Cyber Security · मराठी आवृत्ती
Permissions: r, w, x, chmod आणि chown
या page मध्ये
Permission denied किंवा 403 error चं कारण अनेकदा permissions मध्ये असतं; इतर कारणंही असू शकतात. Error मिटवण्यासाठी permissions वाढवण्याआधी कोणत्या user ला कोणता access हवा ते समजून घ्या.
प्रत्येक file ला owner (u), group (g) आणि others (o) असे permission sets असतात. r read, w write आणि x execute/traverse.
| Permission | File वर अर्थ | Directory वर अर्थ | Value |
|---|---|---|---|
| r (read) | Content वाचणे | Entries ची नावं list करणे (ls) | 4 |
| w (write) | Content बदलणे | आत entries तयार/delete (योग्य x permission सोबत) | 2 |
| x (execute) | Program/script म्हणून चालवणे | Directory traverse/enter करणे (cd) | 1 |
Directory वर r म्हणजे names list करणे, x म्हणजे traverse/entries access करणे; w सोबत आवश्यक x permission असेल तर entries तयार/delete करता येतात. File delete होणं फक्त त्या file च्या write bit वर ठरत नाही; parent directory permissions महत्त्वाच्या आहेत.
Octal numbers कसे बनतात?
r=4, w=2, x=1. Owner, group आणि others साठी स्वतंत्र बेरीज करा. उदा. 7=4+2+1; 5=4+1; 4=read.
| Octal | Symbolic | अर्थ | उदाहरण |
|---|---|---|---|
| 777 | rwxrwxrwx |
सर्वांना read/write/execute | सर्वांना write देणं टाळा |
| 755 | rwxr-xr-x |
Owner पूर्ण; group/others read+execute/traverse | Directories, scripts, web folders |
| 750 | rwxr-x--- |
Owner पूर्ण; group read+execute/traverse; others काही नाही | Private app directories |
| 700 | rwx------ |
फक्त owner | ~/.ssh directory |
| 644 | rw-r--r-- |
Owner read/write; group/others read | Web files (HTML, CSS), configs |
| 640 | rw-r----- |
Owner read/write; group read; others नाही | Config with passwords (wp-config.php) |
| 600 | rw------- |
फक्त owner read/write | ~/.ssh/authorized_keys |
| 400 | r-------- |
फक्त owner read | .pem private key |
chmod 755 deploy.sh # numeric
chmod u+x deploy.sh # symbolic: add execute for user
chmod go-w file.txt # remove write from group and others
chmod -R 755 /var/www/html # recursive
chmod 400 mykey.pem # required before using an SSH key
sudo chown nginx:nginx /usr/share/nginx/html/index.html # owner:group
sudo chown -R www-data:www-data /var/www/html # Ubuntu web user
sudo chown -R apache:apache /var/www/html # AL2023/CentOS Apache user
chmod permissions बदलतो; chown owner/group बदलतो. Table मधले users distribution/service नुसार बदलतात. Recursive -R फक्त path आणि परिणाम समजल्यावर वापरा. Source मधलं recursive 755 हे syntax example आहे; प्रत्येक web file executable करण्याची default गरज नाही.
Web files साठी starting pattern
साध्या public static content साठी directories 755, files 644 हा प्रचलित starting pattern आहे; secrets/configs आणि app-write directories साठी गरजेनुसार tighter/different permissions हवेत. खालील दोन commands स्वतंत्रपणे वापरतात:
sudo find /var/www/html -type d -exec chmod 755 {} \;
sudo find /var/www/html -type f -exec chmod 644 {} \;Owner निवडताना web-server process ला प्रत्येक file बदलण्याचा अधिकार देण्याऐवजी आवश्यक तितकाच write access द्या.
Special permissions
| Bit | Octal | Effect | Example |
|---|---|---|---|
| SUID | 4000 | Program owner च्या effective privileges ने चालतो | /usr/bin/passwd (-rwsr-xr-x) |
| SGID | 2000 | Program ला group privileges; directory मध्ये group inheritance | Shared project folders |
| Sticky bit | 1000 | Shared directory मधल्या deletion/rename वर owner-based restriction | /tmp (drwxrwxrwt) |
SUID (4000): executable program owner च्या effective privileges ने चालतो. SGID (2000): executable ला group privileges; directory मध्ये नव्या entries साठी group inheritance. Sticky bit (1000): shared directory मधल्या entries delete/rename करण्यावर owner-based restriction; file owner, directory owner आणि privileged users यांची भूमिका लागू होते. /tmp हे परिचित उदाहरण.
ls -l /usr/bin/passwd # note the 's' in rws
find / -perm -4000 -type f 2>/dev/null # list all SUID programs (a privesc check)
ls -ld /tmp # note the 't' at the end
Security मध्ये उपयोग
अयोग्य SUID-root program, world-writable privileged files, readable private keys आणि अनावश्यक 777 directories हे धोके आहेत. GTFOBins सारख्या references मध्ये permissions चुकीच्या दिल्यावर programs कसे गैरवापरले जाऊ शकतात हे अभ्यासतात. आपल्या server वर least privilege ठेवा.
Practice
rwxr-x---, rw-r--r--, r-------- यांचे octal numbers लिहा. स्वतःच्या lab मध्ये script तयार करून फक्त स्वतःला executable करा. मग दिलेल्या read-only find command ने SUID files ची list पाहा.
Octal उत्तरं
750, 644 आणि 400.