Page 125 - slides.dvi
P. 125

•
                                                                               •
              •
                                                                        •
                                                                 •
   Unix
                                    –
                                              –
                                                    –
                                                          In
   Case
                          ⇒
                               ⇒
                     ⇒
                                                                        Three
                                                                                                               Access
                                    e.g.
                          it
                                                                               Access
                     but
   Study—
                               any
                                                                        bits
                                                                 Question:
                          can
              Question:
                                                          addition
                                                    normally
   Files
                                         particular
                                    prof
                               user
                                                                        for
   and
                     users
                                                                               control
              and
                                              setuid/setgid
   the
                                                          have
                                                                                                               Control
                                                                 What
                               can
                                    owns
                          update
                                                                        each
                     can’t
                                                                 do
                                                                                                   R
              what
                                                    processes
                                              allow
                               run
                                         program.
                                                                        of
   Filesystem
                                                                                                   W
                                                          setuid
                                    both
              do
                                                                                                   E
                                                                                                       Owner
                               it.
                          score
                                              the
                                                                 these
                                                                                                   R
                     cheat.
                                                                               information
                                                          and
                                                    inherit
                                                                                                   W
                                                                        owner,
                          file.
                                                                                                       Group
              these
                                              user
                                                                                                   E
                                                                               held
                                                                                                   R
                                                                 mean
                                              to
                                                          setgid
                                                                               in
                                                                                                   W
                                    executable
                                                                        group
                                                                                       = 0640
                                                                 for
                                                                                                       World
                                                                                                   E
              mean
                                                          bits:
                                                                               each
              for
                                                                        and
                                    test
                                                    permissions
                                                    of
                                              “become”
                                                                                                   R
                                                                                                   W
                                                                               inode.
                                                                        world:
                                    (0711
                                                                                                       Owner
                                                                                                   E
                                                                 directories?
                                                                        {
                                                                                                   R
                                    and
              directories?
                                                                                                   W
                                                    invoking
                                              someone
                                                                                                       Group
                                                                                                   E
                                                                        read,
                                                                                                   R
                                              else
                                                    user.
                                                                                                   W
                                                                                       = 0755
                                                                                                       World
                                                                                                   E
                                    setuid),
                                                                        write
                                              when
                                    and
                                                                        and
                                    score
                                              running
                                                                        execute
                                              a
                                    file
                                                                        }
   121
                                    (0600)
   120   121   122   123   124   125   126   127   128   129   130