Access control and least privilege · التحكم في الوصول والأقل امتيازًا
Least privilege
- A core security rule: give every person and program only the access they need — no more.
- If an account is broken into, least privilege means the attacker can reach less.
أقل امتياز
- قاعدة أمنية جوهرية: منح كل شخص وبرنامج الوصول الذي يحتاجونه فقط — ولا أكثر من ذلك.
- إذا تم اختراق حساب، فإن أقل امتياز يعني أن المهاجم يمكنه الوصول إلى أقل.
Access control on files
- On Linux, file permissions are access control in action (you met these in the Linux course).
ls -lshows who can read, write, and execute, for the owner, the group, and everyone else.
التحكم في الوصول على الملفات
- في نظام لينكس، صلاحيات الملف هي التحكم في الوصول عمليًا (لقد التقيت بها في course Linux).
ls -lيظهر من يمكنه قراءة r و كتابة w و تنفيذ e، للمالك، المجموعة، والآخرين.
ls -l secret.txt
Locking down a secret
- A file holding a password or key should be readable by its owner only.
chmod 600gives the owner read+write, and nothing to anyone else:
6= read+write for the owner;0and0= no access for group and others.
تأمين السر
- ملف يحتوي على كلمة مرور أو مفتاح يجب أن يكون قابلاً للقراءة بواسطة مالكه فقط.
chmod 600يمنح المالك قراءة+كتابة، و لا شيء للآخرين:
chmod 600 secret.txt
6= قراءة+كتابة للمالك؛0و0= لا وصول للمجموعة والآخرين.
Your turn
- Lock down
secret.txtso only its owner can touch it. Good permissions are a simple, powerful defence.
Covers: A-Level 6.1 (access levels / security measures).
دورك الآن
- قم بقفل
secret.txtبحيث يمكن لمالكه فقط اللمس إليه. الصلاحيات الجيدة هي دفاع بسيط وقوي.
يتناول: A-Level 6.1 (مستويات الوصول / تدابير الأمان).
Common mistakes
- Give each user only the access they need (least privilege).
- Do not use an administrator account for everyday work.
أخطاء شائعة
- امنح كل مستخدم فقط الوصول الذي يحتاجه (أقل امتياز).
- لا تستخدم حساب مسؤول للعمل اليومي.
Least privilege · الأقل امتيازًا
Give each user only the rwx they need — nothing more. · امنح كل مستخدم فقط الصلاحيات rwx التي يحتاجها — لا أكثر.
secret.txt is currently readable by everyone. Lock it down so only its owner can read and write it, with chmod 600 secret.txt. The check shows ls -l. · secret.txt مقروء حاليًا من قبل الجميع. قفله بحيث يملكه فقط يمكنه القراءة والكتابة، باستخدام chmod 600 secret.txt. يُظهر الفحص ls -l.
Least privilege is not always 600. Your team should read team-notes.txt, but not change it — and outsiders get nothing. Use chmod 640 team-notes.txt (6 = owner read+write, 4 = group read-only, 0 = others none). · الأقل امتيازًا ليس دائمًا 600. فريقك يجب أن يقرا team-notes.txt، لكنه لا يغيّره — والمستخدمون الخارجيون يحصلون على شيء. استخدم chmod 640 team-notes.txt (6 = قراءة+كتابة للمالك، 4 = قراءة فقط للمجموعة، 0 = لا شيء للآخرين).