How unit 4 is examined
This unit covers viewing, scheduling, prioritising and killing Unix processes, then system security: physical and login control, file permissions, ACLs, FTP, root access and TCP wrappers. No topic has been asked recently, so every topic is short but complete.
Viewing a Process
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. A process is a program in execution, and viewing a process means listing the running processes with their details.
Key points.
- Every process has a unique process ID (PID) that the kernel assigns when it starts.
- Viewing shows who owns each process, how much CPU and memory it uses, and its state.
- The main viewing tools are
ps,pgrep,topandprstat. - <mark>A process is a running instance of a program, and
psgives a snapshot of it.</mark>
Command to display Process
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. The ps command prints a snapshot of the current processes, and top shows a live, refreshing list.
Key points.
- Plain
pslists only the processes of your own terminal session. ps -eflists every process in full format, andps auxgives the BSD-style listing with CPU and memory.toprefreshes every few seconds and sorts by CPU use, so heavy processes show at the top.- <mark>
psis a one-time snapshot, whereastopis continuous.</mark>
Process Attributes
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Process attributes are the properties the kernel stores for every process.
Key points.
- PID is the unique process number, and PPID is the PID of the parent that created it.
- UID and GID record the owner and group, which decide the process's access rights.
- Priority (nice value), the controlling terminal (TTY) and the current working directory are also stored.
- <mark>Every process has a PID, a PPID, an owner and a priority.</mark>
Process States
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. A process state shows what the process is doing at that moment.
Key points.
- Running (R) means the process is executing or ready to execute on the CPU.
- Sleeping (S) means it is waiting for an event such as input, and stopped (T) means it was suspended by a signal.
- Zombie (Z) means the process has finished but its parent has not yet read its exit status.
- <mark>A zombie is a dead process whose entry stays in the table until the parent collects it.</mark>
Process Fields
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Process fields are the columns that ps prints for each process.
Key points.
- UID is the owner, PID the process ID, PPID the parent ID, and C the recent CPU usage.
- STIME (or START) is the start time, TTY the terminal, and TIME the CPU time used so far.
- CMD (or COMD) is the command that started the process.
- The long listing
ps -ladds S (state), PRI (priority), NI (nice value), SZ (size) and WCHAN (what it waits on). - <mark>The key fields are UID, PID, PPID, C, STIME, TTY, TIME and CMD.</mark>
PS Commands options
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Options of ps select which processes are shown and how much detail is printed.
Key points.
ps -elists every process on the system, andps -fgives the full format.ps -efcombines them and is the standard listing;ps -lgives the long format.ps -u userlists the processes of one user, andps -p PIDshows one process.ps auxis the BSD form that shows all users with %CPU and %MEM.- <mark>
ps -efis the usual command to see every process in full format.</mark>
PGREP
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. pgrep searches the running processes by name or other attribute and prints the matching PIDs.
Key points.
- The syntax is
pgrep pattern, for examplepgrep sshd, and it replacesps -ef | grep. -lalso prints the process name,-u userrestricts the match to one user, and-xneeds an exact name.-nreturns only the newest match and-oonly the oldest.- <mark>
pgrepreturns PIDs directly, so its output can be passed tokill.</mark>
PRSTAT
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. prstat is the Solaris command that reports statistics of the active processes and refreshes them repeatedly.
Key points.
- It shows PID, USERNAME, SIZE, RSS, STATE, PRI, NICE, TIME, CPU and PROCESS for each process.
- The list is sorted by CPU usage by default, and the display refreshes every 5 seconds.
-uselects users,-sand-Ssort the output, and-nlimits the number of lines.- <mark>
prstatis the Solaris counterpart of the Linuxtopcommand.</mark>
CDE Process Manager
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. The CDE Process Manager is a graphical tool of the Solaris Common Desktop Environment for viewing and stopping processes.
Key points.
- It is opened from the Application Manager under the Desktop Tools folder.
- It lists processes with their PID, owner, CPU and memory in a window that can be sorted.
- A process is selected in the list and killed with the Kill option in the menu.
- <mark>It does with the mouse what
psandkilldo on the command line.</mark>
Scheduling Process
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Scheduling a process means arranging for a command to run automatically at a later time or at regular intervals.
Key points.
atruns a job once at a stated time, for exampleat 10pm, andatqlists the waiting jobs.cronruns jobs repeatedly, and each user keeps a table edited withcrontab -e.- A crontab line has five time fields, minute, hour, day of month, month and weekday, followed by the command.
/etc/cron.allowand/etc/cron.denycontrol who may use cron.- <mark>
atruns a job once andcronruns it repeatedly.</mark>
Scheduling Priorities
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. A scheduling priority decides which process gets the CPU first, and the nice value is the user-set part of it.
Key points.
- In Linux the nice value runs from -20 (highest priority) to 19 (lowest), and the default is 0.
- A higher nice value means the process is "nicer" to others and gets less CPU.
- Ordinary users can only raise the nice value, whereas root can also lower it.
- <mark>A lower nice number means a higher priority.</mark>
Changing the Priority of a time-sharing process
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. nice starts a command with a chosen nice value, and renice changes the value of a process that is already running.
Key points.
nice -n 10 commandstarts the command with 10 added to its nice value.renice -n 5 -p PIDchanges the running process with that PID.renicecan also act on all processes of a user with-u.- Only root may give a negative value, because that raises priority.
- <mark>
nicesets the priority at start, andrenicechanges it later.</mark>
Killing Process
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Killing a process means sending it a signal so that it terminates, using the kill command.
Key points.
- The syntax is
kill -signal PID, and the default signal is SIGTERM (15), which asks the process to exit cleanly. kill -9 PIDsends SIGKILL, which cannot be caught or ignored, so it is the last resort.- SIGHUP (1) tells a daemon to reread its configuration, and SIGINT (2) is Ctrl+C.
pkill nameandkillall namekill by name instead of PID.- <mark>
kill -9forces termination because SIGKILL cannot be ignored.</mark>
Physical Security
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Physical security is protection of the computer hardware itself from theft, damage and unauthorised access.
Key points.
- Servers are kept in locked rooms that only authorised staff can enter.
- A firmware or boot-loader password stops a person with physical access from booting a different system.
- Screen locks, cable locks and CCTV protect the machine, and backups are stored in a safe, separate place.
- <mark>Without physical security, all software security can be bypassed.</mark>
Controlling System Access
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Controlling system access means allowing only valid users to log in and limiting what they can do.
Key points.
- Every user has a login name and a password stored in encrypted form in
/etc/shadow. - Password ageing, minimum length and account locking after failed attempts make passwords stronger.
- Unused accounts are deleted or locked, and no account may be left without a password.
/etc/nologinblocks ordinary logins during maintenance.- <mark>Access is controlled by valid user accounts with strong, ageing passwords.</mark>
Restricted Shells Controlling File Access
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. A restricted shell is a shell with limited abilities, such as rsh on Solaris or rbash (bash -r) on Linux.
Key points.
- The user cannot change directory with
cd. - The user cannot change
PATHorSHELL, and cannot run a command that contains a slash. - Output redirection with
>is not allowed. - It is set as the login shell of guests and untrusted users.
- <mark>A restricted shell keeps the user inside a fixed set of commands and directories.</mark>
File Access Commands
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. File access commands set who owns a file and what the owner, group and others may do with it.
Key points.
chmodchanges permissions in symbolic form (chmod u+x file) or octal form (chmod 754 file), where r=4, w=2 and x=1.chown user filechanges the owner, andchgrp group filechanges the group.ls -lshows the ten-character mode, andumasksets the default permissions of new files.- <mark>
chmod 754gives rwx to the owner, r-x to the group and r-- to others.</mark>
Access Control List(ACLs)
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. An ACL is a list attached to a file that gives permissions to specific users and groups beyond the owner, group and others.
Key points.
- Ordinary permissions allow only one owner and one group, and ACLs remove this limit.
getfacl filedisplays the ACL entries.setfaclsets, changes or removes them, andls -lshows a plus sign (+) after the mode when a file has an ACL.- <mark>An ACL gives file permission to any named user or group.</mark>
Setting ACL Entries
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Setting an ACL entry adds a permission for a user or group to a file with setfacl -m.
Key points.
- The syntax is
setfacl -m user:ravi:rw- file, and for a groupsetfacl -m group:staff:r-- file. - Solaris also allows
setfacl -sto set the whole list at once. - The
maskentry limits the maximum rights of all named users and groups. - <mark>
setfacl -m user:name:perm fileadds an entry for a named user.</mark>
Modifying ACL entries on a file
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Modifying an ACL entry changes the permissions of an entry that already exists.
Key points.
- The same command is used,
setfacl -m user:ravi:r-- file, and the new permission replaces the old. - Several entries can be changed in one command by separating them with commas.
getfacl fileshould be run afterwards to confirm the change.- <mark>Modification uses
setfacl -magain with the new permissions.</mark>
Deleting ACL entries on a file
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Deleting an ACL entry removes one user or group entry from a file.
Key points.
- In Linux
setfacl -x user:ravi fileremoves one entry. setfacl -b fileremoves all ACL entries and leaves the ordinary permissions.- On Solaris the delete option is
setfacl -d user:ravi file. - <mark>
setfacl -xdeletes one entry andsetfacl -bdeletes them all.</mark>
Restricting FTP
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Restricting FTP means limiting which users may connect and what they can reach on the FTP server.
Key points.
- Names listed in the
ftpusersfile (/etc/ftpusersor/etc/ftpd/ftpusers) are denied FTP login, and root and system accounts must be listed. - Users can be confined to their home directory with a chroot setting, for example
chroot_local_user=YESin vsftpd. - Anonymous FTP is disabled unless it is really needed.
- <mark>Listing a user in
ftpusersbars that user from FTP.</mark>
Securing Super User Access
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Securing super user access means protecting the root account, which has unlimited power over the system.
Key points.
- Root must have a strong password, and it should be shared with very few people.
sudolets chosen users run chosen commands as root, as listed in/etc/sudoers, which is edited withvisudo.- Each
sudouse is logged, and users type their own password, not the root password. - <mark>Give users only the root commands they need, using sudo.</mark>
Restricting Root Access
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Restricting root access means stopping root from logging in directly from insecure places.
Key points.
- On Solaris, the line
CONSOLE=/dev/consolein/etc/default/loginallows root login only on the console. - In Linux SSH,
PermitRootLogin noin/etc/ssh/sshd_configblocks remote root login. - Users log in with their own accounts and use
suorsudoafterwards, so actions can be traced. - <mark>Root can log in only on the console; everyone else uses su or sudo.</mark>
Monitoring super user Access
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. Monitoring super user access means keeping a record of who became root and when.
Key points.
- Solaris writes every
suattempt to/var/adm/sulog, marked + for success and - for failure. - Linux records
suandsudouse in/var/log/auth.log(or/var/log/secure). lastandlastbshow successful and failed logins.- Logs are checked regularly to detect misuse early.
- <mark>
sulogandauth.logshow who used root and whether it succeeded.</mark>
TCP Wrappers
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. TCP wrappers control which hosts may use network services, using rules in /etc/hosts.allow and /etc/hosts.deny.
Key points.
- The wrapper daemon
tcpdchecks the client address before it starts a service. hosts.allowis read first, thenhosts.deny, and the first matching rule wins.- A rule has the form
service : client, for examplesshd : 192.168.1.in allow andALL : ALLin deny. - If no rule matches, access is allowed.
- <mark>Allow specific hosts in
hosts.allowand deny everyone else inhosts.deny.</mark>
Last-minute revision
- PID is the unique process ID, and PPID is the parent's PID.
- Process states are running, sleeping, stopped and zombie.
ps -efshows all processes in full format, andps auxis the BSD style.pgrepprints PIDs by name, andprstatis the Solaristop.atruns a job once, andcronruns it repeatedly with five time fields.- Linux nice runs from -20 to 19, default 0, and only root can lower it.
kill -9sends SIGKILL, and the defaultkillsends SIGTERM (15).chmod 754means rwx for owner, r-x for group and r-- for others.setfacl -msets or modifies,setfacl -xdeletes, andgetfacldisplays.PermitRootLogin noandCONSOLE=/dev/consolerestrict root login.hosts.allowis checked beforehosts.deny.
Memory hooks
- Zombie means dead but not collected, because the parent has not called wait.
- Nice means kind, so a higher nice number gives away CPU and the priority is lower.
- SIGKILL is number 9, "nine lives, none left".
-mmodifies,-xxes out,-bblanks the whole ACL.- Allow is read first, and deny is the safety net after it.
Coverage checklist
- Viewing a Process: no past questions (definition and tools covered).
- Command to display Process: no past questions.
- Process Attributes: no past questions.
- Process States: no past questions.
- Process Fields: no past questions.
- PS Commands options: no past questions.
- PGREP: no past questions.
- PRSTAT: no past questions.
- CDE Process Manager: no past questions.
- Scheduling Process: no past questions.
- Scheduling Priorities: no past questions.
- Changing the Priority of a time-sharing process: no past questions.
- Killing Process: no past questions.
- Physical Security: no past questions.
- Controlling System Access: no past questions.
- Restricted Shells Controlling File Access: no past questions.
- File Access Commands: no past questions.
- Access Control List(ACLs): no past questions.
- Setting ACL Entries: no past questions.
- Modifying ACL entries on a file: no past questions.
- Deleting ACL entries on a file: no past questions.
- Restricting FTP: no past questions.
- Securing Super User Access: no past questions.
- Restricting Root Access: no past questions.
- Monitoring super user Access: no past questions.
- TCP Wrappers: no past questions.