Ravindra Bagale · Cyber Securityसर्व coursesया course चे lessonsशोधाEnglish

Cyber Security · मराठी आवृत्ती

Permissions: r, w, x, chmod आणि chown

रवींद्र बागले यांच्या course वर आधारित · सहज मराठीत explanation

या page मध्ये

Permission denied किंवा 403 error चं कारण अनेकदा permissions मध्ये असतं; इतर कारणंही असू शकतात. Error मिटवण्यासाठी permissions वाढवण्याआधी कोणत्या user ला कोणता access हवा ते समजून घ्या.

प्रत्येक file ला owner (u), group (g) आणि others (o) असे permission sets असतात. r read, w write आणि x execute/traverse.

Permission File वर अर्थ Directory वर अर्थ Value
r (read) Content वाचणे Entries ची नावं list करणे (ls) 4
w (write) Content बदलणे आत entries तयार/delete (योग्य x permission सोबत) 2
x (execute) Program/script म्हणून चालवणे Directory traverse/enter करणे (cd) 1

Directory वर r म्हणजे names list करणे, x म्हणजे traverse/entries access करणे; w सोबत आवश्यक x permission असेल तर entries तयार/delete करता येतात. File delete होणं फक्त त्या file च्या write bit वर ठरत नाही; parent directory permissions महत्त्वाच्या आहेत.

Octal numbers कसे बनतात?

r=4, w=2, x=1. Owner, group आणि others साठी स्वतंत्र बेरीज करा. उदा. 7=4+2+1; 5=4+1; 4=read.

Octal Symbolic अर्थ उदाहरण
777 rwxrwxrwx सर्वांना read/write/execute सर्वांना write देणं टाळा
755 rwxr-xr-x Owner पूर्ण; group/others read+execute/traverse Directories, scripts, web folders
750 rwxr-x--- Owner पूर्ण; group read+execute/traverse; others काही नाही Private app directories
700 rwx------ फक्त owner ~/.ssh directory
644 rw-r--r-- Owner read/write; group/others read Web files (HTML, CSS), configs
640 rw-r----- Owner read/write; group read; others नाही Config with passwords (wp-config.php)
600 rw------- फक्त owner read/write ~/.​ssh/​authorized_​keys
400 r-------- फक्त owner read .pem private key
chmod 755 deploy.sh           # numeric
chmod u+x deploy.sh           # symbolic: add execute for user
chmod go-w file.txt           # remove write from group and others
chmod -R 755 /var/www/html    # recursive
chmod 400 mykey.pem           # required before using an SSH key

sudo chown nginx:nginx /usr/share/nginx/html/index.html        # owner:group
sudo chown -R www-data:www-data /var/www/html                   # Ubuntu web user
sudo chown -R apache:apache /var/www/html                       # AL2023/CentOS Apache user

chmod permissions बदलतो; chown owner/group बदलतो. Table मधले users distribution/service नुसार बदलतात. Recursive -R फक्त path आणि परिणाम समजल्यावर वापरा. Source मधलं recursive 755 हे syntax example आहे; प्रत्येक web file executable करण्याची default गरज नाही.

Web files साठी starting pattern

साध्या public static content साठी directories 755, files 644 हा प्रचलित starting pattern आहे; secrets/configs आणि app-write directories साठी गरजेनुसार tighter/different permissions हवेत. खालील दोन commands स्वतंत्रपणे वापरतात:

sudo find /var/www/html -type d -exec chmod 755 {} \;
sudo find /var/www/html -type f -exec chmod 644 {} \;

Owner निवडताना web-server process ला प्रत्येक file बदलण्याचा अधिकार देण्याऐवजी आवश्यक तितकाच write access द्या.

Special permissions

Bit Octal Effect Example
SUID 4000 Program owner च्या effective privileges ने चालतो /usr/bin/passwd (-rwsr-xr-x)
SGID 2000 Program ला group privileges; directory मध्ये group inheritance Shared project folders
Sticky bit 1000 Shared directory मधल्या deletion/rename वर owner-based restriction /tmp (drwxrwxrwt)

SUID (4000): executable program owner च्या effective privileges ने चालतो. SGID (2000): executable ला group privileges; directory मध्ये नव्या entries साठी group inheritance. Sticky bit (1000): shared directory मधल्या entries delete/rename करण्यावर owner-based restriction; file owner, directory owner आणि privileged users यांची भूमिका लागू होते. /tmp हे परिचित उदाहरण.

ls -l /usr/bin/passwd                         # note the 's' in rws
find / -perm -4000 -type f 2>/dev/null        # list all SUID programs (a privesc check)
ls -ld /tmp                                   # note the 't' at the end

Security मध्ये उपयोग

अयोग्य SUID-root program, world-writable privileged files, readable private keys आणि अनावश्यक 777 directories हे धोके आहेत. GTFOBins सारख्या references मध्ये permissions चुकीच्या दिल्यावर programs कसे गैरवापरले जाऊ शकतात हे अभ्यासतात. आपल्या server वर least privilege ठेवा.

Practice

rwxr-x---, rw-r--r--, r-------- यांचे octal numbers लिहा. स्वतःच्या lab मध्ये script तयार करून फक्त स्वतःला executable करा. मग दिलेल्या read-only find command ने SUID files ची list पाहा.

Octal उत्तरं

750, 644 आणि 400.