LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 10-03-2006, 03:36 PM   #1
ygloo
Member
 
Registered: Aug 2006
Distribution: slack
Posts: 323

Rep: Reputation: 30
unknown files in /tmp


i found three gif images pointing to www.tempelton.com
with adds to buy viagra...
i'm pretty sure i never visited that site...
i wonder how these files ended in /tmp??
it is world writeble (drwxrwxrwt)
so anyone can copy whatever they want to /tmp!?

Last edited by ygloo; 10-03-2006 at 03:43 PM.
 
Old 10-03-2006, 03:40 PM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
/tmp is designed for temporary storage by all applications. To write anything they want they have to get to your box. It may be you hit another site or opened an email that had these files as attachments. Since they're in /tmp its safe to delete them.
 
Old 10-03-2006, 03:44 PM   #3
ygloo
Member
 
Registered: Aug 2006
Distribution: slack
Posts: 323

Original Poster
Rep: Reputation: 30
files from internet should be store in browser cache?
... i never saw image files in /tmp before...

Last edited by ygloo; 10-03-2006 at 03:46 PM.
 
Old 10-03-2006, 03:58 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
so anyone can copy whatever they want to /tmp!?
That's what /tmp is for. If you don't run SELinux or GRSecurity I suggest you:
- at least mount your temporary partitions (if they are partitions) with the "noexec,nosuid,nodev" flags (note you'll have to test noexec and nodev as it may break some applications),
- use a tmpwatch cronjob to clean up /tmp and
- if you run publicly accessable services use a tool to monitor system (and temporary) directories for files with changing and unexpected permissions like setuid root ones.


... i never saw image files in /tmp before...
What's the date they where put there and who owns them?
 
Old 10-03-2006, 04:10 PM   #5
ygloo
Member
 
Registered: Aug 2006
Distribution: slack
Posts: 323

Original Poster
Rep: Reputation: 30
i have "/" and "/home" partitions...
didn't check files... too hurry to delete them
what will happen when i set this to /tmp - drwxrwxr-t
 
Old 10-03-2006, 04:33 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Then users who are not part of the owner or group the directory is owned by will not be able to write to it (that includes your unprivileged user account).
 
Old 10-03-2006, 04:40 PM   #7
ygloo
Member
 
Registered: Aug 2006
Distribution: slack
Posts: 323

Original Poster
Rep: Reputation: 30
if i change permissions like this:
drwxrwx--t 6 root "usergroup" 4096 2006-10-03 23:28 tmp

root and "usergroup" users have accsess...
sticky bit valid for "usergroup" users??
will system run properly??

Last edited by ygloo; 10-03-2006 at 05:16 PM.
 
Old 10-03-2006, 05:15 PM   #8
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Since you're bent on experimenting, why don't you just try?
I mean it's not destructive or irreversible.
Just reboot and see.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
what to do with files in /tmp Valkyrie_of_valhalla Linux - General 17 09-13-2006 03:44 PM
getting files deleted on /tmp ines Linux - General 13 01-28-2005 03:35 AM
/tmp files Risc91 AIX 4 01-18-2005 02:06 PM
Numerous scb_*.tmp files in /tmp dburk Programming 3 08-18-2003 04:28 PM
removing files in /tmp sakeeb Linux - General 4 06-09-2002 12:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 09:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration