Re: deny deleting a file for users.. trying a solution

From: Nathan Vack (njvack_at_lithium.hsl.wisc.edu)
Date: 06/18/03

  • Next message: Genome .: "Re: Linux firewall/IDS/NAT suggestions"
    Date: Wed, 18 Jun 2003 12:15:54 -0500
    To: focus-linux@securityfocus.com
    
    

    Zow Terry Brugger wrote:

    > Light bulb goes on above head -- check out LIDS (lids.org)
    ...
    > working normally. However, if you just want to protect the one file, you
    > should be able to set it up so that nothing can modify the directory it
    > resides in, and explicitly allow /usr/bin/netscape (or whatever) full access
    > to the directory. That way, users will not be able to delete the file from a
    > shell, but Netscape can continue to do its thing normally.

    Note that LIDS permissions work by inode number, so if you do the
    "obvious thing" and protect the FILE you want to protect, the first time
    it gets recreated (which your mail client may well decide to do) you'll
    lose your protection and be left scratching your head.

    So you really do want to do it per directory.

    Just a minor caveat, really...

    -Nate


  • Next message: Genome .: "Re: Linux firewall/IDS/NAT suggestions"

    Relevant Pages

    • Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks
      ... For example, if I want to protect the /etc/ shadow file regardless of what tool is used to safely modify it, I would set ... A tool like vipw does creat writerenameto overwrite the /etc/shadow file, so any SELinux system relying _only_ on inode is guaranteed to break. ... @old_dentry contains the dentry structure for an existing link to the file. ...
      (Linux-Kernel)
    • Re: Total loss
      ... and was really the first time that sort of ... I can't argue that nuclear weapons facilities aren't obviously in need ... Did they build the nuclear weapon facility that they didn't protect? ... they might have reasonably expected the NPCs who did build ...
      (rec.games.frp.advocacy)
    • Re: "secure" file flag?
      ... >> I may be way off, but I do not think, that a special thread or ... > What happens if you yank the power cord? ... is meant to protect against traces of sensible data being left on ... But such an inode would also ...
      (freebsd-hackers)
    • Re: Passwords
      ... When you save the workbook the first time there is a dialogue ... in the upper right tools, click and from dropdown select General Options, ... there you can password protect the file from being opened ... > Tools menu, select Options, then the General tab. ...
      (microsoft.public.excel.misc)
    • Re: OE6, identities, updates & SP2
      ... Protect your PC ... "Greg" wrote in message ... > Using the "exit" or "X" option causes the last identity used to be the ... > the request for an identity works fine the first time, ...
      (microsoft.public.windows.inetexplorer.ie6_outlookexpress)