Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

PyROm

Members
  • Posts

    661
  • Joined

Everything posted by PyROm

  1. Another way to fetch a webpage, using vbs (in case you already use vbs login/logoff scripts) http.open "GET", "http://", FALSE http.send ""
  2. The windows 10 drivers category is likely to make a massive difference.
  3. We have fsrm quotas on student home drives (the only place they can save to), when they max it out with photos and come to us for more space we send them back and tell them to resize them themselves. We have also asked the photography teacher to teach resizeing and taking images of appropriate size for their use as part of the photography course. We have Flexxi resizer on all the machines (actually just a link the program is hosted on a share) to allow students to bulk resize (is free and fairly simple to use), although for some reason it has pictures of a fox all over it.
  4. An example of what happened here when I accidentally enabled efs encryption for workfolders (only used on already bitlockered laptops), teacher does presentation and saves it to share. Teacher then copies presentation to usb stick to show at another school, teacher plugs usb stick into other schools pc, she can see all her files however cannot open any of her files because they are encrypted, its efs so no way to enter a password etc. to unlock them. Its something worth thinking/planning for if you use efs file encryption.
  5. Another thought rerun the setfacl but without the -d, we might have set the default file permissions for new folders/files, but not actually changed the existing ones so setfacl -Rm g:www-data:rwx /compscihomes
  6. try UserDir /compscihomes/*/public_html Options Indexes FollowSymLinks Require all granted If this works you can gradually add back in limitations you want.
  7. just a sec, got suggested code block wrong
  8. Missed this bit, looks like they changed wildcard handling in apache 2.4, in theory what you have should still work but maybe its a bit buggy, try changing the direcory block to point to just /compscihomes in your userdir.conf, so it reads UserDir public_html UserDir disabled root AllowOverride FileInfo AuthConfig Limit Indexes Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec +ExecCgi AddHandler cgi-script cgi pl Order allow,deny Allow from all Order deny,allow Deny from all also if you still have this section in your apache2.conf remove it, as it might be overiding your userdir.conf settings or vice versa Options Indexes FollowSymLinks MultiViews AllowOverride None Require all granted I think the way you are setting up this server is probably the best way to do it from a security point of view. My sugestion of mounting the homedrives would allow you to serve files straight from their normal homedrive but could potentially open up security holes to let users get at each others normal home drives, especially if you are allowing scripting on the server. For linux to linux mount I would actually use nfs, when you mount anything on linux you can pass options on mount (or in fstab) to fake the owner and file permissions.
  9. Coming from another angle, what if rather then having a second storage area for them, you mounted the windows homes share on your windows server onto the linux server, I believe you can set the effective/fake permissions on the mount option, then served the webpages from there?
  10. Are you sure it would break access, it never used to (switched away from using samba as main fiel server 3 years ago)? as a thought, try the setfacl command again, but dont put a trailing / in, it might not have set the acl`s on the /compscihome folder. so setfacl -Rdm g:www-data:rwx /compscihomes
  11. I cant see anything wrong with that, but im not used to linux acl`s. Im afraid im stuck here. You could disable acl`s on the filesystem but that might break other things. Alternatively you could reinstall, my preference is debian, ubuntu is based off it but a debian (so the commands and configs are mostly the same)minimal install is very small and doesnt have acls or apparmor on as default.
  12. I think the problem is that the ACL will be blocking it somewhere, acl`s are seperate to the normal 777 file permissions.... not used acl on linux before, but looks the below shpould work, after doing it run getfacl /compscihomes/tkid3/public_html/file.html to check it looks right. setfacl -dm "g:www-data:rwx" /compscihomes
  13. Have you created any .htaccess file in the folder any folders above? If you do an ls-l does the file.html have a + on the end of the permissions? When you ran the comand to disable apparmor did you try it again straight away or reboot? (turning apparmor off that way only stops it until next reboot, so rebooting would reset it again).
  14. what happens if you miss the file off and just try for the folder? eg http://compsci/~tkid3/
  15. I think I understand now, change the "userdir public_html" to "userdir /compscihomes/*/public_html" this should overide going to the users actual home folder.
  16. Are you using samba to create users from ad? if so there is option for user home folder in smb.conf which will alter where it creates them.
  17. possibly quick cheating way ln -s /compscihomes /home/year10 This will symlink the home folder back to your comsci folder, you will need to do it with each year. You may also need to allow foolow symlinks for /home (or just / if your not too bothered)
  18. Are the folders under /compscihomes/ symlinks? or actual folders?
  19. Also worth a try, ubuntu uses apparmor rather then selinux, try service apparmor stop Apparmor is a security system (like selinux) that restricts what folders applications can access.
  20. as a wild guess.... chown -R james:www-data /compscihomes/tkid3/public_html Just wondering if it doesnt like root owndership of the public_html as you have told it deny the root user in the userdir option.
  21. Just double checking some basic stuff now because im a bit stuck, is the whole path on the server actually lowercase? eg. the username is all lowercase so /compscihomes/tkid3/public_html not /compscihomes/TKid3/public_html ? The other thing to double check permissions is namei -l /compscihomes/tkid3/public_html To make sure nothing has changed permissions since ou chmodded them. This will list all folders back down to root with permissions.
  22. run systemctl status apache2.service to see why the service wont start. Or look in /var/log/apache2/error.log if the first isnt useful.
  23. Have you restarted apache after making the config changes? eg. /etc/init.d/apache2 restart
  24. Type sestatus to see if selinux is enabled, if it isnt, or you get an error about sestatus not installed then you dont need to run the setsebool as selinux isnt installed/enabled. If it is enabled you could temporerily (until next reboot) turn it off with echo 0 > /selinux/enforce to see if that fixes it.
  25. Have you restarted the whole server since running the setsebool command? I doubt its samba interfering with permission at this point. You could try and chod 644 the file itself to check having execute on it is nt causing a problem, but that wouldnt match your error log.
×
×
  • Create New...