LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-23-2012, 06:39 AM   #1
joaquin.65
LQ Newbie
 
Registered: Jun 2012
Posts: 6

Rep: Reputation: Disabled
Exclamation Indetectable issue with permissions


Hi!
I have a problem here, which I can't pinpont anywhere.
I'll post some output from the terminal adding comments to explain.
I use Debian and Samba.

Here we go:

I have some users, and I manage permissions by adding them to certain groups. The thing is, I found that some user can access folders that he's not supposed to be able.

So, first:

Code:
root@server-AMYQ:~# groups glimone
glimone : micro1 admin1 micro2
And then:

Code:
root@server-AMYQ:/mnt/AMYQ# ls -l
total 64
drwxrwx--x  4 netadm admin1  4096 ago 22 16:10 ADMIN
So, users that belong to group "admin1" can rwx folder ADMIN. So user "glimone" can go inside, since he belongs to groups micro1, admin1 and micro2.

But here's the mess. Let's go inside folder ADMIN and ls -l:

Code:
root@server-AMYQ:/mnt/AMYQ/ADMIN# ls -l
total 5996
drwxrwx--x 2 netadm   admin2    4096 ago 22 16:10 1.- CLIENTES
drwxrwx--x 2 netadm   admin2    4096 ago 22 15:47 2.- ELABORACION DE INFORMES
We have these two folders, and if you pay attention to permissions you'll notice that to access them you need to belong to group "admin2".
As I showed you earlier, user "glimone" doesn't belong to group "admin2". But he can go in, and write!!!

WTF is going on here?!
Maybe it's something with /etc/passwd, or /etc/group? Or with the samba share.
If you need any more information about this to help me solve it, plz post it, and I'll reply soon.

EDIT: All of this happens if I access the folders through samba. If I log with "glimone" directly on the terminal I get the correct Permission Denied message. So that makes me think this is all about samba...
Here's the configuration of the share
Code:
[1.- ADMINISTRACION]
   path = /mnt/AMYQ/ADMIN
   public = yes
   valid users = jbenitez, xpascale, glimone, lacosta, mmondelli, vskrycki, mportas, bgonzalez, netadm
   writable = yes
   create mask = 0755
   force create mode = 0775
   force group = admin2
PLEASE lend me a hand here!
Thanks in advance!

Joaquín.

Last edited by joaquin.65; 08-23-2012 at 08:28 AM.
 
Old 08-23-2012, 08:33 AM   #2
r0b0
Member
 
Registered: Aug 2004
Location: Europe
Posts: 608

Rep: Reputation: 50
Remove the "force group" line from your smb.conf. It's causing that all users are given permissions of this group.
 
1 members found this post helpful.
Old 08-23-2012, 08:37 AM   #3
joaquin.65
LQ Newbie
 
Registered: Jun 2012
Posts: 6

Original Poster
Rep: Reputation: Disabled
THANKS!!!!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CD-rw drive permissions issue. mitchell7man Ubuntu 21 04-17-2007 04:16 PM
Can't su (permissions issue) WeNdeL Linux - General 3 12-05-2005 10:48 AM
Permissions issue? thoffland Debian 8 07-06-2005 02:17 PM
permissions issue with X gvaught Debian 3 01-02-2005 12:07 PM
Folder Permissions Issue Aman9090 Slackware 2 10-17-2003 11:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration