LinuxQuestions.org
Register a domain and help support LQ
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 12-29-2003, 03:07 AM   #1
carlosruiz
Member
 
Registered: Jul 2003
Location: Japan
Distribution: Mandrake
Posts: 53

Rep: Reputation: 15
is it safe to set /var to chmod 777


hello all, i want to install bbclone in my server, the software requires /var and all subdirectories to have 777 permissions, i wonder if it will be safe do do so. thanks in advance
 
Old 12-29-2003, 03:40 AM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 69
What?!?!?! That would let all users write and delete logs (/var/log)! Also, if you have named (BIND) configured, the zone files are most likely in /var/named (which could then be modified by users). Oh, and /var/run stores PID files used by daemons to keep track of whether they're already running... Oh, and /var/spool/mail and /var/spool/cron... I could go on forever. Suffice it to say: NO, that is NOT SAFE.

What the heck kind of software requires those permissions? That's insane! No correctly written software should ever require anything like that.
 
Old 12-29-2003, 03:54 AM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 57
I actually had the same response and I couldn't believe it, so I checked the install howto for bbclone and it does indeed require 777 settings for all the dirs in /var (666 for all the files). I'd have to second chorts feelings that it's crazy to do that. You'd be allowing anyone to read and edit any of the system logs as well as modify any files in webserver directories, CGI scripts etc. You should really think twice before installing that.
 
Old 12-29-2003, 04:21 AM   #4
carlosruiz
Member
 
Registered: Jul 2003
Location: Japan
Distribution: Mandrake
Posts: 53

Original Poster
Rep: Reputation: 15
Thank you very much guys for your replys, i hope this helps other people to think twice before installing bbclone.
 
Old 12-31-2003, 04:00 AM   #5
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 69
Hopefully this bbclone thing isn't very popular, because that's just an instant rooted box waiting to happen. All you need is one little slip-up on the webserver that let's you write to an arbitrary file, and BOOM. You could write to any files you know are going to be executed or scanned for parameters, like if you have your named.conf in /var/named, or the if httpd.conf is in /var/www somewhere, or any number of other things. Oh, the most blatantly obvious would just be to write to roots crontab. That would just be INSTANT total ownage. Just from one, tiny slip-up any where... httpd would be the most obvious, but perhaps even a malicious mail message could exploit it, depending on what agent is being used to read the mail spool.

Someone should report this junk to BugTraq. That is definitely not software that anyone should be installing.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot set chmod for directory to 777 or 666 q.sa Linux - Software 6 07-19-2005 09:36 AM
Is it safe to chmod 777 Navaboy Slackware 4 03-24-2005 06:54 AM
CHMOD in shell : chmod 777 /usr/ <---is that right? cpanelskindepot Programming 5 07-16-2004 05:37 AM
is it safe to set /var to chmod 777 carlosruiz Linux - Security 5 06-17-2004 05:57 AM
accidently set "chmod -R 777 *".. need help? scorpatron Linux - General 10 12-05-2003 03:12 AM


All times are GMT -5. The time now is 11:28 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration