Some questions about file permissions.

Hi, what happens in these scenarios?

  1. You give no permissions to "others" on a directory, but in that directory the files have read permissions for "others", can they read the file?

  2. Are files with rwx attributes to "others" at risk of being copied or read on the system, even if you are the only physical user? (i am running a web server as well)

  3. Also when I type "ls -l" after I have changed some file permissions, why are there still some temp files with the old permissions?
    e.g:
    rwxrwx--- fileone.php
    rwxrwxrwx fileone.php~

Thanks

  1. No, because they can't get into the directory to access the file.
  2. If someone finds a vulnerability they can exploit on your system, then it increases the chances that they can overwrite your files. It's up to you to assess that risk based on the importance of the information in the files and whether or not modifying those files gives someone a way to access even further information on your system.
  3. I presume those backup files are created by your text editor? Strange that they are created with rwxrwxwrx, perhaps your umask is set to 000 instead of the usual 022?

For second point,
If you ought to give rwx permission to the file, then better add a sticky bit the directory which contains that file. So no one other than you can edit or delete the file.