Excessive file permissions

Insecure file permissions

Description

Inadequate access control on files or directories can expose sensitive information or let unauthorized users alter data. If the application later executes or trusts modified content, the impact can extend to system compromise.

Potential impact

  • Data exposure: Unauthorized users may read sensitive files.
  • Data tampering: Other users may modify file contents and undermine integrity.
  • System damage: Modifying or deleting important files may disrupt the system.

Remediation

  • Apply least privilege to files and directories.
  • Review permissions regularly and remove unnecessary access.

Examples

File permissions

Before

python
# Unsafe file permissions
import os

file_path = 'sensitive_data.txt'
with open(file_path, 'w') as f:
    f.write('Sensitive information')

# Excessive permissions let other users overwrite the file; execution risks depend on how it is used.
os.chmod(file_path, 0o777)

After

python
# Safe file permissions
import os

file_path = 'sensitive_data.txt'
# Atomically create a new file with mode 0o600; fail if a file or symbolic link already exists.
fd = os.open(file_path, os.O_WRONLY | os.O_CREAT | os.O_EXCL, 0o600)
with os.fdopen(fd, 'w') as f:
    f.write('Sensitive information')

Explanation

  • Before: Excessive permissions let other users overwrite the file. Code execution depends on how the application uses the modified content.
  • After: O_CREAT | O_EXCL and 0o600 create the file with restricted permissions from the start. An existing file or symbolic link at the same path causes failure instead of being overwritten.

Directory permissions

Before

python
# Unsafe directory permissions
import os

dir_path = 'sensitive_dir'
os.mkdir(dir_path)

# Explicitly grant every user read, write and search permissions.
os.chmod(dir_path, 0o777)

After

python
# Safe directory permissions
import os

dir_path = 'sensitive_dir'
# Restrict access to the owner from the moment of creation.
os.mkdir(dir_path, mode=0o700)

Explanation

  • Before: Explicit mode 0o777 lets other users search the directory and change its contents.
  • After: Mode 0o700 restricts access to the owner at creation, avoiding a gap before a later permission change.

References