# Permissions: r, w, x, chmod आणि chown

Source: https://ravindrabagale.com/mr/cyber/part-02/ch05-linux-basic-commands/5-5-permissions-r-w-x-chmod-and-chown.html
Language: mr (Marathi with English technical terms)

Permission denied किंवा 403 error चं कारण अनेकदा permissions मध्ये असतं; इतर कारणंही असू शकतात. Error मिटवण्यासाठी permissions वाढवण्याआधी कोणत्या user ला कोणता access हवा ते समजून घ्या.

प्रत्येक file ला owner (u), group (g) आणि others (o) असे permission sets असतात. r read, w write आणि x execute/traverse.

 | Permission
 | File वर अर्थ
 | Directory वर अर्थ
 | Value

 | r (read)
 | Content वाचणे
 | Entries ची नावं list करणे (ls)
 | 4

 | w (write)
 | Content बदलणे
 | आत entries तयार/delete (योग्य x permission सोबत)
 | 2

 | x (execute)
 | Program/script म्हणून चालवणे
 | Directory traverse/enter करणे (cd)
 | 1

Directory वर r म्हणजे names list करणे, x म्हणजे traverse/entries access करणे; w सोबत आवश्यक x permission असेल तर entries तयार/delete करता येतात. File delete होणं फक्त त्या file च्या write bit वर ठरत नाही; parent directory permissions महत्त्वाच्या आहेत.

Octal numbers कसे बनतात?

r=4, w=2, x=1. Owner, group आणि others साठी स्वतंत्र बेरीज करा. उदा. 7=4+2+1; 5=4+1; 4=read.

 | Octal
 | Symbolic
 | अर्थ
 | उदाहरण

 | 777
 | rwxrwxrwx
 | सर्वांना read/write/execute
 | सर्वांना write देणं टाळा

 | 755
 | rwxr-xr-x
 | Owner पूर्ण; group/others read+execute/traverse
 | Directories, scripts, web folders

 | 750
 | rwxr-x---
 | Owner पूर्ण; group read+execute/traverse; others काही नाही
 | Private app directories

 | 700
 | rwx------
 | फक्त owner
 | ~/.ssh directory

 | 644
 | rw-r--r--
 | Owner read/write; group/others read
 | Web files (HTML, CSS), configs

 | 640
 | rw-r-----
 | Owner read/write; group read; others नाही
 | Config with passwords (wp-config.php)

 | 600
 | rw-------
 | फक्त owner read/write
 | ~/.​ssh/​authorized_​keys

 | 400
 | r--------
 | फक्त owner read
 | .pem private key

chmod 755 deploy.sh           # numeric
chmod u+x deploy.sh           # symbolic: add execute for user
chmod go-w file.txt           # remove write from group and others
chmod -R 755 /var/www/html    # recursive
chmod 400 mykey.pem           # required before using an SSH key

sudo chown nginx:nginx /usr/share/nginx/html/index.html        # owner:group
sudo chown -R www-data:www-data /var/www/html                   # Ubuntu web user
sudo chown -R apache:apache /var/www/html                       # AL2023/CentOS Apache user

chmod permissions बदलतो; chown owner/group बदलतो. Table मधले users distribution/service नुसार बदलतात. Recursive -R फक्त path आणि परिणाम समजल्यावर वापरा. Source मधलं recursive 755 हे syntax example आहे; प्रत्येक web file executable करण्याची default गरज नाही.

Web files साठी starting pattern

साध्या public static content साठी directories 755, files 644 हा प्रचलित starting pattern आहे; secrets/configs आणि app-write directories साठी गरजेनुसार tighter/different permissions हवेत. खालील दोन commands स्वतंत्रपणे वापरतात:

sudo find /var/www/html -type d -exec chmod 755 {} \;
sudo find /var/www/html -type f -exec chmod 644 {} \;

Owner निवडताना web-server process ला प्रत्येक file बदलण्याचा अधिकार देण्याऐवजी आवश्यक तितकाच write access द्या.

Special permissions

 | Bit
 | Octal
 | Effect
 | Example

 | SUID
 | 4000
 | Program owner च्या effective privileges ने चालतो
 | /usr/bin/passwd (-rwsr-xr-x)

 | SGID
 | 2000
 | Program ला group privileges; directory मध्ये group inheritance
 | Shared project folders

 | Sticky bit
 | 1000
 | Shared directory मधल्या deletion/rename वर owner-based restriction
 | /tmp (drwxrwxrwt)

SUID (4000): executable program owner च्या effective privileges ने चालतो. SGID (2000): executable ला group privileges; directory मध्ये नव्या entries साठी group inheritance. Sticky bit (1000): shared directory मधल्या entries delete/rename करण्यावर owner-based restriction; file owner, directory owner आणि privileged users यांची भूमिका लागू होते. /tmp हे परिचित उदाहरण.

ls -l /usr/bin/passwd                         # note the 's' in rws
find / -perm -4000 -type f 2>/dev/null        # list all SUID programs (a privesc check)
ls -ld /tmp                                   # note the 't' at the end

Security मध्ये उपयोग

अयोग्य SUID-root program, world-writable privileged files, readable private keys आणि अनावश्यक 777 directories हे धोके आहेत. GTFOBins सारख्या references मध्ये permissions चुकीच्या दिल्यावर programs कसे गैरवापरले जाऊ शकतात हे अभ्यासतात. आपल्या server वर least privilege ठेवा.

Practice

rwxr-x---, rw-r--r--, r-------- यांचे octal numbers लिहा. स्वतःच्या lab मध्ये script तयार करून फक्त स्वतःला executable करा. मग दिलेल्या read-only find command ने SUID files ची list पाहा.
Octal उत्तरं
750, 644 आणि 400.

रवींद्र बागले यांची tip

Error आला की chmod -R 777 करू नका. ls -l आणि directory permissions पाहा. Process कोणत्या user ने चालतो ते तपासा आणि त्या कामापुरताच access द्या.
