Skip to content
CS-505 · Linux (LAB)/Quick Revision Short Notes

Linux (LAB) (CS-505) - Unit 4 Short Notes

How unit 4 is examined

This unit covers viewing, scheduling, prioritising and killing Unix processes, then system security: physical and login control, file permissions, ACLs, FTP, root access and TCP wrappers. No topic has been asked recently, so every topic is short but complete.

Viewing a Process

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. A process is a program in execution, and viewing a process means listing the running processes with their details.

Key points.

  1. Every process has a unique process ID (PID) that the kernel assigns when it starts.
  2. Viewing shows who owns each process, how much CPU and memory it uses, and its state.
  3. The main viewing tools are ps, pgrep, top and prstat.
  4. <mark>A process is a running instance of a program, and ps gives a snapshot of it.</mark>

Command to display Process

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. The ps command prints a snapshot of the current processes, and top shows a live, refreshing list.

Key points.

  1. Plain ps lists only the processes of your own terminal session.
  2. ps -ef lists every process in full format, and ps aux gives the BSD-style listing with CPU and memory.
  3. top refreshes every few seconds and sorts by CPU use, so heavy processes show at the top.
  4. <mark>ps is a one-time snapshot, whereas top is continuous.</mark>

Process Attributes

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Process attributes are the properties the kernel stores for every process.

Key points.

  1. PID is the unique process number, and PPID is the PID of the parent that created it.
  2. UID and GID record the owner and group, which decide the process's access rights.
  3. Priority (nice value), the controlling terminal (TTY) and the current working directory are also stored.
  4. <mark>Every process has a PID, a PPID, an owner and a priority.</mark>

Process States

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. A process state shows what the process is doing at that moment.

Key points.

  1. Running (R) means the process is executing or ready to execute on the CPU.
  2. Sleeping (S) means it is waiting for an event such as input, and stopped (T) means it was suspended by a signal.
  3. Zombie (Z) means the process has finished but its parent has not yet read its exit status.
  4. <mark>A zombie is a dead process whose entry stays in the table until the parent collects it.</mark>

Process Fields

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Process fields are the columns that ps prints for each process.

Key points.

  1. UID is the owner, PID the process ID, PPID the parent ID, and C the recent CPU usage.
  2. STIME (or START) is the start time, TTY the terminal, and TIME the CPU time used so far.
  3. CMD (or COMD) is the command that started the process.
  4. The long listing ps -l adds S (state), PRI (priority), NI (nice value), SZ (size) and WCHAN (what it waits on).
  5. <mark>The key fields are UID, PID, PPID, C, STIME, TTY, TIME and CMD.</mark>

PS Commands options

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Options of ps select which processes are shown and how much detail is printed.

Key points.

  1. ps -e lists every process on the system, and ps -f gives the full format.
  2. ps -ef combines them and is the standard listing; ps -l gives the long format.
  3. ps -u user lists the processes of one user, and ps -p PID shows one process.
  4. ps aux is the BSD form that shows all users with %CPU and %MEM.
  5. <mark>ps -ef is the usual command to see every process in full format.</mark>

PGREP

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. pgrep searches the running processes by name or other attribute and prints the matching PIDs.

Key points.

  1. The syntax is pgrep pattern, for example pgrep sshd, and it replaces ps -ef | grep.
  2. -l also prints the process name, -u user restricts the match to one user, and -x needs an exact name.
  3. -n returns only the newest match and -o only the oldest.
  4. <mark>pgrep returns PIDs directly, so its output can be passed to kill.</mark>

PRSTAT

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. prstat is the Solaris command that reports statistics of the active processes and refreshes them repeatedly.

Key points.

  1. It shows PID, USERNAME, SIZE, RSS, STATE, PRI, NICE, TIME, CPU and PROCESS for each process.
  2. The list is sorted by CPU usage by default, and the display refreshes every 5 seconds.
  3. -u selects users, -s and -S sort the output, and -n limits the number of lines.
  4. <mark>prstat is the Solaris counterpart of the Linux top command.</mark>

CDE Process Manager

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. The CDE Process Manager is a graphical tool of the Solaris Common Desktop Environment for viewing and stopping processes.

Key points.

  1. It is opened from the Application Manager under the Desktop Tools folder.
  2. It lists processes with their PID, owner, CPU and memory in a window that can be sorted.
  3. A process is selected in the list and killed with the Kill option in the menu.
  4. <mark>It does with the mouse what ps and kill do on the command line.</mark>

Scheduling Process

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Scheduling a process means arranging for a command to run automatically at a later time or at regular intervals.

Key points.

  1. at runs a job once at a stated time, for example at 10pm, and atq lists the waiting jobs.
  2. cron runs jobs repeatedly, and each user keeps a table edited with crontab -e.
  3. A crontab line has five time fields, minute, hour, day of month, month and weekday, followed by the command.
  4. /etc/cron.allow and /etc/cron.deny control who may use cron.
  5. <mark>at runs a job once and cron runs it repeatedly.</mark>

Scheduling Priorities

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. A scheduling priority decides which process gets the CPU first, and the nice value is the user-set part of it.

Key points.

  1. In Linux the nice value runs from -20 (highest priority) to 19 (lowest), and the default is 0.
  2. A higher nice value means the process is "nicer" to others and gets less CPU.
  3. Ordinary users can only raise the nice value, whereas root can also lower it.
  4. <mark>A lower nice number means a higher priority.</mark>

Changing the Priority of a time-sharing process

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. nice starts a command with a chosen nice value, and renice changes the value of a process that is already running.

Key points.

  1. nice -n 10 command starts the command with 10 added to its nice value.
  2. renice -n 5 -p PID changes the running process with that PID.
  3. renice can also act on all processes of a user with -u.
  4. Only root may give a negative value, because that raises priority.
  5. <mark>nice sets the priority at start, and renice changes it later.</mark>

Killing Process

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Killing a process means sending it a signal so that it terminates, using the kill command.

Key points.

  1. The syntax is kill -signal PID, and the default signal is SIGTERM (15), which asks the process to exit cleanly.
  2. kill -9 PID sends SIGKILL, which cannot be caught or ignored, so it is the last resort.
  3. SIGHUP (1) tells a daemon to reread its configuration, and SIGINT (2) is Ctrl+C.
  4. pkill name and killall name kill by name instead of PID.
  5. <mark>kill -9 forces termination because SIGKILL cannot be ignored.</mark>

Physical Security

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Physical security is protection of the computer hardware itself from theft, damage and unauthorised access.

Key points.

  1. Servers are kept in locked rooms that only authorised staff can enter.
  2. A firmware or boot-loader password stops a person with physical access from booting a different system.
  3. Screen locks, cable locks and CCTV protect the machine, and backups are stored in a safe, separate place.
  4. <mark>Without physical security, all software security can be bypassed.</mark>

Controlling System Access

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Controlling system access means allowing only valid users to log in and limiting what they can do.

Key points.

  1. Every user has a login name and a password stored in encrypted form in /etc/shadow.
  2. Password ageing, minimum length and account locking after failed attempts make passwords stronger.
  3. Unused accounts are deleted or locked, and no account may be left without a password.
  4. /etc/nologin blocks ordinary logins during maintenance.
  5. <mark>Access is controlled by valid user accounts with strong, ageing passwords.</mark>

Restricted Shells Controlling File Access

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. A restricted shell is a shell with limited abilities, such as rsh on Solaris or rbash (bash -r) on Linux.

Key points.

  1. The user cannot change directory with cd.
  2. The user cannot change PATH or SHELL, and cannot run a command that contains a slash.
  3. Output redirection with > is not allowed.
  4. It is set as the login shell of guests and untrusted users.
  5. <mark>A restricted shell keeps the user inside a fixed set of commands and directories.</mark>

File Access Commands

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. File access commands set who owns a file and what the owner, group and others may do with it.

Key points.

  1. chmod changes permissions in symbolic form (chmod u+x file) or octal form (chmod 754 file), where r=4, w=2 and x=1.
  2. chown user file changes the owner, and chgrp group file changes the group.
  3. ls -l shows the ten-character mode, and umask sets the default permissions of new files.
  4. <mark>chmod 754 gives rwx to the owner, r-x to the group and r-- to others.</mark>

Access Control List(ACLs)

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. An ACL is a list attached to a file that gives permissions to specific users and groups beyond the owner, group and others.

Key points.

  1. Ordinary permissions allow only one owner and one group, and ACLs remove this limit.
  2. getfacl file displays the ACL entries.
  3. setfacl sets, changes or removes them, and ls -l shows a plus sign (+) after the mode when a file has an ACL.
  4. <mark>An ACL gives file permission to any named user or group.</mark>

Setting ACL Entries

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Setting an ACL entry adds a permission for a user or group to a file with setfacl -m.

Key points.

  1. The syntax is setfacl -m user:ravi:rw- file, and for a group setfacl -m group:staff:r-- file.
  2. Solaris also allows setfacl -s to set the whole list at once.
  3. The mask entry limits the maximum rights of all named users and groups.
  4. <mark>setfacl -m user:name:perm file adds an entry for a named user.</mark>

Modifying ACL entries on a file

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Modifying an ACL entry changes the permissions of an entry that already exists.

Key points.

  1. The same command is used, setfacl -m user:ravi:r-- file, and the new permission replaces the old.
  2. Several entries can be changed in one command by separating them with commas.
  3. getfacl file should be run afterwards to confirm the change.
  4. <mark>Modification uses setfacl -m again with the new permissions.</mark>

Deleting ACL entries on a file

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Deleting an ACL entry removes one user or group entry from a file.

Key points.

  1. In Linux setfacl -x user:ravi file removes one entry.
  2. setfacl -b file removes all ACL entries and leaves the ordinary permissions.
  3. On Solaris the delete option is setfacl -d user:ravi file.
  4. <mark>setfacl -x deletes one entry and setfacl -b deletes them all.</mark>

Restricting FTP

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Restricting FTP means limiting which users may connect and what they can reach on the FTP server.

Key points.

  1. Names listed in the ftpusers file (/etc/ftpusers or /etc/ftpd/ftpusers) are denied FTP login, and root and system accounts must be listed.
  2. Users can be confined to their home directory with a chroot setting, for example chroot_local_user=YES in vsftpd.
  3. Anonymous FTP is disabled unless it is really needed.
  4. <mark>Listing a user in ftpusers bars that user from FTP.</mark>

Securing Super User Access

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Securing super user access means protecting the root account, which has unlimited power over the system.

Key points.

  1. Root must have a strong password, and it should be shared with very few people.
  2. sudo lets chosen users run chosen commands as root, as listed in /etc/sudoers, which is edited with visudo.
  3. Each sudo use is logged, and users type their own password, not the root password.
  4. <mark>Give users only the root commands they need, using sudo.</mark>

Restricting Root Access

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Restricting root access means stopping root from logging in directly from insecure places.

Key points.

  1. On Solaris, the line CONSOLE=/dev/console in /etc/default/login allows root login only on the console.
  2. In Linux SSH, PermitRootLogin no in /etc/ssh/sshd_config blocks remote root login.
  3. Users log in with their own accounts and use su or sudo afterwards, so actions can be traced.
  4. <mark>Root can log in only on the console; everyone else uses su or sudo.</mark>

Monitoring super user Access

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. Monitoring super user access means keeping a record of who became root and when.

Key points.

  1. Solaris writes every su attempt to /var/adm/sulog, marked + for success and - for failure.
  2. Linux records su and sudo use in /var/log/auth.log (or /var/log/secure).
  3. last and lastb show successful and failed logins.
  4. Logs are checked regularly to detect misuse early.
  5. <mark>sulog and auth.log show who used root and whether it succeeded.</mark>

TCP Wrappers

<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>

Definition. TCP wrappers control which hosts may use network services, using rules in /etc/hosts.allow and /etc/hosts.deny.

Key points.

  1. The wrapper daemon tcpd checks the client address before it starts a service.
  2. hosts.allow is read first, then hosts.deny, and the first matching rule wins.
  3. A rule has the form service : client, for example sshd : 192.168.1. in allow and ALL : ALL in deny.
  4. If no rule matches, access is allowed.
  5. <mark>Allow specific hosts in hosts.allow and deny everyone else in hosts.deny.</mark>

Last-minute revision

  • PID is the unique process ID, and PPID is the parent's PID.
  • Process states are running, sleeping, stopped and zombie.
  • ps -ef shows all processes in full format, and ps aux is the BSD style.
  • pgrep prints PIDs by name, and prstat is the Solaris top.
  • at runs a job once, and cron runs it repeatedly with five time fields.
  • Linux nice runs from -20 to 19, default 0, and only root can lower it.
  • kill -9 sends SIGKILL, and the default kill sends SIGTERM (15).
  • chmod 754 means rwx for owner, r-x for group and r-- for others.
  • setfacl -m sets or modifies, setfacl -x deletes, and getfacl displays.
  • PermitRootLogin no and CONSOLE=/dev/console restrict root login.
  • hosts.allow is checked before hosts.deny.

Memory hooks

  • Zombie means dead but not collected, because the parent has not called wait.
  • Nice means kind, so a higher nice number gives away CPU and the priority is lower.
  • SIGKILL is number 9, "nine lives, none left".
  • -m modifies, -x xes out, -b blanks the whole ACL.
  • Allow is read first, and deny is the safety net after it.

Coverage checklist

  • Viewing a Process: no past questions (definition and tools covered).
  • Command to display Process: no past questions.
  • Process Attributes: no past questions.
  • Process States: no past questions.
  • Process Fields: no past questions.
  • PS Commands options: no past questions.
  • PGREP: no past questions.
  • PRSTAT: no past questions.
  • CDE Process Manager: no past questions.
  • Scheduling Process: no past questions.
  • Scheduling Priorities: no past questions.
  • Changing the Priority of a time-sharing process: no past questions.
  • Killing Process: no past questions.
  • Physical Security: no past questions.
  • Controlling System Access: no past questions.
  • Restricted Shells Controlling File Access: no past questions.
  • File Access Commands: no past questions.
  • Access Control List(ACLs): no past questions.
  • Setting ACL Entries: no past questions.
  • Modifying ACL entries on a file: no past questions.
  • Deleting ACL entries on a file: no past questions.
  • Restricting FTP: no past questions.
  • Securing Super User Access: no past questions.
  • Restricting Root Access: no past questions.
  • Monitoring super user Access: no past questions.
  • TCP Wrappers: no past questions.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in