[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: RC Security Flaw - mkdir & script create as 755, 644. SB &700, yes?



On Mon, Feb 25, 2002 at 10:28:47PM +0000, Andrew Beresford wrote:
> umask can do this. Any sysadmin running a multiuser system who doesn't
> know how to use umask has far worse problems than leaving files open to
> read.
> 
> 755 seems like a fairly reasonable default to me. (is that what's it's
> set to? I haven't checked!)

755 has been the classic default.  By request of many people, a config
question has been added to prevent world read of user's files by default,
I believe the home directories are created with permissions 751 in that
case.  Since the default on a Debian system is to give each user their own
group, this is reasonable.

I personally know of little harm execute permission can do on a directory
without read permission.  I don't fancy people playing around in my ~
either, but ~knghtbrd/src and ~knghtbrd/public_html are fair game for
local users.

-- 
Joseph Carter <knghtbrd@bluecherry.net>       My opinions are always right
 
<Culus-> libc6 is not essential :|

Attachment: pgpvd2OoCUSLC.pgp
Description: PGP signature


Reply to: