UID,GID,粘滯位,setattr,lsattr

來源:互聯網
上載者:User

標籤:control   linux   access   模型   file   

我們有的時候有這樣的需要,允許一人使用者查看修改其它使用者的檔案,但不允許刪除。用一個普通使用者執行一個命令,但這個命令的運行身份是root。因為linux系統使用權限設定過於簡單,像做這些事情就需要用到facl了。facl是file access control list的縮寫。

當一個使用者訪問一個檔案時,檔案許可權匹配模型是這樣的工作順序:檢查使用者是否為檔案的屬主,如果是則按屬主的許可權來看讀寫執行許可權。如果不是則檢查使用者是否為此檔案的所屬組的成員,如果是則按屬組的許可權。如果不是則都其它使用者權限來給定。

SUID

一般情況下當我們以一個普通使用者運行一個程式時,這個程式的發起者是使用者本身,而這個程式是使用者的代理。但如果給一個程式指定了SUID時,其它使用者再運行這個程式則是以這個程式的所有者運行,passwd命令就是這樣啟動並執行,前提是程式的屬主需要有執行許可權。

chmod u+s [檔案名稱] 用來給可執行檔程式加上SUID位,然後用ls -l 查看這個檔案,執行許可權位顯示為小s或大S。小s表示屬主有執行的許可權,大S表示屬主沒有執行許可權。

650) this.width=650;" title="clipboard" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424350qzsG.png" width="244" height="85" />

用途,/etc/shadow這個檔案普通使用者使用cat命令無法查看,以root身份把cat這個程式加上SUID然後普通使用者再執行cat /etc/shadow時就可以查看到檔案的內容。

使用者普通使用者執行cat /etc/shadow

650) this.width=650;" title="clipboard[1]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[1]" src="http://img1.51cto.com/attachment/201408/7/1080241_14074243516I1L.png" width="244" height="46" />

把cat程式拷貝到/wukui/test下並加上SUID後

#cp `which cat` /wukui/test/

#chmod u+s /wukui/test/cat

650) this.width=650;" title="clipboard[2]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[2]" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424351EO58.png" width="244" height="28" />

#su - wukui

#/tmp/test/cat /wukui/shadow

650) this.width=650;" title="clipboard[3]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[3]" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424351xaro.png" width="244" height="57" />

SGID

如果我們想給系統的一個使用者對某個檔案有寫的許可權,又不想給其它使用者寫入權限,還不想把這個使用者加入到我們這個組裡,這時候就用到SUID了。SUID一般用在給目錄設定。

比如/wukui/test這個目錄裡普通使用者可以修改此目錄裡的檔案內容,但不動這個目錄的other許可權。做法如下

#mkdir /wukui/test  建立目錄

#groupadd fileshare 建立組

#chown :fileshare /wukui/test  修改此目錄的所屬組

#chmod g+s /wukui/test  給此目錄添加SGID

#usermod -G fileshare user1  把user1加入到fileshare組

經過以上的操作,此目錄裡的檔案other沒有寫的許可權,user1使用者也可以修改了。

ls -ld /wukui/test

650) this.width=650;" title="clipboard[4]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[4]" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424351qyGq.png" width="244" height="66" />

sticky :沾滯位

    這個一般給目錄用,如果想讓user1使用者修改user2的檔案,又不想讓user2刪除user1的檔案,每個使用者只能刪除自己的檔案。這裡就需要乃至粘滯位了。

使用格式 :chmod o+s <目錄名>

chmod o+s /wukui/test 這樣/wukui/test這個目錄裡所有普通使用者只能刪除自己的檔案,而不能刪除它人的檔案。

650) this.width=650;" title="clipboard[5]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[5]" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424351DEd0.png" width="244" height="61" />

facl

通過facl普通使用者可以透過檔案的擴充屬性,單獨向其它使用者或組設定額外的訪問機制,而不需要改other許可權來實現。啟用facl之後的許可權應用優先順序,屬主-使用者層級的facl-屬組-組層級的facl-其它使用者

getfacl 顯示 facl

            getfacl filename

650) this.width=650;" title="clipboard[6]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[6]" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424351DVZA.png" width="244" height="91" />

setfacl 修改 facl

使用格式:setfacl {-m|-x} [使用者或組]:MODE FILE

  -m 添加許可權

setfacl -m u:wukui:rwx wukui.txt
getfacl wukui.txt
650) this.width=650;" title="clipboard[7]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[7]" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424352GIqU.png" width="244" height="106" />

  -x  刪除許可權

  setfacl -x u:wukui wukui.txt

  getfacl wukui.txt

650) this.width=650;" title="clipboard[8]" style="border-left- 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px" border="0" alt="clipboard[8]" src="http://img1.51cto.com/attachment/201408/7/1080241_1407424352pNBw.png" width="244" height="185" />

  -x u:USERNAME

  -R 遞迴修改。僅對已有的檔案生效。

setfacl -m u:wukui:rwx a.txt 添加使用者可以訪問格式

setfacl -m g:wukui:rw a.txt 添加組可以訪問格式

chattr

lsattr

+ :在原有參數設定基礎上,追加參數。
- :在原有參數設定基礎上,移除參數。
= :更新為指定參數設定。
A:檔案或目錄的 atime (access time)不可被修改(modified), 可以有效預防例如手提電腦磁碟I/O錯誤的發生。
S:硬碟I/O同步選項,功能類似sync。
a:即append,設定該參數後,只能向檔案中添加資料,而不能刪除,多用於伺服器日誌文 件安全,只有root才能設定這個屬性。
c:即compresse,設定檔案是否經壓縮後再儲存。讀取時需要經過自動解壓操作。
d:即no dump,設定檔案不能成為dump程式的備份目標。
i:設定檔案不能被刪除、改名、設定連結關係,同時不能寫入或新增內容。i參數對於檔案 系統的安全設定有很大協助。
j:即journal,設定此參數使得當通過mount參數:data=ordered 或者 data=writeback 掛 載的檔案系統,檔案在寫入時會先被記錄(在journal中)。如果filesystem被設定參數為 data=journal,則該參數自動失效。
s:保密性地刪除檔案或目錄,即硬碟空間被全部收回。
u:與s相反,當設定為u時,資料內容其實還存在磁碟中,可以用於undeletion.
各參數選項中常用到的是a和i。a選項強制只可添加不可刪除,多用於日誌系統的安全設定。而i是更為嚴格的安全設定,只有superuser (root) 或具有CAP_LINUX_IMMUTABLE處理能力(標識)的進程能夠施加該選項。

chattr +i /etc/passwd

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.