<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rapid 7 Vulnerability for world writable files in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580847#M16996</link>
    <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2019 15:28:14 GMT</pubDate>
    <dc:creator>Aasth</dc:creator>
    <dc:date>2019-08-13T15:28:14Z</dc:date>
    <item>
      <title>Rapid 7 Vulnerability for world writable files</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580831#M16991</link>
      <description>&lt;P&gt;&amp;nbsp;We are seeing rapid 7 vulnerabilities on our sas servers for the following world writable files. Can the permissions of this files be changed without any impact to the services running?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* /sas/install/SASHome/Secure/sasexe/libccme_asym.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libccme_base.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libccme_base_non_fips.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*/sas/install/SASHome/Secure/sasexe/libccme_ecc.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libccme_ecc_accel_fips.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libccme_ecc_accel_non_fips.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libccme_ecc_non_fips.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libccme_ecdrbg.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libccme_error_info.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/SASHome/Secure/sasexe/libcryptocme.so (-rwxrwxrwx)&lt;/P&gt;&lt;P&gt;* /sas/install/gms_install/gms8.0.1_install/Install.log (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/lsf/gms/log/gabd.log (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/lsf/gms/log/gabd.log.back (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/lsf/log/Install.log (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/lsf/log/res.log.nlr1sasdev1.abcbs.net (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* /sas/install/pm/9.1/install/Install.log (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/pm_install/pm9.1.3.0_sas_pinstall/lsf9.1.3_lsfinstall/Install.err (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/pm_install/pm9.1.3.0_sas_pinstall/lsf9.1.3_lsfinstall/Install.log (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/pm_install/pm9.1.3.0_sas_pinstall/pm9.1.3.0_install/Install.err (-rw-rw-rw-)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;* /sas/install/pm_install/pm9.1.3.0_sas_pinstall/pm9.1.3.0_install/Install.log (-rw-rw-rw&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 14:53:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580831#M16991</guid>
      <dc:creator>Aasth</dc:creator>
      <dc:date>2019-08-13T14:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid 7 Vulnerability for world writable files</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580833#M16992</link>
      <description>&lt;P&gt;The libccme_* libraries can have all write bits turned off.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Install logs generally only need the write bit set for the user (i.e., the SAS install user or in this case the LSF/PM installer).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The LSF/PM operational logs need to have the user write bit set for the user running the daemon. Sometimes that is root and other times it is the primary grid administrator.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 15:01:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580833#M16992</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2019-08-13T15:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid 7 Vulnerability for world writable files</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580842#M16994</link>
      <description>&lt;P&gt;Thank you for the response. In that case is 770 safe bet for all the listed files?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 15:24:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580842#M16994</guid>
      <dc:creator>Aasth</dc:creator>
      <dc:date>2019-08-13T15:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid 7 Vulnerability for world writable files</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580845#M16995</link>
      <description>&lt;P&gt;libccme_* files should have 555 since they are read-only shared libraries.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Logs can have 770.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 15:27:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580845#M16995</guid>
      <dc:creator>doug_sas</dc:creator>
      <dc:date>2019-08-13T15:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Rapid 7 Vulnerability for world writable files</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580847#M16996</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 15:28:14 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Rapid-7-Vulnerability-for-world-writable-files/m-p/580847#M16996</guid>
      <dc:creator>Aasth</dc:creator>
      <dc:date>2019-08-13T15:28:14Z</dc:date>
    </item>
  </channel>
</rss>

