Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
iw.local runs at startup!
abhishek_gupta
Hi,
I am using TS 5.5.2 on Solaris 8. There any file called iw.local which runs at startup when we reboot the solaris system. This script executes a command called chmod -R. This is causing various security problems on the Solaris server at the clients machine.
Does TS have to run this iw.local script at startup or can we take this file out from the startup of Solaris OS? If it is required in the startup, is there any way to stop it executing chmod -R or letting it perform anyother options on the Solaris OS files.
Thanks in advance,
Abhishek
Find more posts tagged with
Comments
johnjamesmarsh
My iwlocal.cfg is non existent. Do you know who set that up for you and why?
nipper
$iw-home/local/iwlocal.cfg is completely optional. comment out the triggers or just remove the file.
That being said, someone put it there for a reason (that may have been due to stupidity, but a reason none the less.
So you may want to figure out what it is doing and why. RTFM about triggers.
ALso, do not remove the iwlocal script, remove the config file it uses (iw-home/local/iwlocal.cfg)
Andy
Edited by nipper on 07/09/03 08:16 AM (server time).
Rathina
Actually, there is no iwlocal.cfg in my system too. The problem is that there is a script file called iw.local residing in etc/init.d which has a section which I'm reproducing without change
*********************************************
#
# PIDs File
#
IW_PIDSDIR="$IW_HOME/local/.pids"
IW_PIDSFILE="$IW_PIDSDIR/PIDS"
if [ ! -d "$IW_PIDSDIR" ] ; then
mkdir -p "$IW_PIDSDIR"
fi
if [ ! -d "$IW_PIDSDIR" ] ; then
echo "ERROR: Could not create directory $IW_PIDSDIR." 1>&2
exit 1
fi
touch "$IW_PIDSFILE" 1>/dev/null 2>&1
if [ $? -ne 0 ] ; then
echo "ERROR: This program needs to be run by a superuser" 1>&2
exit 1
fi
(chown -R root "$IW_PIDSDIR") 1>/dev/null 2>&1
(chmod -R go-wrx "$IW_PIDSDIR") 1>/dev/null 2>&1
TMPPIDSFILE="$IW_PIDSFILE.$$.tmp"
**************************
The security problem arises because the script is trying to change the permissions (chmod - R).
Any suggestions?
nipper
That should not be a huge issue
basically what is happening is that it makes the
dir:
$iw-home/local/.pids
and makes certain that ONLY root has access
It also creates a files name PIDS and chowns it.
This should not be a security problem. What is the issue ? there is 1 directory and one file, it is not going through a lot of directories and files.
If this is a big issue, then you could change the script for PIDSDIR and PIDSFILE, but it will get replaced on the next upgrade.
I would avoid changing this file, but if you have to, you will likely not be able to use triggers.
Andy
StrsHttpTest.txt
Rathina
Then in that case if we are not using any custom triggers then shall we remove the iw.local script from /etc/init.d/ .?
It may cause any problem to normal teamsite function?
Please suggest.
nipper
I would never remove a startup file, but hey, it is your system.
What is the problem with the chmod & chown ? It is not a security hole. Who is telling you to stop this ? Just say no. If you are really concerned, put an if in there something like:
if ( -e $iw-home/local/iwlocal.cfg) { do the chmod....}
so if the file is not there, it won't change anything.
But when you get an upgrade, these changes will be lost.
Like I say, my first choice is to leave it alone.
Andy
abhishek_gupta
Hi,
I am sure that no one has put the iw.local in the startup. Can it be that due to some internal process or while installation iw.local is put into the startup. And we are also not using any triggers explicitly. So I presume that removing the iw.local from the startup should not cause any problems. And we are not worried about upgrade.
The client moresoever is skeptical about having to run this script at startup because once when the Solaris box rebooted, it stopped users to telnet to the system. So they suspect, or rather charge that iw.local in the startup caused the problem.
Thanks,
Abhishek
skip11
IT smoke and mirrors. I defy them to prove that iw.local changed the
behaviour of telnet. It just doesn't fly.
Skip
johnjamesmarsh
Your client doesn't like start up scripts? Do they know about the scripts in /etc/rc3.d? I think the system won't work without these.
I would love to know how the iw.local stopped telnet working. I think it was more likely to have been witch craft.
Documentum_Foundation_Classes_Development_GuideD65.pdf
abhishek_gupta
Well the script iw.local is in the /etc/rc3.d directory - don't know how! From the posts above it seems it might not be used since we aren't using triggers and no one in my knowledge has put it there. So we would go ahead and delete it !
johnjamesmarsh
Do you have a sys admin on this Solaris machine? I would let them decide what needs to happen. The files in/etc/rc3.d are used at system start up to make Teamsite run. It is needed by the product in order for it to work. I have the same line in my S99iw.local and I expect you will be invalidating your support if you delete it.
abhishek_gupta
We have involved the Unix Admin into this. But from the TS part we have to be sure if the files are required or not.
Now, there is a file iw.local in /etc/init.d folder. Is this file required?
And also, as you mentioned S99iw.local exists in /etc/rc3.d folder, which is not safe to delete.
But initially in the post its mentioned "My iwlocal.cfg is non existent." This iw.local file which is not required, is being referred to under which directory
nipper
If you want to remove the file. GO ahead, remove it. It isn't my system, so if it breaks, not my problem.
But. iwlocal is not stopping your telnet.
All it does is make certain the .pid directory is available and starts any triggers (which you have none defined) So it does not do jack.
What will happen if you remove it ? One of the startup files references it, so maybe it is smart enough to proceed if the file is not there, maybe not.
What won't happen. Telnet still won't work.
Start looking elsewhere.
Andy
johnjamesmarsh
Scripts that live in /etc/init.d are generally the same as the scripts that live in /etc/rc3.d. Quite often the scripts in rc3 are symbolic links to the scripts in init.d. For example, on my system:
/etc/rc3.d/S99netscape -> /etc/init.d/netscape
The scripts inside rc3.d are the ones Solaris uses as it starts. The scripts in init.d are the actual start up scripts. Generally on a well configured system you will have both.
There is also the iwlocal.cfg that lives in $iwhome/local that configures the triggers in use but this is not used on my system.
I have to agree with Andy though. If you remove the iw.local or the S99iw.local or even the whole of Teamsite the problem stopping Telnet from working will still be there.