search cancel

World Writable Files Compliance

book

Article ID: 203265

calendar_today

Updated On:

Products

CA Infrastructure Management CA Performance Management - Usage and Administration DX NetOps

Issue/Introduction

Our NetOps servers have been flagged under our World Writable Files compliance checking as having issues with certain files containing too many write permissions. They would like to execute a command on our servers to remove this WWF issue. Please advise on if this will have adverse impact. The command would be executed on the Data Collectors

Command:

# chmod o-w <filename>   ( Removing the write permission for others )

Files:

-rwxrwxrwx 1 root root 1863 Sep 18 11:42 /var/.com.zerog.registry.xml
-rwxrwxrwx 1 xxxxxxx root 1716537 Sep 18 11:40 /app/IMDataCollector/Uninstall/.com.zerog.registry.xml
-rwxrwxrwx 1 xxxxxxx root 3408 Jun 19 09:38 /app/IMDataCollector/backup/apache-karaf/bin/setenv.bat
-rwxrwxrwx 1 xxxxxxx root 1818 Jun 19 09:38 /app/IMDataCollector/backup/apache-karaf/bin/karaf-service.bat
-rwxrwxrwx 1 xxxxxxx root 13440 Jun 19 09:38 /app/IMDataCollector/backup/apache-karaf/bin/karaf
-rwxrwxrwx 1 xxxxxxx root 3556 Jul  8  2015 /app/IMDataCollector/backup/apache-karaf/bin/stop
-rwxrwxrwx 1 xxxxxxx root 1587 Jul 10 08:14 /app/IMDataCollector/backup/apache-karaf/bin/restart
-rwxrwxrwx 1 xxxxxxx root 8868 Jul  8  2015 /app/IMDataCollector/backup/apache-karaf/bin/client
-rwxrwxrwx 1 xxxxxxx root 9778 Jul  8  2015 /app/IMDataCollector/backup/apache-karaf/bin/shell
-rwxrwxrwx 1 xxxxxxx root 10776 Jul  8  2015 /app/IMDataCollector/backup/apache-karaf/bin/admin
-rwxrwxrwx 1 xxxxxxx root 3560 Jul  8  2015 /app/IMDataCollector/backup/apache-karaf/bin/status
-rwxrwxrwx 1 xxxxxxx root 493568 Jun 19 09:38 /app/IMDataCollector/backup/apache-karaf/bin/karaf-wrapper.exe
-rwxrwxrwx 1 xxxxxxx root 4701 Jul 10 08:14 /app/IMDataCollector/backup/apache-karaf/bin/setenv
-rwxrwxrwx 1 xxxxxxx root 3810 Jul  8  2015 /app/IMDataCollector/backup/apache-karaf/bin/start
-rwxrwxrwx 1 xxxxxxx root 3408 Aug 13 09:55 /app/IMDataCollector/apache-karaf-2.4.3/bin/setenv.bat
-rwxrwxrwx 1 xxxxxxx root 1818 Aug 13 09:55 /app/IMDataCollector/apache-karaf-2.4.3/bin/karaf-service.bat
-rwxrwxrwx 1 xxxxxxx root 13440 Aug 13 09:55 /app/IMDataCollector/apache-karaf-2.4.3/bin/karaf
-rwxrwxrwx 1 xxxxxxx root 3556 Jul  8  2015 /app/IMDataCollector/apache-karaf-2.4.3/bin/stop
-rwxrwxrwx 1 xxxxxxx root 1587 Sep 18 11:40 /app/IMDataCollector/apache-karaf-2.4.3/bin/restart
-rwxrwxrwx 1 xxxxxxx root 8868 Jul  8  2015 /app/IMDataCollector/apache-karaf-2.4.3/bin/client
-rwxrwxrwx 1 xxxxxxx root 9778 Jul  8  2015 /app/IMDataCollector/apache-karaf-2.4.3/bin/shell
-rwxrwxrwx 1 xxxxxxx root 10776 Jul  8  2015 /app/IMDataCollector/apache-karaf-2.4.3/bin/admin
-rwxrwxrwx 1 xxxxxxx root 3560 Jul  8  2015 /app/IMDataCollector/apache-karaf-2.4.3/bin/status
-rwxrwxrwx 1 xxxxxxx root 493568 Aug 13 09:55 /app/IMDataCollector/apache-karaf-2.4.3/bin/karaf-wrapper.exe
-rwxrwxrwx 1 xxxxxxx root 4701 Sep 18 11:40 /app/IMDataCollector/apache-karaf-2.4.3/bin/setenv
-rwxrwxrwx 1 xxxxxxx root 3810 Jul  8  2015 /app/IMDataCollector/apache-karaf-2.4.3/bin/start
-rwxrwxrwx 1 root root 1863 Sep 18 11:40 /var/.com.zerog.registry.xml

Environment

Dx NetOps Performance Management 20.2.x

Resolution

There is no need for world writeable - really only owner writable is needed. Group is if you want to give more than the owner access to update.  So there is no danger is running  chmod o-w <filename>