home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!cis.ohio-state.edu!ucbvax!mhs.attmail.com!simons/G=Colin/I=CB/S=Sewell/O=H.A.Simons.Ltd/OU=CORP
- From: simons/G=Colin/I=CB/S=Sewell/O=H.A.Simons.Ltd/OU=CORP@mhs.attmail.com
- Newsgroups: comp.os.vms
- Subject: Re: HELP!!! Security problem for gurus.
- Message-ID: <9212211720.AA15326@ucbvax.Berkeley.EDU>
- Date: 21 Dec 92 15:48:43 GMT
- Sender: daemon@ucbvax.BERKELEY.EDU
- Distribution: world
- Organization: The Internet
- Lines: 43
-
- |B. Bochnik writes:
- |
- |In article <1992Dec16.114913.1@ttd.teradyne.com> rice@ttd.teradyne.com writes:
- |>
- |> In article <B1FB21FFA27F004AEF@imimnvx.irfmn.mnegri.it>, PSI%ITAPAC.22800002::PITCLS::ADRIANO@imimnvx.irfmn.mnegri.it (Adriano Santoni) writes:
- |>>
- |>> Hi netters!
- |>>
- |>> I need to avoid certain people to scan a directory of mine. This
- |>> could seem a very trivial issue, if it was not for the following:
- |>>
- |>> o Some users of mine have (and need to retain) *ALL* privileges
- |>>
- |>> o I don't want to clear the DIRECTORY file characteristic bit
- |>>
- |>> o I don't want to do encrypting or any other tricky thing
- |>>
- |>> o I want to be able to access my directory whenever I need to
- |>>
- |>> In other words: do you know of a feasible method of protecting
- |>> private areas without resorting to the traditional & documented
- |>> practics? Impossible? That's what I fear! Sigh!
- |>>
- |>
- |>Have you heard of ACLs (Access Control Lists) ? An access control list can
- |>protect directories as well as files.
- |>
- |> John Rice K9IJ | "Did I say that ?" I must have, but It was
- |> | MY opinion only, no one else's...Especially
- |> | Not my Employer's....
- |> rice@ttd.teradyne.com | Purveyor of Miracles,Magic and Sleight-of-hand
- |
- |
- |Please re-read the original post. ACL's will NOT protect you from users with
- |all privs (BYPASS for one comes to mind)
-
-
- Yup, ACL's won't protect you. Another priv that can get around ACL's
- is one that is given to operators and special backup accounts so they can read
- all files on a disk for backup purposes: READALL priv. What most of the people
- around here didn't know was that this priv also grants you implicit write access
- to all files!
-
-