RE: Solaris 10 necessary file question
"Levenglick, Jeff" <[email protected]> Mon, 6 Nov 2006 13:01:14 -0500
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Message-ID | <[email protected]> |
=0D=0A" but the administrator is not very familiar with Solaris and doesn't= "=0D=0A=0D=0ABad feeling #1 :) Unix, unlike windows, will let you delete an= ything you=0D=0Awant and not warn or stop you=2E (try a rm -r * from / as u= ser root :) )=0D=0AIt will then crash without a care=2E The point, if you d= o not really know=0D=0Athe OS, then do not try to manually delete things=2E= Delete the package=2E=0D=0AUnix will even be nice enough to tell you if an= ything else depends on=0D=0Athat package=2E=0D=0A=0D=0ALp is for the printi= ng package/system=2E Are you sure you will never need=0D=0Aprinting service= s?=0D=0A=0D=0AAre you just wanting a more secure box? The two easy solution= s:=0D=0A=0D=0A1) Lock the account=2E=0D=0A2) If you do not want to lock the= account then change the shell to point=0D=0Ato /dev/null=2E=0D=0A=0D=0AYou= can change the sendmail user to be anything=2E (in the sendmail=2Ecf,=0D= =0Auser to run as setting) Just remove the package if you do not want it= =2E=0D=0A=0D=0A=0D=0AAgain, if your running an up-to-date sendmail, you can= secure it=2E It=0D=0Amakes life very each to get alerts/logs from the host= to your email=0D=0Aaccount=2E (unless you like connecting to the box all t= he time to check=0D=0Alogs) you also may need to check all of your config f= iles=2E Some may want=0D=0Ato send an email to root if there is a problem/t= rap=2E=0D=0A=0D=0A=0D=0A" Does anyone know if those files are still in use = even though the=0D=0Afile's owner accounts have been deleted?"=0D=0A=0D=0AB= ad feeling #2 :)=0D=0AThat sounds like a very beginner type of question=2E = In Unix, if you=0D=0Adelete the user or group, the file owner or group will= change to the=0D=0Anumber of the uid or group that the account was=2E=0D= =0A=0D=0AIe: user - joeshmo uid 2000=2E If you delete joeshmo then all fil= es that=0D=0Ahe owned will now show 2000 as the owner=2E=0D=0A=0D=0AWhy is= this bad -=0D=0A1) If you create a new user sometime later and give them t= he same uid,=0D=0Athen they own that file=2E (Which you may or may not want= )=0D=0A=0D=0A2) It becomes harder to search for the file(s) as you need to = search by=0D=0Anumber and not a name=2E=0D=0A=0D=0A3) depending on the righ= ts, you may think the file is gone, when it is=0D=0Astill there=2E=0D=0A=0D= =0A4) It is sloppy admin'ing=2E Auditors will have a field day with it=2E = =0D=0A=0D=0A=0D=0AYou really should learn the OS first, before you delete/r= emove things=0D=0Athat your not sure of=2E=0D=0A=0D=0AJeff=0D=0A=0D=0A=0D= =0A-----Original Message-----=0D=0AFrom: listbounce@securityfocus=2Ecom [ma= ilto:listbounce@securityfocus=2Ecom]=0D=0AOn Behalf Of Stephen Hauskins=0D= =0ASent: Friday, November 03, 2006 10:46 AM=0D=0ATo: jeffnjillian@gmail=2Ec= om=0D=0ACc: focus-sun@securityfocus=2Ecom; focus-sun-return-1414@securityfo= cus=2Ecom=0D=0ASubject: Re: Solaris 10 necessary file question=0D=0A=0D=0A= =0D=0A=0D=0AIf you are running sendmail I would be careful about doing=0D= =0Aaway with smmsp=2E The others are not necessary but really=0D=0Adon't r= epresent much in the way of diskspace usage or system=0D=0Aresources=2E=0D= =0A=0D=0A=0D=0AOn Thu, 2 Nov 2006, jeffnjillian@gmail=2Ecom wrote:=0D=0A=0D= =0A> We removed the following default accounts in Solaris 10: lp, smmsp,=0D= =0Awww, uucp, nuccp, however the files owned by these accounts still exist= =2E=0D=0AI would like to delete these files, but the administrator is not v= ery=0D=0Afamiliar with Solaris and doesn't know if the O/S needs the associ= ated=0D=0Afiles or not=2E Does anyone know if those files are still in use = even=0D=0Athough the file's owner accounts have been deleted?=0D=0A>=0D=0A>= Thank You in Advance,=0D=0A> Jeff=0D=0A>=0D=0A=0D=0A=0D=0A----------------= -------------------------=0D=0AThis e-mail message is private and may conta= in confidential or=0D=0Aprivileged information=2E=0D=0A