HP3000-L Archives

February 2000, Week 2

HP3000-L@RAVEN.UTC.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Andreas Schmidt <[log in to unmask]>
Reply To:
Date:
Thu, 10 Feb 2000 10:30:43 +0100
Content-Type:
text/plain
Parts/Attachments:
text/plain (56 lines)
Check the accounts' and groups' security!

I assume that all accounts are widely opened.
To check this you may use the ls -als command in posix - this will show you the
security setting as Unix based services will interpret the MPE settings.

Best regards, Andreas Schmidt, CSC, Germany




[log in to unmask] on 10/02/2000 09:52:31 AM

Please respond to [log in to unmask]

To:   [log in to unmask]
cc:    (bcc: Andreas Schmidt/GIS/CSC)
Subject:  Big security problem ...



Hi all,

Could somebody help me to resolve a big security problem ?

I've users using ftp to put files on my system.
I've created the following directories:

/BOULAN/AC/in
/BOULAN/AC/in/ack
/BOULAN/AC/out
...
In mpe, BOULAN is an account and AC is a group, the rest are HFS
directories.

The user is connecting in accout BOULAN with homegroup AC.
At this moment, the user can traverse the HFS directories to put his files.

Recently, all my files in account BOULAN disapeared, except databases and
open files.
The reaon was a delete from this connected user.
I saw that this user can traverse the parent directories with 'cd ..' and
even go to other accounts.

I tried to resolved this issue with ACD's, but they are not allowed on group
and accounts.

Can anybody help me to prevent the user to go to the parent directories, or
to map /BOULAN/AC
as a root directory ?

Thank You.

Beghein Johan.
[log in to unmask]

ATOM RSS1 RSS2