FIT1093 Chap.9 Access Control, Linux Permissions and Firewalls
Access Control, Linux Permissions and Firewalls
Once a user has been authenticated, access control decides what that user may do. Week 8 introduces the vocabulary: a subject is the active party making a request, an object is the resource requested, and an access right such as read, write or execute is what a subject may do to an object.
Rights can be delegated, and the workshop names the two classic vulnerabilities, excess privilege and unsafe defaults, along with the SUID permission, which lets a program run with its owner's rights instead of the rights of the user who launched it.
Linux records access control in a ten-character permission string.
The first character gives the object type, such as d for a directory, and the next three groups of three give the rights of the owner, the object's group and everyone else. On a file, r, w and x mean read, write and execute. On a directory, r means listing the names inside, w means adding or removing entries, and x means entering the directory and reaching files by name.
Linux applies only the first class that matches, owner, then group, then others. Workshop 8 builds its trickiest case on a directory with execute but not read permission, which can be entered but not listed.
Assignment 2 applies these ideas twice.
Task 3 asks you to act as a system administrator, creating users, groups, home and shared folders with the right ownership and permissions, including a special program for controlled access, and to show every step with screenshots and a hierarchy diagram.
Task 4 moves access control to the network, configuring the virtual machine's firewall so that public web and service ports are reachable from outside while an internal port answers only local requests, with evidence of both success and failure for each port.
What this chapter covers
- 01
Subjects, objects and access rights after authentication
- 02
Owner, group and others in the Linux permission string
- 03
Read, write and execute on files and on directories
- 04
SUID, excess privilege and unsafe defaults
- 05
Users, groups and ownership in Assignment 2 Task 3
- 06
Firewall rules for public and internal ports in Task 4
Worked example · free
Decide who can reach a file inside a restricted folder
- 2Priya is the owner: rwx on the folder and rw- on the file, so she can list the folder and read and edit the file.
- 2Kai matches the group class: r-x on the folder lets him list and enter it, and r-- on the file lets him read but not change it.
- 2Mia is others: --x on the folder lets her enter but not list it, and --- on the file blocks reading even if she knows the name.
Key terms
- Access Right
- A permitted operation, such as read, write or execute, that a subject may perform on an object.
- SUID Permission
- A Linux permission that makes a program run with the rights of its owner rather than those of the user who starts it.
- Least Privilege
- The design rule of giving each user, group or program only the rights its task requires.
- Firewall Rule
- An instruction that allows or blocks network traffic by direction, protocol and port according to a security policy.
Access Control, Linux Permissions and Firewalls FAQ
What does execute permission mean on a directory?
It allows a user to enter the directory and reach files inside it by name. Without read permission as well, the user cannot list the directory's contents, so they must already know the file name.
Does Linux combine owner, group and other permissions?
No. It checks whether the user is the owner, then whether they are in the group, and applies only the first class that matches, so a restricted group triple is not overridden by a more generous others triple.
What is the SUID permission used for?
It gives a program temporarily elevated rights by running it with its owner's privileges, which lets users perform one controlled action, such as reading protected files through a dedicated viewer, without direct access to those files.
How should I evidence firewall rules in Assignment 2?
The specification asks for the firewall configuration and, for each designated port, a terminal running the listener and the result in the host browser. The internal port must show local success and external failure.
Assessment move
Practise reading permission strings until you can say instantly what each user can do with a file and with the folder above it; write out ten mixed cases with owners, group members and others and check them against the first-matching-class rule.
Draw a hierarchy diagram for an invented organisation with two business units and a management group, decide owners and groups for each folder, and then write the permission string each folder needs, before touching any commands. For firewalls, write the policy in words first, default deny plus the specific allows, then translate it into rules and plan one test that should pass and one that should fail for each port.
Rehearse the full sequence on a test user, because the Week 12 demonstration expects commands from memory.
Working through Access Control, Linux Permissions and Firewalls in FIT1093? Sia is AskSia’s AI Cybersecurity tutor — ask any FIT1093 Access Control, Linux Permissions and Firewalls question and get a clear, step-by-step explanation grounded in how FIT1093 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.