Insecure file permissions

Insecure file permissions

Description

Granting group or other-user write access to a security-sensitive file lets untrusted users with those permissions change its contents.

Potential impact

  • Configuration tampering, privilege escalation, or replacement of code or data.

Remediation

Create sensitive files with minimal permissions, generally 0600 or a more restrictive mode. Check file ownership and who can modify parent directories too.

Examples

Before

c
open("/var/app/config", O_CREAT | O_WRONLY, 0666);

After

c
open("/var/app/config", O_CREAT | O_WRONLY, 0600);

The first excerpt requests group and other-user write bits for a new file. Actual permissions also depend on the umask and ACLs. The second requests owner read/write access only.

The mode argument to open does not change an existing file's permissions. Check the ownership and actual permissions of existing files separately. These excerpts assume a trusted directory and path.

References