LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 04-15-2004, 10:29 AM   #1
connman
LQ Newbie
 
Registered: Apr 2004
Location: connecticut
Distribution: debian
Posts: 2

Rep: Reputation: 0
Question sgid/directory security


All:

I'm using debian/apache-ssl and want to set the sgid bit on the directory containing web files so that our webdev group has ownership of all files created there. Are there security risks associated with this move?

Also, how do I set recursive write permissions on those files for the webdev group?

Many TIA's...
 
Old 04-15-2004, 11:35 AM   #2
druuna
LQ Veteran
 
Registered: Sep 2003
Posts: 10,532
Blog Entries: 7

Rep: Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371Reputation: 2371
Not the sort of security risk you had in mind, but developers having access to production files is asking for unplanned downtime

Even if you are the only person on that box you should seperate your online stuff from test/develop environments. Typo's can potentionaly whipe out all those hours of work.........

About sgid: If you feed your fav searchengine with sgid and linux you will get plenty of hits. Here are just 2:
http://www.linuxgazette.com/node/view/2759
http://linux.about.com/cs/linux101/g..._set_group.htm

Hope this helps.
 
Old 04-15-2004, 11:42 AM   #3
connman
LQ Newbie
 
Registered: Apr 2004
Location: connecticut
Distribution: debian
Posts: 2

Original Poster
Rep: Reputation: 0
Thanks druuna--the machine in question is in fact a test/dev server and saw both of those articles--but never hurts to corroborate!!
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
RedHat Enterprise 3 directory security from Windows Fillys6 Linux - Networking 3 06-03-2005 08:08 AM
Help! Setting SGID on directory skilian Linux - General 1 09-06-2004 04:57 AM
apache directory security steve_babbage Linux - Security 1 02-20-2004 01:15 PM
Directory security issue malcie Linux - Newbie 4 07-18-2003 07:10 AM
Apache directory security cli_man Linux - Security 2 10-14-2002 05:40 PM


All times are GMT -5. The time now is 05:12 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration