LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 03-23-2015, 10:31 AM   #1
netops
LQ Newbie
 
Registered: Mar 2015
Posts: 2

Rep: Reputation: Disabled
File got deleted in samba with read only user


Hi,

I am using samba-3.4.6 file server on centos-5.8 under winbind authentication with SMBLDAP domain server. Last day I found one of file was missing from a folder, after checking smbaudit log I came to know that file got deleted by a user (abc) that don't have read & write permission on that path. I checked with user (abc) login physically on his system but user (abc) are unable to modify/delete/create any file at that path.

As per my past experience I got smbaudit log correct every time but not sure with this case.

File was missed, smbaudit logged the event but that user (abc) don't have write permission on that folder.

Could you please advise the possible reason for this event.

Thanks and regards,
Shekhar
 
Old 03-24-2015, 07:20 AM   #2
rtmistler
Moderator
 
Registered: Mar 2011
Location: USA
Distribution: MINT Debian, Angstrom, SUSE, Ubuntu, Debian
Posts: 9,882
Blog Entries: 13

Rep: Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930Reputation: 4930
It sounds as if you're saying that the log clearly shows that "user abc deleted a file" and when you looked further using two methods, you verified that (a) user abc does not have read, nor write permissions to the specific directory, and (b) you attempted to delete a file as that user, were unable too, and the log indicates that it was attempted, the attempt failed, and why the attempt failed.

Is this correct? If so, it does make no sense.

Can you clarify your description of the problem, because I think it's open to interpretation as to exactly what happened and how you're diagnosing it.

For diagnosis, I would put a test file in that directory and then attempt to access and delete that file as this user.
 
Old 03-24-2015, 11:30 PM   #3
netops
LQ Newbie
 
Registered: Mar 2015
Posts: 2

Original Poster
Rep: Reputation: Disabled
smbaudit log pointing that file deleted successfully

Mar 18 14:51:44 cswpp1 smbd_audit: CSW\abc|192.168.xx.xxx|SOFTWARE|unlink|ok|shiftinchargedownload/SplashScreen.dll

and below is ACL permission output of shiftinchargedownload folder. where abc is member of unvdfa group & he has read only rights.

# file: shiftinchargedownload
# owner: CSW\134bis
# group: root
user::rwx
group::r-x
group:CSW\134software:r-x
group:CSW\134unvdfa:r-x
group:BUILTIN\134users:r-x
group:CSW\134adeptsupt:r-x
mask::rwx
other::---
default:user::rwx
default:group::r-x
default:group:CSW\134software:r-x
default:group:CSW\134unvdfa:r-x
default:group:BUILTIN\134users:r-x
default:group:CSW\134adeptsupt:r-x
default:mask::rwx
defaultther::---

After this event, user abc is unable to create/modify/delete files/folder under shiftinchargedownload.

Please reply in case any information needed to trace this event.
 
Old 03-25-2015, 04:48 AM   #4
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,830

Rep: Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308
Is this reproducible?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hi where do i find deleted file from samba link.? hamisngos Linux - Newbie 4 06-02-2013 08:17 PM
File/User permissions - how it can be deleted? laki47 Linux - Newbie 6 02-19-2009 12:49 AM
who deleted share file/folder in samba ? megerdin Linux - Server 6 09-18-2008 08:06 AM
restricted user to only read an other read and write in samba Gran_Maestre Linux - Security 0 02-12-2008 01:16 PM
how to check who deleted a file in samba server tajamari Linux - General 2 08-14-2007 09:48 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 10:12 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration