Bugtraq mailing list archives
Re: setuid scripts in SunOS 4.1.x
From: jhawk () panix com (John Hawkinson)
Date: Wed, 28 Sep 1994 01:02:48 -0400 (EDT)
Well, now that I've been trounced upon by several of you folks, ;-) I realize that that by 'fixing the kernel' I was (mistakenly) assuming that what was meant was 'disable set-uid interpreter scripts'. It was disabling them entirely that I disagree with. Yes, I am aware of the race condition with such scripts, and agree that it needs to be solved before such scripts have any hope of being considered 'safe'.
Excuse me? When we say FIXING THE KERNEL, we MEAN DISABLING SETUID SCRIPTS. If you have some other reasonable mechanism, I'd be interested in hearing it...
While we're on the subject: What should happen if you have a set-uid interpreter script and the interpreter it invokes is also set-uid to a different uid? This is a philosophical point, so I suppose the discussion should be moved to some other list or newsgroup.
Well, under SunOS 4.1.3, which was the OS in question, it keeps the uid/gid of the script, not the interpreter. This is arguably more consistent than taking the uid & gid of the interpreter. -- John Hawkinson jhawk () panix com
Current thread:
- Re: setuid scripts in SunOS 4.1.x, (continued)
- Re: setuid scripts in SunOS 4.1.x Peter Jeremy (Sep 22)
- Re: setuid scripts in SunOS 4.1.x Colin Campbell (Sep 23)
- Re: setuid scripts in SunOS 4.1.x John Hawkinson (Sep 22)
- Re: setuid scripts in SunOS 4.1.x Karl Strickland (Sep 24)
- Re: setuid scripts in SunOS 4.1.x Fred Blonder (Sep 26)
- Re: setuid scripts in SunOS 4.1.x John Hawkinson (Sep 26)
- Re: setuid scripts in SunOS 4.1.x Harold van Aalderen (Sep 27)
- Re: setuid scripts in SunOS 4.1.x Rafi Sadowsky (Sep 27)
- Re: setuid scripts in SunOS 4.1.x Paul O'Donnell (Sep 27)
- Re: setuid scripts in SunOS 4.1.x Fred Blonder (Sep 27)
- Re: setuid scripts in SunOS 4.1.x John Hawkinson (Sep 27)
- Re: setuid scripts in SunOS 4.1.x Valdis.Kletnieks () vt edu (Apr 17)
- Re: setuid scripts in SunOS 4.1.x jmc () gnu ai mit edu (Sep 28)
- request Michel JACQUOT (Sep 29)
- Re: setuid scripts in SunOS 4.1.x Fred Blonder (Sep 28)
- Re: setuid scripts in SunOS 4.1.x John Hawkinson (Sep 28)
- Re: setuid scripts in SunOS 4.1.x John Hawkinson (Sep 22)
- Security Info (root broken) Pat Myrto (Sep 28)
- Re: Security Info (root broken) Valdis.Kletnieks () vt edu (Apr 18)
- Re: Security Info (root broken) Perry E. Metzger (Sep 28)
- Re: Security Info (root broken) pluvius (Sep 28)
- Re: Security Info (root broken) Charles R. Hoynowski (Sep 29)