Re: setuid question
Posted in 1999
In article <37C2FA9F.A129D618@bloomberg.net>, Art S. Kagel <kagel@bloomberg.net> writes >the script to become. For security reasons you many want to make this >a 'C' program that verifies the identity itself of the user running it and >then, if the real user is authorized, runs the perl script. This is more >secure and the DBAs will be able to just run the perl script directly >since they have permissions already and the ordinary users will have to >run the suid program to run the script for them. While you're at it: >Whenever I write one of these permission buster programs I ALWAYS have it >log the real user and time of execution in a secure and inaccessible log >file so I can bash heads when I need to and for CYA. > True, I had to write one of these once (setuid root!). I statically linked it - no loading shared libraries like libc.so at runtime and did if getuid() = <required value> { do stuff.. } This should mean a) Since only getuid() is used there is no need to look at passed files,NIS maps etc. to convert the username to a uid. Only the relevant entry in the process table needs to examined i.e. no reliance on external files. b) getuid not geteuid so no su-ing before hand. I think I saw an article once about writing secure UNIX programs so there more to this then just the above. >Art S. Kagel > -- David Williams