Show Menu
Cheatography

Linux Permissions (Hardening) Cheat Sheet by

A simple checklist for Linux permission when performing hardening.

Ownership & Permis­sions

Command
Purpose
ls -l
View permis­sions
stat FILE
Detailed file info
chmod MODE FILE
Change permis­sions
chown USER FILE
Change owner
chgrp GROUP FILE
Change group
umask
View default permis­sions
umask 022
Set default permis­sions

Common Permission Values

600
Owner RW
644
Owner RW, Others R
700
Owner RWX
755
Owner RWX, Others RX
777
Everyone RWX (Avoid)
 

ACL (Access Control Lists)

Command
Purpose
getfacl FILE
View ACL
setfacl -m u:USER:rwx FILE
Add ACL
setfacl -x u:USER FILE
Remove ACL
setfacl -b FILE
Remove all ACLs

Attributes

Command
Purpose
lsattr
View attributes
chattr +i FILE
Immutable
chattr -i FILE
Remove immutable
chattr +a FILE
Append only

Reference Box

r = Read
w = Write
x = Execute

4 = Read
2 = Write
1 = Execute

------­---­---­---­---­------

SUID = Run as Owner
SGID = Run as Group
Sticky = Only Owner Can Delete
 

SUID / SGID

Command
Purpose
find / -perm -4000
Find SUID files
find / -perm -2000
Find SGID files
chmod u-s FILE
Remove SUID
chmod g-s FILE
Remove SGID

Sticky Bit

Command
Purpose
chmod +t DIR
Set Sticky Bit
chmod -t DIR
Remove Sticky Bit

Security Checklist

Least Privilege
Avoid chmod 777
Secure ~/.ssh (700)
Secure private keys (600)
Protect /etc/s­hadow
Audit SUID files
Review ownership
 

Comments

No comments yet. Add yours below!

Add a Comment

Your Comment

Please enter your name.

    Please enter your email address

      Please enter your Comment.

          Related Cheat Sheets

          Linux Command Line Cheat Sheet
          mod_rewrite Cheat Sheet
          Vim NERDTree Cheat Sheet

          More Cheat Sheets by hlhlhl

          Linux File and Directory Commands Cheat Sheet
          Managing Processes and Jobs in Linux Cheat Sheet
           
          Advertisement