[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: file permisions in /etc



On 30/11/99 Quietman wrote:

I don't think that is likely to work since bit one is the execute bit and most
config files don't need to be executed, just read by the program that needs
them.

he does not mean the files in /etc, he suggested leaving the file's permissions alone and changing the /etc DIRECTORY permissions to 711, that would allow access to the contents of /etc (given permission to individual file's permission) but not allow a general listing of the /etc directory.

in other words you can access anything just as you can now, the only difference is you would need to know its exact filename and that it exists to access it, you would be unable to get that information from a ls -l on /etc.

but this is really no added security since most files in /etc are 1) not security critical, and if they are they are protected anyway and 2) most files in /etc are in every linux systems /etc so getting filenames is trivial.



Ethan Benson
To obtain my PGP key: http://www.alaska.net/~erbenson/pgp/


Reply to: