LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-30-2005, 12:59 PM   #1
keysorsoze
Member
 
Registered: Apr 2004
Location: Queens, NY
Distribution: Red Hat, Solaris
Posts: 295

Rep: Reputation: 30
Folder Security


Hi! I currently have a question regarding folder security. I have a Linux box at work and created two user accounts for two specific portions of the company. One for the marketing department and sales department. I created two users called markdept and salesdept. Inside those to users I have added to folders each user called posted_work and work_completed.

For example : /home/markdept/posted_work
/home/markdept/work_completed

Then I added members to each group and chmodded
both the markdept and salesdept home folders with 770 which only allows the owner and group members to see the /home/posted_work

chmod 770 /home/markdept

The current situation is that even though I chmod the folder called posted_work with 750 which is only d-rwxr-x--- and assign an owner with
chown -R user1:markdept /home/markdept/posted_work people in the markdept group can still delete the folder called /home/markdept/posted_work. I have done an ls -l on the folders and see that owner has full privileges, groups have only read and execute, and zero permissions to others. However how can members of the group still delte the folder using the rm -rf command.

Sorry for the long post I am just stuck and need to find a resolution fast for security purposes.
 
Old 11-30-2005, 04:09 PM   #2
tkedwards
Senior Member
 
Registered: Aug 2004
Location: Munich, Germany
Distribution: Opensuse 11.2
Posts: 1,549

Rep: Reputation: 52
This is the correct behaviour - the markdept group has rwx permission on /home/markdept/. This means that they can delete anything in /home/markdept, including any subdirectories. However if you put a file in posted_work that the markdept group doesn't have permission to delete you'll have effectively stopped them from being able to delete posted_work.
 
Old 11-30-2005, 08:48 PM   #3
keysorsoze
Member
 
Registered: Apr 2004
Location: Queens, NY
Distribution: Red Hat, Solaris
Posts: 295

Original Poster
Rep: Reputation: 30
Hi! Thanks for the reply I was going nuts trying to figure out why I was able to delete a folder when I was not granting the permission so I just added a file that belonged specifically to root.

Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Folder Max Size and Limiting SSH access to home folder. Mefistofeles Linux - General 4 11-26-2005 02:09 PM
Samba WinXP roaming profile not loaded because folder exists with incorrect security. fireman949 Linux - Enterprise 1 10-28-2005 07:52 PM
permissions difference between /home/..../folder and /root/folder darkleaf Linux - General 3 07-21-2005 05:23 PM
Reboot and folder security. What the...? lowbrow Linux - Security 9 06-20-2005 06:02 PM
how can i default the max folder file size when it create inside a folder antony_csf Linux - Software 1 06-17-2004 02:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration