2013-02-06 15:45:29 +01:00
|
|
|
#!/usr/bin/env bash
|
|
|
|
# This script removes permissions from other people than the owner to
|
|
|
|
# files/folders that they don't have access to and where they don't need
|
|
|
|
# access.
|
|
|
|
## THIS SCRIPT HAS MOVED TO SHELL-THINGS AS "chmod"!
|
|
|
|
## https://raw.github.com/Mkaysi/shell-things/master/chmod
|
|
|
|
|
2013-02-07 17:13:45 +01:00
|
|
|
GROUP=`id -gn`
|
|
|
|
|
2013-02-07 17:17:02 +01:00
|
|
|
wwwdata=`head -n1 wwwuser`
|
2013-02-07 17:13:45 +01:00
|
|
|
|
2013-02-06 15:45:29 +01:00
|
|
|
echo "Denying Reading, Writing and eXecuting from other users in"
|
|
|
|
echo "your home directory $HOME ."
|
2013-02-07 17:13:45 +01:00
|
|
|
echo ""
|
2013-02-06 15:45:29 +01:00
|
|
|
chmod g-rwx,o-rwx $HOME -R
|
|
|
|
|
|
|
|
echo "Creating empty oidentd user configuration file, if it doesn't"
|
|
|
|
echo "already exist."
|
2013-02-07 17:13:45 +01:00
|
|
|
echo ""
|
2013-02-06 15:45:29 +01:00
|
|
|
touch ~/.oidentd.conf
|
|
|
|
|
|
|
|
echo "Allowing other users to read oidentd configuration file."
|
|
|
|
chmod u+rw,g-wx+r,o-wx+r ~/.oidentd.conf
|
2013-02-07 17:13:45 +01:00
|
|
|
echo ""
|
2013-02-06 15:45:29 +01:00
|
|
|
|
|
|
|
echo "Denying directory listing from other users and allowing them to"
|
|
|
|
echo "access files/folders where they have permissions."
|
|
|
|
touch ~/.ICEauthority
|
|
|
|
chmod o-rw+x,g-rw+x ~
|
2013-02-07 17:13:45 +01:00
|
|
|
echo ""
|
2013-02-06 15:45:29 +01:00
|
|
|
|
|
|
|
echo "Creating apache2 UserDir..."
|
2013-02-06 15:54:38 +01:00
|
|
|
mkdir -p ~/public_html/
|
2013-02-07 17:13:45 +01:00
|
|
|
echo ""
|
2013-02-06 15:45:29 +01:00
|
|
|
echo "Allowing everyone to Read and eXecute everything in your apache2"
|
2013-02-07 17:13:45 +01:00
|
|
|
echo "userdir and hoping that we are the only user in group $GROUP..."
|
|
|
|
chmod o+rx-w,g+rxw ~/public_html/ -R
|
|
|
|
echo ""
|
2013-02-07 06:21:59 +01:00
|
|
|
|
|
|
|
echo "Setting corret permissions to other files which others should access."
|
2013-02-07 06:22:51 +01:00
|
|
|
touch ~/.face
|
|
|
|
touch ~/.forward
|
2013-02-07 17:13:45 +01:00
|
|
|
echo ""
|
2013-02-07 06:22:51 +01:00
|
|
|
chmod a+r-wx,u+rw ~/.face
|
|
|
|
chmod a+r-wx,u+rw ~/.forward
|
2013-02-07 06:21:59 +01:00
|
|
|
|
2013-02-07 17:13:45 +01:00
|
|
|
echo "Setting access lists. This requires package acl to be installed"
|
|
|
|
echo "and kernel support for it and mount point being mounted with option"
|
|
|
|
echo "acl"
|
|
|
|
echo ""
|
|
|
|
|
|
|
|
setfacl -R -m u:$wwwdata:rwx ~/public_html
|
|
|
|
setfacl -R -m d:u:$wwwdata:rwx ~/public_html
|
|
|
|
|
|
|
|
if [ -f chmod.2 ]; then
|
|
|
|
./chmod.2
|
|
|
|
fi
|
|
|
|
|
2013-02-07 06:21:59 +01:00
|
|
|
echo "Everything is now done :)"
|