Cheatography
https://cheatography.com
A simple checklist for Linux permission when performing hardening.
Ownership & Permissions
Command |
Purpose |
|
View permissions |
|
Detailed file info |
|
Change permissions |
|
Change owner |
|
Change group |
|
View default permissions |
|
Set default permissions |
Common Permission Values
600 |
Owner RW |
644 |
Owner RW, Others R |
700 |
Owner RWX |
755 |
Owner RWX, Others RX |
777 |
Everyone RWX (Avoid) |
|
|
ACL (Access Control Lists)
Command |
Purpose |
|
View ACL |
setfacl -m u:USER:rwx FILE
|
Add ACL |
|
Remove ACL |
|
Remove all ACLs |
Attributes
Command |
Purpose |
|
View attributes |
|
Immutable |
|
Remove immutable |
|
Append only |
Reference Box
r = Read
w = Write
x = Execute
4 = Read
2 = Write
1 = Execute
------------------------
SUID = Run as Owner
SGID = Run as Group
Sticky = Only Owner Can Delete |
|
|
SUID / SGID
Command |
Purpose |
|
Find SUID files |
|
Find SGID files |
|
Remove SUID |
|
Remove SGID |
Sticky Bit
Command |
Purpose |
|
Set Sticky Bit |
|
Remove Sticky Bit |
Security Checklist
Least Privilege
Avoid chmod 777
Secure ~/.ssh (700)
Secure private keys (600)
Protect /etc/shadow
Audit SUID files
Review ownership |
|
Created By
Metadata
Comments
No comments yet. Add yours below!
Add a Comment
Related Cheat Sheets
More Cheat Sheets by hlhlhl