About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network Security and Hacking
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network Security and Hacking Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such iscompletely LEGAL in the United States -- it's covered by the First Ammendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cellphone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cellphone's number, you could do it like so" is perfectly ok. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
  #1   Add Toraton to your ignore list  
Old 2007-04-03, 22:22
Toraton Toraton is online now
Moderator
 
Des Moines, WA, USA Send a message via AIM to Toraton Send a message via MSN to Toraton Toraton is worth listening to Toraton is worth listening to Toraton is worth listening to Toraton is worth listening to
Default

Hi guys.

I've got a dedicated server running Debian Etch. It's fully up to date and running Apache2. Here's the issue:

I have been providing shell accounts to those who want them, provided that they can assure me they won't do anything malicious. I trust my users. However, I do not trust them to not make mistakes.

The root of the problem is, some users have SSH access and they are immediately dropped into their home directory, /home/username.

I have sensitive sever-side scripts located in /var/www and I cannot allow any users to grab my database passwords. Unfortunately, I cannot rely on permissions alone because they must allow outside users to access the website. Here are my options, as I see them:<UL TYPE=SQUARE>

<LI>Trust my users. Not a chance.

<LI>Maintain two directory trees and chroot the users into the jail with prespecified binaries. Possible, but I want to avoid this.

</UL>

Any and all advice is welcome and if you need more information just let me know.

This is the first box I have administered start to finish, so any tips on making everything play nice would also be welcome. I have set up users/groups like www and svn to control apache and subversion access, respectively.
Reply With Quote
  #2   Add cense to your ignore list  
Old 2007-04-03, 22:30
cense cense is offline
Moderator
 
cense is worth listening to cense is worth listening to cense is worth listening to cense is worth listening to
Default

Quote:
quote:because they must allow outside users to access the website.
Why? If you users have their own little sites to maintain, use apache to put their DocumentRoot inside their home directories and then disallow them any access to /var/www.

[This message has been edited by cense (edited 04-03-2007).]
Reply With Quote
  #3   Add Toraton to your ignore list  
Old 2007-04-03, 22:46
Toraton Toraton is online now
Moderator
 
Des Moines, WA, USA Send a message via AIM to Toraton Send a message via MSN to Toraton Toraton is worth listening to Toraton is worth listening to Toraton is worth listening to Toraton is worth listening to
Default

Quote:
quote:Originally posted by cense:

Why? If you users have their own little sites to maintain, use apache to put their DocumentRoot inside their home directories and then disallow them any access to /var/www.

If I am hosting a website on /var/www, it needs to be world readable in order to display the pages correctly to outside users. Correct me if I am wrong, but I think /var/www needs to be set to 555 at least.

Also, I suppose I may have the option of using setuid and giving apache root, but that scares me for obvious reasons.
Reply With Quote
  #4   Add M0rt to your ignore list  
Old 2007-04-04, 01:46
M0rt M0rt is offline
Regular
 
a fish? Send a message via MSN to M0rt M0rt is an unknown
Default

Usualy you want to place a jail around your webserver dir so that unvelcomed guest doesn't get any further. Trial and error is probably the best advice I can give.

Also long as you set the proper permissions to your configuration files it wouldn't be a problem. Flatfile storage is the same procedure.

Reply With Quote
  #5   Add BiOPSY to your ignore list  
Old 2007-04-04, 03:47
BiOPSY BiOPSY is offline
Moderator
 
Ft. Payne, Alabama BiOPSY is worth listening to BiOPSY is worth listening to BiOPSY is worth listening to BiOPSY is worth listening to
Default

Quote:
quote:Originally posted by Toraton:

If I am hosting a website on /var/www, it needs to be world readable in order to display the pages correctly to outside users. Correct me if I am wrong, but I think /var/www needs to be set to 555 at least.

Untrue. Apache HTTPd under Fedora Core runs as user: apache:x:48:48:Apache:/var/www:/sbin/nologin

User "apache". This means /var/www can be owned by user "apache" and group "apache" then chmod to 500, which will effectively restrict access to any other user and still allow apache to access the directories and files which need displaying.

The reason you believe it needs to be set to 555 I will bet is because your /var/www directory is owned by "root" and group "root". This means if it isn't chmod 555 Apache cannot access these directories because he belongs to "other" when root owns /var/www, simply change the owner and group of /var/www to that of which Apache HTTPd runs under on Debian, and set permissions to 500. This is your solution, using permissions alone.

Quote:
quote:

Also, I suppose I may have the option of using setuid and giving apache root, but that scares me for obvious reasons.
Absolutely no need to do this.
Reply With Quote
  #6   Add jebuonag to your ignore list  
Old 2007-04-04, 04:38
jebuonag jebuonag is online now
Moderator
 
Arizona jebuonag is worth listening to jebuonag is worth listening to jebuonag is worth listening to jebuonag is worth listening to
Default

If you have separate user accounts for every daemon for which it is appropriate, I don't see what the issue is. The solution is simply with discretionary access control.
Reply With Quote
  #7   Add cense to your ignore list  
Old 2007-04-04, 05:39
cense cense is offline
Moderator
 
cense is worth listening to cense is worth listening to cense is worth listening to cense is worth listening to
Default

Quote:
quote:If I am hosting a website on /var/www, it needs to be world readable in order to display the pages correctly to outside users. Correct me if I am wrong, but I think /var/www needs to be set to 555 at least.
I think it's been covered but no, you don't need world readable. You only need the user that the apache daemon is running as to read it. No other account needs to have access.

If you're running your httpd as user www and that user is in group www, for instance, you just chown www.www /var/www -R and chmod o-rwx to prevent anyone not in that group from reading any of that data.
Reply With Quote
  #8   Add BiOPSY to your ignore list  
Old 2007-04-04, 06:48
BiOPSY BiOPSY is offline
Moderator
 
Ft. Payne, Alabama BiOPSY is worth listening to BiOPSY is worth listening to BiOPSY is worth listening to BiOPSY is worth listening to
Default

Quote:
quote:Originally posted by M0rt:

Usualy you want to place a jail around your webserver dir so that unvelcomed guest doesn't get any further.

He was talking about creating a jail and keeping the users in it, not the webserver.
Reply With Quote
  #9   Add Toraton to your ignore list  
Old 2007-04-04, 15:30
Toraton Toraton is online now
Moderator
 
Des Moines, WA, USA Send a message via AIM to Toraton Send a message via MSN to Toraton Toraton is worth listening to Toraton is worth listening to Toraton is worth listening to Toraton is worth listening to
Default Re: Need advice on security options for server.

Thanks guys.

I was having trouble locating the user account for it, but it looks like www-data is the user account for Apache2 on Debian Etch. I've set the access to 770 and added webmasters to group www, so everything looks to be in order.

If I have any more questions, I'll ask them here. Also, does anyone have any tips for running a full server? I've run some servers from home before, but never one that was so loaded with users. I've been reading all that I can and I'm fighting my way through IP tables, but I usually skimp on security because it never really mattered. That's not really an option anymore.
Reply With Quote
  #10   Add BiOPSY to your ignore list  
Old 2007-04-04, 20:11
BiOPSY BiOPSY is offline
Moderator
 
Ft. Payne, Alabama BiOPSY is worth listening to BiOPSY is worth listening to BiOPSY is worth listening to BiOPSY is worth listening to
Default Re: Need advice on security options for server.

Quote:
Originally Posted by Toraton View Post
Thanks guys.

Also, does anyone have any tips for running a full server? I've run some servers from home before, but never one that was so loaded with users. I've been reading all that I can and I'm fighting my way through IP tables, but I usually skimp on security because it never really mattered.
Depends on what exactly you're wanting to accomplish.

For starters, dropping all ICMP requests would make your machine not appear as if it existed, circumventing some script kiddies.
The IP tables rule would look like this:
iptables -A INPUT --source 0.0.0.0/0 --destination <Your interface address> --protocol icmp -j DROP

Hre is the example in action:
Code:
[root@localhost ~]# iptables -A INPUT --source 0.0.0.0/0 --destination 192.168.1.10 --protocol icmp -j DROP

[root@localhost ~]# ping 192.168.1.10

PING 192.168.1.10 (192.168.1.10) 56(84) bytes of data.



--- 192.168.1.10 ping statistics ---

6 packets transmitted, 0 received, 100% packet loss, time 4999ms



[root@localhost ~]#
Other than this, monitoring traffic using netstat will help you locate any strange activity, and if you suspect foul play, simply drop packets from these people or create specific rules to only allow certain types of traffic, then create a rule to drop all data last.
__________________
[autopsy@localhost ~]$ cat you >>/dev/null && rm -rf you
Reply With Quote
This thread continued for 2 pages in the real archive, 19 posts total - only page 1 survived here.
Reply


Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics