fsize isize , fsize  isize , fsdb, - , .  fsdb, , . , , (512 UNIX 1024 XENIX). UNIX: +-------------------------------------------------------------- | 512 | 001000: 000173 (123) | fsdb , - (512), (001000). , , - ( - ). , <Return>, . +-------------------------------------------------------------- | 002000: 000173 (123) | <Return> | 002002: 000000 (0) | <Return> | 002004: 007461 (3889) | UNIX fsize <Return>, XENIX - . ( - UNIX.) . - 4-25 -  - : block out of range ( ) , fsize , fsdb , - . , O. . INTERRUPT (DEL) <CTL>d, . , - fsize, 0 ( - 3889): +-------------------------------------------------------------- | 002000: 000173 (123) | <Return> | 002002: 000000 (0) | <Return> | 002004: 000000 (0) | , - , fsdb. ( , - , , , . fsdb , sync.) , - : +-------------------------------------------------------------- | 002002: 000000 (0) | <Return> | 002004: 000000 (0) | =3889 | 002004: 007461 (3889) | q | fsdb - , fsdb. fsck. - 4-26 -  isize ( 16 2) ISIZE, - fsdb . fsize FSIZE, fsdb , - .  5   5-1 ? 5-3 5-3 5-7 5-7 sysadmsh 5-9 5-9 , 5-11 5-11 5-14 5-15 5-15 5-15 5-16 sysadmsh 5-17 5-18 5-18 5-18 5-20 5-21 5-23 5-23 5-26 5-27 / 5-32 5-32 5-33 5-33 5-34 5-36 5-36 5-41 5-44 5-44 5-45 . 5-45 5-45 5-48 SUID/SGID sticky- 5-48 Sticky- 5-49 5-51 5-51 5-51 5-52 5-53 GID 5-53 5-54 /etc/fsck 5-54 5-54 5-55 5-55 5-57 5-57 , 5-59 5-59 5-60 5-61 5-62 5-64 5-65 5-66 , 5-66 / cron 5-67 cron 5-68 / at/batch 5-68 at/batch 5-68 at/batch 5-69 . - 5-1 -  - , . , , - UNIX. - , C2, " " ( " "). , - . - , , "- " " " (User's Guide). : * * * * sysadmsh * * * * * * * * - 5-2 -    , . - , - . : 1. " ". 2. . . - 5-3 -  ? , , "" (trusted) "" (secure). , 2. "" - , , - ( ) - . - , , "" UNIX. , UNIX. - - , . , , - "" . . - , - , - . , - . . , , UNIX. " , - ". , - , , 2. . - . , , - , ( ) .   , - . , , , . ; - , . . - 5-4 - , , - . , - , . UNIX - : . , - - , lp cron, ; . , UNIX - - , . UNIX , . - root - . - , - (LUID). , , . LUID , - . LUID , , . - LUID. - , , - . -  (, ..), -  . UNIX - , , - (, , ), . - - . ( ) ( ). UNIX - , ( ), ( ) SUID ( ) - - , . , UNIX , SUID .  (promain - protected domain, .. ). (). SUID, - , . - . - 5-5 - SUID , , . , SUID . promain(M) " " (User's Reference). - - . UNIX , , root , . - , - . - : . . ( - , - .) , . - . - (- ). - , , . , lp , , - , lpadmin(ADM). , . - , . - . (I&A) UNIX, - . - (/etc/passwd). , , - , - . - , , , . I&A. , - . . . , , - . - - -   ( auth). . . - 5-6 - (audit) UNIX . - . - (trail). , - , , . ,  -  ( audit). - , , , . - . - , , . UNIX setuid - (SUID) - setgid - - (SGID). - , . , .  . ( / ), , , - . - SUID/SGID , . - : * , ( ); * , - , - ; * , ; . - - , . . - 5-7 -   - . , , - . - -, root, , , - .   UNIX . - . - ( ) - . - . . , , - . - . , , . - , - , , . . - 5-8 -  5.1   ---------------------------------------------------------------- | | | | ---------------------------------------------------------------- | auth | | | | lp | | | *| terminal | - | | cron * | cron | at cron * | mem | | audit | | | | backup | | | | su | su | | - | sysadmin | | | integrity(ADM) --------------- * , . , , . - , , , ( ) . . sysadmsh : Accounts -> User -> Examine:Privilege  , , , . - , - , . , . , - . - . . - 5-9 -  sysadmsh , . , - - , mem . , sysadmsh(ADM). ; . 5.2 , - sysadmsh , .  5.2  sysadmsh ---------------------------------------------------------------- | | | sysadmsh | ---------------------------------------------------------------- -| Printers | " " | | | Backups | " " | Accounts | " | | " Cron | Jobs | " | | " | | ( ) | System->Audit | " | | " ( ) audit . " " (User's Reference), , subsystem(M). , - . , - , UNIX, , - . - . , . - - . , - su, su(C) -. , root, root. ( . " - " .)   : . , . 5.3 . . - 5-10 -  5.3   ---------------------------------------------------------------- | ---------------------------------------------------------------- configaudit | writeaudit | execsuid | SUID chmodsugid | SUID SGID chown | suspendaudit | nopromain | nopromain  execsuid . ( , . nopromain - , - ; - . . promain(M).) - SUID, execsuid. ( - , - . , - , .) SUID SGID, - chmodsugid. ( ), chown. - , root.  NIST FIPS 151-1 chown. , NIST FIPS 151-1.  , - . - , - . , configaudit . - . - audit. . sysadmsh : Account->User->Examine:Privileges . - 5-11 - , , , - , . , ("C2" "Relaxed"), ; chown, execsuid chown .  5.4   ---------------------------------------------------------------- | ---------------------------------------------------------------- audit | configaudit, suspendaudit, execsuid auth | chown, execsuid backup | execsuid lp | chown cron | execsuid, chown, chmodsugid sysadmin | execsuid, chmodsugid, chown  , -   2. , - , : C2 "Relaxed", - UNIX. , - - , . - " - , " " - ". " - " .   , . - , : * * * . " " " - ". , . . - 5-12 - " " (Password Management Guideline) ; , UNIX. , . , , , . , - - UNIX. ,  . - , ( - ) . , - . expired,  .  . - , Accounts sysadmsh. - , .   , - .  - ( , ), ( ). - "- , " "- " - , " - " . ; - , . - , - . - . , - . - , - . - 5-13 - . , , ; - . , - , - , . ( , .) , , . " " - " " . , , , - , . , - , . " , " " " . . - 5-14 -   , - ,  , . , - , - . , . -  - . . . , - , , - , - . , . - . ,  -   (DAC), - , . , " ", DAC, - , , . , - , - . , , . , , - . , , - - (LUID). , su(C). , , -