-forum
MRTG-FORUM(1) mrtg MRTG-FORUM(1)
NAME
mrtg-forum - Interactive Help for MRTG users
SYNOPSIS
There is a lot of written documentation for mrtg, but nevertheless you may have a problem where you can't find the solution. In this case
some Human Help may be necessary. With MRTG there are several ways to get Humans to help you.
MAILING-LIST
There are three mailing lists for MRTG available.
mrtg
for discussion among mrtg users.
mrtg-announce
for announcements regarding new versions of mrtg related software.
mrtg-developers
for discussion among people who write software in connection with mrtg or who hack mrtg itself.
THE RULES
Please note that the memebers of the mrtg mailinglist value politeness highly. This means behave in a way you would like others to behave
towards you.
o No shouting. (NO CAPS)
o No rude language
o No demands. everybody is on the list out of their own free will. If you do not get an answer to your question, chances are high that
you did not give sufficent details about the nature of your problem or that the answer to your problem is in the documentation.
o If you do not follow the rules you will be unsubscribed from the list with no further questions asked.
o Decisions about your unsubscription from the list will be taken by
Alex van den Bogaerdt <alex at ergens.op.het.net>
Paul C. Williamson <pwilliamson at MANDTBANK.COM>
If you feel that you have been treated unfairly, you may send mail to me and explain the situation.
Tobi Oetiker <tobi@oetiker.ch>
SUBSCRIBING
These lists are managed by a mailing-list management program (listar). It allows you to subscribe to these lists by sending a message with
the subject: subscribe to the following address:
listname-request@lists.oetiker.ch
You will then get a message asking you to confirm your subscription.
For posting to the lists use the following address
listname@lists.oetiker.ch
Note that only people who are subscribed to the list can post.
Further information about the usage of the mailing lists is available by sending a message with the subject line help to either one of the
request addresses.
There is also a webinterface to the lists on
http://lists.oetiker.ch
List archives are on
http://www.mail-archive.com/index.php?hunt=mrtg
and
http://gmane.org/find.php?list=mrtg
NEWSGROUP
For discussion of MRTG or related topics on the Usenet, please send your posts to:
news:comp.dcom.net-management
Many MRTG users are in this forum and will help you. You can also find an archive of past activity from this Newsgroup on:
http://groups.google.com/group/comp.dcom.net-management
IRC Channel
For discussion of MRTG and related topics on IRC, the `#mrtg' channel on EFNet has been created.
More information can be found at
http://mrtg.easymac.org
MRTG Japan
There is a special Mailinglist for MRTG Users in Japan. It carries translations of the traffic from MRTG-ANNOUNCE as well as updates on the
Japanese Translation of the MRTG documentation. Go to http://www.mrtg.jp/ for further Information.
AUTHOR
Tobias Oetiker <tobi@oetiker.ch> and many contributors
2.17.4 2012-01-12 MRTG-FORUM(1)