Is default new file privilege '700 OK?

In my new Mountain Lion installation I noticed that new files were created with privileges set to:
Me (owner):full access
staff (group): read only
everyone: read only
IOW - '744 in octal
Being a Tiger dinosaur up to now, that didn't make me feel real comfortable, so I looked around and found a pretty recent (Feb 2012) source from UC davis that recommends setting the new file defaults to:
owner: full access
group: no access
everyone: no access
I'd like to get a blessing from someone with a lot of experience as to whether or not its OK to set new file priviliges as recommend and whether the method recommended in the cited article is the right way to do it.

Actually, I have 3 accounts, one admin acct and two standard accounts for myself and my wife.  I established the separate admin account primarily to be the installer of apps, per security concerns that I inherited from my early Tiger days (and may not be necessary anymore).
I know that the privilege settings for the top-level subfolders of the home folder generally act as locked gates to all but the owner for access to what's inside each of them.  But, I wasn't sure if someone might be able to access a resource inside such a subfolder if (1) the privilege settings of the resource allow it ('644 for example) (2) the access request provides the full path to the resource.
So I did some experiments with Finder and also with Terminal ... and discovered that at least my simple straight-forward attempts to access a file by it's full path failed.  I'm no UNIX mavin, so my Terminal experiments didn't prove there was no way for a more knowledgeable non-admin to go around a blocking folder ... ergo I sent out this inquiry. 
If there were a way for a non-admin user to circumvent the privilege blocks in the primary home sub-folders (by giving the full path) ... I can image a scenario where one of our standard accounts is inadvertently infected by malware, which would exploit the vulnerability of unprotected files lying inside a protected folder.
It sounds as if you're telling me that to your knowledge this is not possible.

Similar Messages

  • Default New File Type In Files Panel

    Hello...in DW CS5, when I right click on a directory in my local root folder and select New File, the default extension for the new file is php.  The default new document type in the Preferences dialog box is html. Doesn't the Preferences dialog box new document type define the default extension when I right click to create a new file in the Files Panel? Thanks for any help.

    Randy,
    I set the server model to "None" as you suggested and the default extension when I right click to create a new file in the Files Panel matches up with the default in the Preferences diaolg box.
    Thanks for the help!
    Upbubble

  • How do i set a default group (not staff) for new files?

    by default, new files created from within applications appear to be assigned group "staff", regardless of the folder in which they are being created.
    i want new files to inherit the group of the folder in which they are being created. if i create a new file from the terminal command-line, this works. note that it also works when creating new folders from the finder and "save as" dialogue boxes.
    how do i get this to work for new files saved from all applications?
    thanks.

    I usually use the .NET method myself, but if I were forced to poll I would do something like this.  I use a variant to hold the list of filenames.  I would only poll the folder info, when it has been modified then do the Folder List.  Any new files are spotted when the variant attribute does not exist (Replace = FALSE), and this is added to the array.

  • Itunes saves my songs in a new file that is not the default setting

    My settings for downloading purchased music from itunes is c:\pop\music.
    Since a few months itunes generates a 2nd file named "music" within the existing file "music" and downloads all new songs in there. (It just happens, I surely didn´t tamper with the settings.)
    So everytime I buy music from the itunes store the new files are now saved under c:\pop\music\music.
    Also my ipod now only synchronizes the new files as long as they´re in c:\pop\music\music and not under c:\pop\music where I want to have them to be able to combine them with the others.
    I checked under "Information" of the new songs and for each song the setting for the place where it´s (supposed to be) saved under is still c:\pop\music. Also my default settings are still c:\pop\music.
    So why does itunes create a new file?????
    I can change almost every entry under "Information" but not the storage location.
    I don´t know why this happened and how I can change this back. Can anyone help me here, please!

    What im trying to say is, i purchased a imac after getting a new phone, which was on windows.
    So i now need to sync it so i can enjoy all the easy pleasures of genius so on and so on
    However not eveything made the shift over, so now my itunes on phone has songs from my old library, that due to whatever multiverse lays between mac and pc, are now not available on my new smarter and amazing mac.
    So if i sync the phone i will lose my songs, yes which did cost me money!! Does anyone know a way to prevent this?
    please bare in mind I am Mac simple, quite ******** really
    thank you in advance

  • How do I change the default save location for new files in Pages back from iCloud to my Documents folder?

    I just upgraded OSX to Mountain Lion and Pages to 4.2, and because OSX is syncing with my iCloud account, when I go to save a new file in Pages it defaults to try to save to my iCloud account rather than giving me the folder structure on my hard-drive that I prefer. It requires two extra steps to save to the proper place in my Documents folder on my hard drive.
    Is there a way to reset the default so that when I go to save a new file, the folder structure opens to the last saved folder (like it does in other non-iCloud applications) rather than defaulting to my iCloud, and to do it without just removing documents from my iCloud account entirely?
    I checked the Preferences for both Pages and iCloud and found nothing about this.

    What I meant is turn off Documents and Data in iCloud in OS X. Keep it on on your iOS devices. iCloud will sync documents between the iOS devices and make them available on the iCloud web site, but it won't mess up iWorks' open and save dialog boxes. It also won't assume that you want all your documents in iCloud, which I think is undesirable anyway.
    Keep iOS and OS X separate, and use the web site to move files between the two as necessary.
    iOS iWork is different from OS X iWork. There are fewer fonts on an iOS device. iOS iWork programs have slightly different feature sets than OS X iWork programs, and the file formats are different. iCloud automatically converts the file format when necessary, but if you make a habit of saving things directly to iCloud, you are limited to the lowest common denominator between the two versions of iWorks. So why would anyone want iWork on the Mac to open and save documents on iCloud by default?
    If you want to store files in the cloud and sync them on your Macs, SugarSync is a much better solution. It lets you choose your sync folders, it doesn't make you reorganize your files, it lets you sync all file types, it doesn't convert files to a different format and back, and it stores everything in the cloud, too. Just the simle act of saving a file backs it up and syncs it. I wouldn't live without it. iCloud is best with iTunes purchases and synchronizing Mac settings and iOS files; I woudln't live without it. The two make an unbeatable combination.

  • Default optimization for new files in Acrobat 9 Pro

    When I create a new file in Acrobat Pro 9, it automatically saves as version 1.6 (Acrobat 7.x). Much as I would love the whole world to have the latest reader version on their computer, the reality is that many of my website's users have older versions installed. As a consequence, I need to optimize all files as version 1.4, otherwise they won't be able to open the documents in their browsers.
    Why isn't there a preference setting to optimize all new files as 1.4 by default? This would save having to run the optimizer every time. Also, if I start from a file that is already optimized as 1.4, I extract a page and save it, this saves as 1.6. Why? If I am starting from a 1.4 PDF, surely that's the version I want?
    So every time I extract a page, tese are the steps I have to take:
    1) Extract and save the page
    2) Optimize it for 1.4
    3) Save it again (after confirming that yes, I do indeed want to overwrite it).
    I do this several times a day and it's an absolute pain in the neck, which could be avoided by implemeting any of these features:
    1) A setting under Preferences> Default PDF Version for new files;
    2) A PDF version selection box within the "Save As" dialog (I believe this feature has been requested by others);
    3) Acrobat Pro realizing that you have extracted the page from a 1.4 file and therefore saving the new file with the same format;
    4) Some sort of batch optimization option, so I only have to run the conversion once.
    Frankly I'm surprised none of these features already exist.
    Come on Adobe, is this really so hard to do?
    Thank you.

    Acrobat : Advanced menu : Preflight…
    Then:

  • I want to open a domain.site2 file outside the default folder (User/Library/Application Support/iWeb) with iWeb11, but iWeb only opens the domain file in the default folder. If I delete the default domain file, iWeb wants to create a new site. Help please

    I want to open a domain.site2 file outside the default folder (User/Library/Application Support/iWeb) with iWeb11, but iWeb only opens the domain file in the default folder. If I delete the default domain file, iWeb wants to create a new site. Does anyone have the same problem or know how to fix it?

    In Lion the Finder folder is now invisible.  To make it permanetely visible enter the following in the Terminal applicaiton window: chflags nohidden ~/Library and hit the Enter button - 10.7: Un-hide the User Library folder.
    For opening your domain file in Lion for the first time or to switch between multiple domain files  Cyclosaurus has provided us with the following script that you can make into an Applescript application with Script Editor. Open Script Editor, copy and paste the script below into Script Editor's window and save as an applicaiton.
    Just launch the applicaiton, find and select the domain file you want to open and it will open with iWeb. It modifies the iWeb preference file each time it's launched so one can switch between domain files.
    do shell script "/usr/bin/defaults write com.apple.iWeb iWebDefaultsDocumentPath -boolean no"delay 1
    tell application "iWeb" to activate
    OT

  • How to set default sharing permission for new files???

    Hello. I have an imac 24" and a macbook pro 15". they are connected over an airport network. i have file sharing set up, which is working great. i am having one problem though.
    whenever a file is created on either computer, it defaults to only allow the other computer to access it read only. is there a way to set a preference that will make all new files that are created to have read & write permission by the other computer????

    the easiest way to do that is to connect from one computer to the other not as a guest but as a registered user. then any files you create will be owned by that user. so if you have user1 on imac and user2 on mbp connect from the imac to the mbp as user2.

  • Copying objects from InDesign to paste into Photoshop: new file always defaults to 72 dpi.  How do I fix this?

    In previous versions, you could copy and object in another piece of software and Photoshop would automatically size the new file to take the object at 300 dpi.  In CS this appears not to be the case, the default size being 72 dpi.  How do I fix this? 

    Please refer PS system requirements from this link:
    http://helpx.adobe.com/photoshop/system-requirements.html#Photoshop CC system requirements/
    Regards,
    Ashutosh

  • Change the default way a new file opens

    Hi
    I'm working on Mac OS 10.7.5 and DW2014.1
    One of the most irritating things about up grades is when you discover the nice cosy way you've done things for years gets trampled all over for no apparent benefit- the only solace is that I guess the new way of working MUST please more people than it annoys - otherwise Adobe wouldn't have done it - right?
    ANYHOW - when I used to open a new file in DW it opened in split code / design view with the design view on the right. This is not just habit - it's actually how i want to work. The default is now suddenly the opposite and I'm darned if I can change the default. (I can of course change it EVERY time I open a file which is about 12 times an hour). I have tried changing it and then saving the current workspace - doesn't work. I have tried changing it and saving a new workspace. This doesn't work either. Feels like a preference but I can't find one.
    Any ideas anyone?
    Ans
    If I'm allowed a supplementary - a couple of other bits of bit of really useful functionality seem to have disappeared -
    1. When you clicked on the opening tag of an element a little line used to show up above the properties window showing the CSS stack and highlighting the current tag in a nice bright blue - it's gone. I can select the 'show parent div' icon in the tool bar but it's way clumsier.
    2. In the tool bar there used to be a fabulously useful icon that let you backwards select a tag - i.e. to click on the closing tag and it would show you the matching closing tag - this seems to have gone too.
    Sorry about the War and Peace questions - any answers hugely appreciated.
    Martin

    Feels like a preference but I can't find one.
    There is no setting that will change this currently. Please vote for the Idea I have posted to the ideas section which you can reach by clicking on the "Ideas" tab at the top of the summary page. I completely agree with your analysis.
    For your other questions, I'm a little unsure about what you are describing:
    1. Do you mean the Tag selector listing that would appear immediately below the document window?
    2. Do you mean the "balance braces" icon on the Code view toolbar?

  • New file default settings???

    Hi Guys, how do I change the default settings so it's always the same when I open a new file? For Instance, I'm trying to set the sample rate to 44.1k so that everytime I open a new file it defaults to that sample everytime. It was set to that sample rate originally then someone went and changed it inadvertantly. Now I should be able to change it back with out loading the CD and clicking on the repair to restore the default. Somebody changed the default to 48k so it should be changed back to 44.1. I just can't find in the book where it talks about that, nor can I find it by clicking around on all the controls. FYI we are a radio station and Audition 3 is our main audio work station. There are many hands who come in and produce commercials and sound bites for various reasons. None of whom are fluent in Audition, so they know just the basics and when they try to do something beyond that they usually screw it up and it causes problems for other people. I called the tech support line but I think the group of people in India who answer the phones don't actually use the software but recite what the book says as their answer.

    In Multitrack view File menu Default Session where you can either Set Current Session as Default or Clear Default.

  • Excel 2010 missing default suggested file name in Save As dialog box

    I’m using Excel 2010 running on Windows 7 (32 bit).  When I open a certain file which produces the following message: "A file is in a different file format than its extension indicates", and then go to “Save As” (or “Save”) the
    file, the default suggested file name is missing (blank).  This didn't occur in previous versions of Excel. 
    In previous versions, Excel would automatically populate the original file name in to the File Name field.
      I have searched all over the net, looking for a way to change Excel so that it will once again populate the file name in this situation. 
    To reproduce:
    Create a new blank workbook
    save as type “Web Page”, (i.e. File name:  “Blank Example.html”)
    Close workbook
    In windows, rename file from .html to .xls  (i.e. rename “Blank Example.html” to “Blank Example.xls”)
    In Excel open renamed file (i.e. “Blank Example.xls”) and click “Yes” when prompted with the “A file is in a different file format than its extension indicates” message.
    Do a “Save As” and you will notice that the File Name is blank. In previous versions, this field would contain the current workbook file name
     (i.e. “Blank Example.xls”)
    Any help will be greatly appreciated.

    Hi Jaynet,
    In order to re-produce this, you need to answer "yes" to the rename file prompt and then continue with step 5 (above).
    The reason for this is not an exercise in futility - I assure you.  At my work and elsewhere, when web developers have created features to permit the end user to save web data in Excel format, often times the Excel files are saved locally in Excel's
    html format (but with the .xls
    extension). 
    (I actually prefer the .xls
    extension, because it is easier to just double-click the file to open in Excel, rather than to select the open-with and then select Excel. a file with the .html extension will default open in your default browser. Now, I could change my default program
    for the .html extension, but that would only solve a part of the problem and would not really address the bigger issue and that being that Microsoft changed a behavior in Excel and may not even be aware that it was a much used feature. )
    To continue, when I go to open the resulting Excel file, I am prompted with the message that the file type does not match the extension (which is fine and not bothersome to me).  It's at this point when I go to save the file that I get really annoyed.
    In previous versions of Excel, the default file name would be pre-filled with the current name of the file and the default file type would state that it is a Web html file.  I would just change the file type to Excel Workbook and hit enter to save.
    I would be prompted with "Are you sure you want to overwrite your existing file?" message and I would click "yes" and that would be that.
    However, in Excel 2010, because the default file name is blank, I then need to re-type the name into the field to save the file. 
    Any help is greatly appreciated.
    Thanks

  • How to change the default "Safe" files in Safari?

    I would really appreciate if anybody could teach me how to change the default "Safe" files using AppleScripts, Folder Actions or .plist files. I really would like to have some files to open automatically after download, specially .pps files, and safari doesn't recognize such files as "safe". I tried to find out reading the help files but got lost.
    I posted a reply in an old topic for somebody who seemed to know, but it was not related to that topic, so I decided to open a new one.
    I'll be gratefull for any help. Thanks.

    Hi MDRC,
    Have a read of [this topic|http://discussions.apple.com/thread.jspa?threadID=1237961] to see if that helps.

  • Read-only access permissions for new files/folders?

    System:
    Clean Install on new intel Xserve
    10.4.8 Server w/ Open Directory
    Windows clients can read/write completely fine...
    Clients connecting using AFP (whether Standard or Kerberos authentication) can access files, but when new files/folders are created on the server, they register as full permissions for the user who created them, but not for the rest of the group.
    The share(s) in question are set using POSIX from WGM: Full access for owner/group/everyone (changed it to this thinking it would help, but it does not). Of course, no one can make changes to a newly-created/deposited files/folders, which is just plain silly.
    I can chmod the permissions recursively from a script (which fixes the problem, of course) on a regular basis so that its not (as much of) an issue, but there is still a 5-minute lag for the script to kick in, since we don't want to bombard the server with chmod requests every minute....which is unnecessary in the first place!
    I have plenty of other setups which are identical but have no such issue...
    Any reason why POSIX permissions on the share are being ignored from every user account?
    Thanks,
    k

    "That's default posix behaviour no matter what access permissions you set on the sharepoint."
    I'm afraid this is dead wrong. What matters most is how you set permissions on the share, not if you've chosen to inherit vs. using POSIX. POSIX is still used in inherit functions, though you can use ACL's to override them. In this case, ACL's are not being used on those shares (though we tried it).
    After all, why would Apple (let alone anyone else) even offer the ability to change POSIX permissions on a share if it didn't have any effect? That would be somewhat contradictory in nature.
    Like I said before, I have several other installations which are identically setup that have no such issues.
    As for Windows, it is also not set to inherit permissions; we're setting those explicitly. And they work fine.
    Any other ideas?
    Thanks,
    k

  • To create a new file in application server and transfer data to ti

    i am doing the following where i have to create a new file in application server and transfer data to tht file from an internal table.but its saying file cant be opened.the path i am giving to parameter p_prefil is /tmp/prachi.txt.
    wats the prob..can anyone help.
    DATA:L_WA_FINAL TYPE TY_FINAL,
         l_wa_string type string.
    OPEN DATASET P_PREFIL FOR OUTPUT IN text mode encoding default.
    if sy-subrc <> 0.
    write: ' file cannot be opened'.
    stop.
    endif.
    LOOP AT P_I_FINAL INTO L_WA_FINAL.
    move l_wa_final to l_wa_string.
    TRANSFER l_wa_string TO P_PREFIL.
    if sy-subrc <> 0.
    write: 'file can not be written'.
    stop.
    endif.
    clear l_wa_final.
    ENDLOOP.
    CLOSE DATASET P_PREFIL.
    if sy-subrc <> 0.
    write: ' file cannot be closed'.
    stop.
    endif.

    DATA:L_WA_FINAL TYPE TY_FINAL,
    l_wa_string type string.
    OPEN DATASET P_PREFIL FOR OUTPUT IN text mode encoding default.
    if sy-subrc ne 0.
    write: ' file cannot be opened'.
    stop.
    endif.
    LOOP AT P_I_FINAL INTO L_WA_FINAL.
    move l_wa_final to l_wa_string.
    TRANSFER l_wa_string TO P_PREFIL.
    write: 'file can not be written'.
    clear l_wa_final.
    ENDLOOP.
    CLOSE DATASET P_PREFIL.
    if sy-subrc ne  0.
    write: ' file cannot be closed'.
    stop.
    endif.

Maybe you are looking for