- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- World writable files after default HP-UX 11.11 ins...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2003 02:24 AM
01-30-2003 02:24 AM
World writable files after default HP-UX 11.11 install
Is there any OS files that needs (really mandatory!) to be world writable in the unix system after a "default" installation?
This is a security-related question. Indeed, if some files NEEDS to be world writable then how to prevent any user to modify this/these file(s) and impact the system.
Thanks in advance for your help,
Regards,
Nicolas
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2003 02:38 AM
01-30-2003 02:38 AM
Re: World writable files after default HP-UX 11.11 install
Certainly one thing you can/should tighten immediately is the ability for anyone to delete files from the '/tmp', '/var/tmp', and 'usr/local' directories regardless of whether or not they are the owner.
To correct this, set the sticky bit on the directory. This will prevent a file's non-owner from deleting it, while allowing anyone write access to the directory and the ability for the file's owner to delete.
By example:
# chmod 1777 /tmp
Regards!
...JRF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2003 03:01 AM
01-30-2003 03:01 AM
Re: World writable files after default HP-UX 11.11 install
Will do that.
Rgds,
Nicolas
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2003 05:14 AM
01-30-2003 05:14 AM
Re: World writable files after default HP-UX 11.11 install
you might want to read http://people.hp.se/stevesk/bastion11.html,
which explains how to "build a bastion host using HP-UX 11", and especially its chapter 9: "file permissions".
Basically, what they do is remove write permissions systemwide, then:
# chmod 1777 /tmp /var/tmp /var/preserve
# chmod 666 /dev/null
Notice the use of the sticky bit for the public directories...
Cheers,
FiX
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2003 05:43 AM
01-30-2003 05:43 AM
Re: World writable files after default HP-UX 11.11 install
It lets you know what's world writeable and really should not be. security_patch_check also does a cursory analysis.
Here are links.
Bastille
https://payment.ecommerce.hp.com/cgi-bin/swdepot_parser.cgi/cgi/try.pl?productNumber=B6849AA&date=
security_patch_check
https://payment.ecommerce.hp.com/cgi-bin/swdepot_parser.cgi/cgi/try.pl?productNumber=B6834AA&date=
If you are really into security you should consider running crack against your password file in a test environment(ftp it in) and the saint system probe utility.
This toolset will really help you lock things down.
P
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-30-2003 10:58 AM
01-30-2003 10:58 AM
Re: World writable files after default HP-UX 11.11 install
Additionally, all standard HP-UX installs have bad permissions on /usr/local directories. Warnings to this effect are contained in several places but the default install still leaves /usr/local directories as 777. They MUST be changed to 755 on every machine.
If you install any of the OpenView products such as node manager, then there will be a massive number of wide open directories and files in places like /etc...these will have to be fixed to prevent problems in the future.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-12-2003 08:23 PM
02-12-2003 08:23 PM
Re: World writable files after default HP-UX 11.11 install
Well thanks a lot to all of you who have responded to my question. I really appreciate your support.
Each information that you have provided has been very useful to me (ie. doc "build a bastion host using HP-UX 11", Security_patch_Check and Bastille, etc..)
No doubt it could certainly help other people as well.
This is really a great forum and community.
Regards,
Nicolas