Skip to Content
Cybersecurity Ops with bash
book

Cybersecurity Ops with bash

by Paul Troncone, Carl Albing
April 2019
Intermediate to advanced
303 pages
6h 16m
English
O'Reilly Media, Inc.
Content preview from Cybersecurity Ops with bash

Chapter 17. Users, Groups, and Permissions

The ability to control user permissions is a critical aspect of maintaining the security of any system. Users should be given only the permissions that are necessary to perform their job. This is known as the principle of least privilege.

In most cases, you will need to be the owner of a file/directory or have root/administrator privileges in order to change permissions.

Warning

Be cautious when setting file permissions. Changing permissions not only has security implications, but if done incorrectly can cause a system to become nonfunctional or vulnerable to attack.

Commands in Use

In this chapter, we introduce chmod, chown, getfacl, groupadd, setfacl, useradd, and usermod for administering Linux systems, and icacls and net for administering Windows.

chmod

The chmod command is used to change file permissions in Linux. This command can be used to change three permissions: read (r), write (w), and execute (x). The read, write, and execute permissions can be set for the user (u), group (g), and other (o) users of a file or directory.

Common command options

-f

Suppress error messages

-R

Recursively change files and directories

chown

The chwon command is used to change the owner of a file or directory in Linux.

Common command options

-f

Suppress error messages

-R

Recursively change files and directories

getfacl

The getfacl command displays the permissions and access control list (ACL) for a Linux file or directory. ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Linux Basics for Hackers

Linux Basics for Hackers

OccupyTheWeb .
Hacking Kubernetes

Hacking Kubernetes

Andrew Martin, Michael Hausenblas

Publisher Resources

ISBN: 9781492041306Errata Page