RE: User can delete root's file from user's home directory

From: Alexandre Skyrme (alexandre.skyrme_at_ciphersec.com.br)
Date: 10/28/04

  • Next message: Danny Puckett: "AW: Two VPN clients on one computer"
    To: <security-basics@securityfocus.com>
    Date: Thu, 28 Oct 2004 15:05:05 -0300
    
    

    Greetings Jimbo,

    That behavior is normal. Test's home directory (/home/test) is owned by test
    and he (probably) has write permission on it. That means he is allowed to
    erase any files in the directory, no matter what user created the file. If
    you try to change the data in the file created by root you won't be able to,
    however you should be able to erase it and create a new one with whatever
    data suits you.

    In order to put a file in a user's home directory and prevent him from
    erasing/altering/renaming it you could look at chattr (with the +i
    attribute).

    Regards,

    --
    Alexandre Skyrme
    Cipher - Segurança da Informação
    +55-21-2529-2629
    www.ciphersec.com.br
     
    Esta mensagem eletrônica pode conter informações privilegiadas e/ou
    confidenciais, portanto fica o seu receptor notificado de que qualquer
    disseminação, distribuição ou cópia não autorizada é estritamente proibida.
    Se você recebeu esta mensagem indevidamente ou por engano, por favor,
    informe este fato ao remetente e a apague de seu computador imediatamente.
    This e-mail message may contain legally privileged and/or confidential
    information, therefore, the recipient is hereby notified that any
    unauthorized dissemination, distribution or copying is strictly prohibited.
    If you have received this e-mail message inappropriately or accidentally,
    please notify the sender and delete it from your computer immediately.
    -----Original Message-----
    From: Imre [mailto:jimbo@mailbox.hu] 
    Sent: quinta-feira, 28 de outubro de 2004 08:29
    To: security-basics@securityfocus.com
    Subject: User can delete root's file from user's home directory
    Hello
    I have a big problem.
    On my system I have 2 users, root and a test-user named test.
    I made this:
    (as root, in /home/test)
    # touch testfile
    # echo probe > testfile
    After this I type 'ls -l' and get:
    test:/home/test# ls -l
    total 4
    -rw-r--r--    1 root     root            6 Oct 28 13:27 testfile
    OK, it's default, right?
    But my problem starts here:
    test@test:~$ ls -l
    total 4
    -rw-r--r--    1 root     root            6 Oct 28 13:27 testfile
    test@test:~$ rm testfile
    rm: remove write-protected file `testfile'? y
    teszt@teszt:~$ ls -l
    total 0
    teszt@teszt:~$
    I don't want to delete files and directories from my ~ which made by 
    root. Could anyone help me?
    (Sorry about my english, usually only read this language)
    Thanks
    Jimbo
    

  • Next message: Danny Puckett: "AW: Two VPN clients on one computer"

    Relevant Pages

    • Re: Disk Druid - Fedora flame #1
      ... What I do as root, ... Root's home directory should contain very little: ... part of a minimal boot environment. ... And the root filesystem should be as small as reasonably possible, ...
      (Fedora)
    • Re: X11Forwarding, ssh -X, and /bin/su
      ... ]>but I'm not really tunneled using ssh then, ... ]connecting to the X server and have the home directory NFS-mounted ... ](unless you leave root unmapped over NFS, ... ]root-readable place and set the environment $XAUTHORITY variable ...
      (comp.security.ssh)
    • Re: Shared User Folders and printer setup
      ... only mapping to the root? ... I have a 2003 standard server setup running as a Terminal Server to allow our other location to access our main SBS 2003 server and run our Mfg/accntg software. ... In order to get this software to work Trans-Micro (the makers of Check Factory) have a detailed procedure that allows multiple Terminal Server users to run the software at the same time. ... Does anyone have any idea why and how can I get it to look at the Home directory path Z: ...
      (microsoft.public.windows.terminal_services)
    • Re: Excellent news.. Malware for OS X!
      ... compromise and that nothing is immune. ... If it isn't already running as root, it will ask for the password ... the majority of Mac users, then malware has an even larger reach. ... Another method of avoiding that is to simply copy everything in /Applications to somewhere in your home directory and changing links appropriately. ...
      (comp.sys.mac.advocacy)
    • Re: move your home directory - second newsgroup post
      ... I'm fairly sure you'll have to enable root access ... user's home directory. ... I've never found ANY action that requires enabling ... Steve W. Jackson ...
      (comp.sys.mac.misc)