From 68ebfc5fc46591d84ed1b0887c1c0b19ba7aa47d Mon Sep 17 00:00:00 2001 From: Frederic Lepied Date: Thu, 17 Jan 2002 19:56:19 +0000 Subject: 0.17 --- conf/perm.snf | 38 ++++++++++++++++++-------------------- 1 file changed, 18 insertions(+), 20 deletions(-) (limited to 'conf/perm.snf') diff --git a/conf/perm.snf b/conf/perm.snf index 33bc189..3b12650 100644 --- a/conf/perm.snf +++ b/conf/perm.snf @@ -1,11 +1,10 @@ # Welcome in Level 4, aka secure & usable. ### +/ root.adm 751 /bin/ root.root 711 /bin/rpm rpm.rpm 750 /boot/ root.root 700 /dev/ root.root 711 -/dev/audio* root.audio 600 -/dev/dsp* root.audio 600 /etc/ root.adm 711 /etc/conf.modules root.adm 640 /etc/cron.daily/ root.adm 750 @@ -15,7 +14,6 @@ /etc/crontab root.adm 640 /etc/dhcpcd/ root.adm 750 /etc/dhcpcd/* root.adm 640 -/etc/esd.conf root.audio 640 /etc/ftpaccess root.adm 640 /etc/ftpconversions root.adm 640 /etc/ftpgroups root.adm 640 @@ -26,29 +24,31 @@ /etc/hosts.deny root.adm 640 /etc/hosts.equiv root.adm 640 /etc/inetd.conf root.adm 640 -/etc/rc.d/init.d/ root.adm 750 -/etc/rc.d/init.d/syslog root.adm 740 /etc/inittab root.adm 640 /etc/ld.so.conf root.adm 640 /etc/lilo.conf root.adm 600 +/etc/mandrake-release root.adm 640 /etc/modules.conf root.adm 640 /etc/motd root.adm 644 /etc/printcap root.lp 640 /etc/profile.d/* root.root 755 /etc/rc.d/ root.adm 640 +/etc/rc.d/init.d/ root.adm 750 +/etc/rc.d/init.d/syslog root.adm 740 /etc/securetty root.root 640 /etc/sendmail.cf root.adm 640 /etc/shutdown.allow root.root 600 -/etc/ssh_config root.root 644 -/etc/ssh_host_key root.adm 640 -/etc/ssh_host_key.pub root.adm 644 -/etc/sshd_config root.adm 640 +/etc/ssh/ssh_config root.root 644 +/etc/ssh/ssh_host_*key root.adm 600 +/etc/ssh/ssh_host_*key.pub root.adm 644 +/etc/ssh/sshd_config root.adm 640 /etc/syslog.conf root.adm 640 /etc/updatedb.conf root.adm 640 /home/ root.adm 751 /home/* current 700 /lib/ root.adm 751 /mnt/ root.adm 750 +/proc root.kmem 550 /root/ root.root 700 /sbin/ root.adm 751 /tmp/ root.root 1777 @@ -56,22 +56,20 @@ /usr/* root.adm 751 /usr/X11R6/ root.xgrp 751 /usr/bin/ root.adm 751 -/usr/sbin/ root.adm 751 /usr/lib/rpm/rpm? rpm.rpm 750 +/usr/sbin/ root.adm 751 /usr/share/doc rpm.rpm 750 +/usr/share/man rpm.rpm 750 +/usr/tmp root.root 1777 /var/ root.root 755 +/var/lib/monitoring root.root 751 +/var/lib/naat root.admin 2770 +/var/lock/subsys root.root 700 /var/log/ root.root 711 /var/log/* root.root 600 -/var/log/squidGuard squid.squid 751 -/var/log/squid squid.squid 751 -/var/log/uucp uucp.uucp 750 -/var/log/news news.news 750 -/var/log/security/ root.root 700 -/var/log/security/* root.root 600 +/var/log/*/* current 600 +/var/log/*/*/* current 600 +/var/log/*/. current 700 /var/spool/mail/ root.mail 771 /var/tmp root.root 1777 -/var/lib/monitoring root.root 751 -/var/lib/naat root.admin 2770 -/var/log/httpd-naat httpd-naat.admin 750 /var/www-naat httpd-naat.admin 750 -/var/log/snort snort.snort 750 -- cgit v1.2.1