Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Securing base system file permissions.
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
RecoilUK
Tux's lil' helper
Tux's lil' helper


Joined: 13 Nov 2002
Posts: 94

PostPosted: Sun Apr 10, 2005 5:44 pm    Post subject: Securing base system file permissions. Reply with quote

Hi guys

I have a gentoo system that I have just installed, I was going to try and create a chroot enviroment for users, but it seems like its to much hassle and in some circumstances cant be done, so I have decided to keep it as it is.

I,m am however a little worried about the default file permissions on the system.

Is it safe and recommended to do the following ? ....

chmod o-rwx /*

Will it break anything?

How can I also stop users from reading files that arent in there home directory?

Can I do the following safelt and will it break anything? ...

chmod g-rw /*

Thanks guys
_________________
RecoilUK
Back to top
View user's profile Send private message
imp
n00b
n00b


Joined: 03 Dec 2002
Posts: 45
Location: Belgrade, SCG

PostPosted: Sun Apr 10, 2005 5:54 pm    Post subject: Reply with quote

Yes, it will break almost everything for users not in the root group. You must keep atleast r on the files, and rx on the dirs for other.

Take a look yourself: ls -l /usr, for example. Who owns those dirs and files beneath?
_________________
blog :: bookmarks
Back to top
View user's profile Send private message
RecoilUK
Tux's lil' helper
Tux's lil' helper


Joined: 13 Nov 2002
Posts: 94

PostPosted: Sun Apr 10, 2005 6:26 pm    Post subject: Reply with quote

Hi thanks for the reply.

Besides the root user, there will be one other user whose sole purpose is to su.

Then a few other users who will only be running a game server, the files needed for each game server will be located in there home dir.

Besides that, I,m running shorewall and sshd.

Thats everything the machine will be doing.

Surely everything in /bin should only be run as root, cant I chmod go-rwx that?

Thanks
_________________
RecoilUK
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum