Re: setuid question
Posted in 1999
On Thursday 26th August 1999, David Williams <djw@smooth1.demon.co.uk> wrote: >Art S. Kagel <kagel@bloomberg.net> writes: >>For security reasons you many want to make this >>a 'C' program that verifies the identity itself of the user running it and >>then, if the real user is authorized, runs the perl script. This is more >>secure and the DBAs will be able to just run the perl script directly >>since they have permissions already and the ordinary users will have to >>run the suid program to run the script for them. Perl supposedly checks for the secureness or otherwise of SUID scripts. You can do any validation in Perl that you can do in C. That said, one advantage of a C program is that it is more difficult to see what it is doing, which makes it harder to discover flaws and devise circumventions for the security system. >>While you're at it: Whenever I write one of these permission buster >>programs I ALWAYS have it log the real user and time of execution in a >>secure and inaccessible log file so I can bash heads when I need to >>and for CYA. Logging is a good idea, and is an omission in my own version of this. And, clearly, the program should decline to do anything if the log file is not accessible, or if it is too accessible (eg others can write to it, or if the containing directory is not secure). > I think I saw an article once about writing secure UNIX programs so > there more to this then just the above. I don't know whether it was this site, but this site certainly covers 'Writing Safe Setuid Programs'. It happened to cross my path y'day (in the context of SUID root security problems with Oracle 8 and 8i). http://olympus.cs.ucdavis.edu/~bishop/secprog.html Yours, Jonathan Leffler (jleffler@informix.com) #include <witticism.h> Guardian of DBD::Informix v0.60 (v0.61_02) -- http://www.perl.com/CPAN Informix IDN for D4GL & Linux -- http://www.informix.com/idn