OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Vincent Danen (vdanenmandrakesoft.com)
Date: Sun Jan 21 2001 - 10:40:01 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Sun Jan 21, 2001 at 05:03:35AM -0500, Dave wrote:

    > The problem:
    > Root gets daily message as follows (sorry, it's kind of long):
    >
    > Security Warning: World Writeable files found :
    > - /home/sundance/.wprc/.wp8styles
    > - /tmp
    > - /tmp/.ICE-unix
    [...]

    This is just warning you that those files are world writable.
    Typically, you shouldn't have so many world writable files, but it
    looks like WP installed a lot. I don't know if it will break things
    to make them user-writable only; it might.

    This is basically a mechanism for you to see if any new world writable
    files exist on your system. A new world writable file that isn't
    installed by you should be a cause for concern. This list in and of
    itself, isn't *too* bad.

    > Security Warning: these home directory should not be owned by someone
    > else or
    > writeable :
    > user=zope(104) : home directory is group writeable.

    I haven't used Zope in a while, so I don't remember what the
    appropriate permissions for the home directory should be. You might
    have to leave this in order for it to work properly via apache, I
    don't remember. If you don't use Zope do (rpm -qa|grep Zope) and
    remove each Zope package.

    > These are the ports listening on your machine :
    > Active Internet connections (only servers)
    > Proto Recv-Q Send-Q Local Address Foreign Address State

    I believe someone else already commented on the servers and what you
    can do to minimize the number of daemons waiting for connections.

    -- 
    vdanenmandrakesoft.com, OpenPGP key available on www.keyserver.net
    1024D/FE6F2AFD   88D8 0D23 8D4B 3407 5BD7  66F9 2043 D0E5 FE6F 2AFD
     - Danen Consulting Services    www.danen.net, www.freezer-burn.org
     - MandrakeSoft, Inc. Security  www.linux-mandrake.com
    

    Current Linux uptime: 22 hours 15 minutes.