Re: getting login name in 4GL
Posted in 1996
Mike Segel wrote:
> In UNIX, the current username is stored in $LOGNAME. LOGNAME is a read
> only shell variable. I tested this for /bin/ksh and /bin/sh. You cannot
> change this variable, hence it should be considered reliable. LOGNAME
> represents the user name of the login account.
>
I tried it too, and just changed it to whatever I wanted. I spawned a
Bourne shell from a Korn shell, and the changed $LOGNAME came along with
it. I had done a "export LOGNAME=foofoo", and the new shell adopted
this new LOGNAME.
It still bugs me to use an environment variable, and to say you "can't"
change it is not 100% in UNIX. The UNIX I tested it on is 88/Open
Certified, but I guess that doesn't mean $LOGNAME is secure. So it remains
a weak link. But maybe on certain UNIX machines this doesn't happen.
When we finally get to the "unified" UNIX, maybe then I can trust it.
>>
> Informix, when the front end starts, gets the effective UID and user
> name.It does not use any
> of the shell variables. I just tested this. First I tried to change all
> the variables I could.
> Informix still picked my login name correctly.
>
OK. Good. I still don't trust it. :-)
> I then ran a setuid program I had written. This program changes the
> effective uid of the user and execs a shell.
>
I couldn't test this today, maybe next week.
> From the shell I called dbaccess and ran the SQL statement. It picked up
> the username of the user I set myself to. The variable $LOGNAME still
> represented me.
>
> So if you want the Login Name use $LOGNAME. If you want to see what the
> effective user id running your program, use the "global" username.
>
Cool. But test it on YOUR machine FIRST to see if it's secure.
> IMHO- I'd trust Informix on this one. (God. Imagine me saying that ;-)
> For you to do this, you would need to exec a shell, get the UID, then
> do a lookup against the passwd file.
>
Which is to say for security reasons, it's a possible weak link.
> All really simple C function calls, but you will have to write the
> runner, load and link it to your app. I'd say a select statement is
> much easier.
>
The bottom line is to test it as you've done, then proceed.
What platform did you run your tests on?
> -Mikey
> "Hey wadda ya expect? Another great tip from your uncle lou."
> #include<std.disclaimer.h>
--
\\\\|//
(6 6)
==============================---o00--(_)--00o---============================
Tim Schaefer tschaefe@encore.com tschaefe@shadow.net
Encore Computer Corp http://www.shadow.net/~tschaefe
=============================================================================