I am using users and groups to set permissions to my shared folders, which are accessed via Samba. Somehow, users that should not have access to certain folders can do it, despite of world read being disabled and that they don't belong to the folder's group.
Let's start with the problem. This is one of my folders:
folder /DataVolume/Public/Backup/
drwxr-x--- 14 Andre casa 4096 Aug 12 01:43 A organizar
drwxrwx--- 3 Andre familia 22 Aug 12 01:43 Antigo
drwxrwx--- 8 Andre casa 89 Aug 12 03:07 COBEL
drwxrwx--- 12 Andre familia 146 Aug 12 04:45 Dell Mimi
drwxrwx--- 2 arroyo familia 6 Sep 21 01:46 EE
drwx------ 6 Andre familia 4096 Aug 12 04:48 Inbev
drwxrwx--- 2 Andre familia 4096 Aug 12 04:49 Library B
drwxrwx--- 2 Andre familia 4096 Aug 12 04:49 Library C
drwx------ 188 Andre familia 12288 Sep 14 02:43 Mail
I am trying to access (via samba or just doing cd) folder "A organizar", using username "arroyo".
The user is not part of group "casa", and therefore should not be able to read such folder. But it does.
Some files:
passwd
(...)
admin:x:98:1000:administrator:/shares:/bin/sh
nobody:x:99:1000:nobody:/home:/bin/sh
nfsnobody:x:65534:65534:nfsnobody:/nfs:/bin/sh
jewab:x:500:1000:jewab:/home:/bin/sh
guest:x:501:501:Linux User,,,:/shares:/bin/sh
Andre:x:502:1001:Linux User,,,:/shares:/bin/sh
anarroyo:x:503:1000:Linux User,,,:/shares:/bin/sh
arroyo:x:504:1002:Linux User,,,:/shares:/bin/sh
Mimi:x:505:1001:Linux User,,,:/shares:/bin/sh
gistelinck:x:506:1002:Linux User,,,:/shares:/bin/sh
convidado:x:507:1003:Linux User,,,:/shares:/bin/sh
group
ftp:x:14:ftp
admin:x:98:admin
nobody:x:99:guest
users:x:100:
nfsnobody:x:65534:
jewab:x:1000:nobody
Andre:x:502:Andre
Mimi:x:505:Mimi
arroyo:x:504:arroyo
gistelinck:x:506:gistelinck
casa:x:1001:Andre,Mimi,admin
familia:x:1002:Andre,Mimi,arroyo,gistelinck,admin
convidado:x:507:convidado
convidados:x:1003:Andre,Mimi,arroyo,gistelinck,convidado,jewab,admin
/etc/vsftpd.share_acl
admin=:Public:Download:
Andre=:Public:Download:
anarroyo=:Public:Download:anarroyo:
arroyo=:Public:Download:
ftp=:Public:Download:
Mimi=:Public:Download:
convidado=:Public:
gistelinck=:Public:Download: