Re: Group permissions changed
From: Glynn Clements (glynn_at_gclements.plus.com)
Date: 09/30/05
- Previous message: joop gerritse: "Re: Group permissions changed"
- In reply to: Eduardo Tongson: "Re: Group permissions changed"
- Next in thread: joop gerritse: "Re: Group permissions changed"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 30 Sep 2005 02:01:25 +0100 To: Eduardo Tongson <propolice@gmail.com>
Eduardo Tongson wrote:
> > I posted this before on the security basics, but haven't recieved
> > a response, and it worries me a bit, so I'm sending this to a few
> > other groups in hopes that someone will have an idea about it.
> >
> > ---
> >
> > Fairly recently I noticed my ftp client wouldn't list files in
> > certain directories on my server anymore - so I ssh'd in (it's
> > dedicated), and did a ls -aFl on the files, hoping to see what the
> > problem was - here are a few of the results:
> >
> > -rw-r--r-- 1 larry 503 371 2005-02-25 08:36 head.php
> > -rw-r--r-- 1 larry 48 873 2005-09-09 03:23 foot.php
> >
> > I never set the group ids to 503 or 48, so I checked just to make
> > sure - and no groups with those ids even exist. Is there an
> > exploit/tool that causes this, and should I be worried?
>
> 503 and 48 has [r] rights only no need to worry.
> Whoever uploaded the files probably had the owner/group preserved.
This can only happen if the ftpd is running as root (or has CAP_CHOWN,
if you're using capabilities).
An unprivileged process can only change a file's group to either its
EGID (FSGID on Linux) or one of its supplementary GIDs.
Files with an invalid UID or GID are usually caused by unpacking a tar
archive as root, in which case the UID and GID are set to the values
stored in the tar archive (unless you use --no-same-owner).
-- Glynn Clements <glynn@gclements.plus.com>
- Previous message: joop gerritse: "Re: Group permissions changed"
- In reply to: Eduardo Tongson: "Re: Group permissions changed"
- Next in thread: joop gerritse: "Re: Group permissions changed"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|