oncheck -pP for users
Posted in 2000
Topics: Storage & Space Management, Server Administration, Platform-Specific Issues
Hi Family.
I'm working on another utility shell script. As part of the algorithm,
it invokes oncheck -pP - dump a page given the chunk and page number
(relative to the chunk). If I were to try running this as myself, I get
the message:
$ oncheck -pP 0x009 0x00024
Must be user informix to run this program.
Now I tried embedding this command in a shell script and set the "set-
uid" flags for it:
$ chown informix:informix myscript.sh
$ chmod 6755 myscript.sh
The classical result of this SHOULD be that the program/script can
access any file that is accssible by user informix because, for the
duration of the process, the effective user-id *is* informix. As I
have understood the process control system calls, if the process were
to run a getproc() call, the effective user-id returned would be
informix. However, the *real* user-id would still be lil' ol' me.
Result: my set-uid script fails when calling oncheck -pP.
Conlusion: oncheck is deliberately checking the real user-id instead of
the emminently more logical (IMHO) effective user-id.
Corrolary: Only user informix will be able to run this new script.
Impact: YAAARGHHHhhhhhh......!!!!
Can anyone come up with some unix chicanery that will get around this?
I am running on HP-UX 10.20 and 11.0
Thanks.
--
+----- Jacob Salomon - DBA JSalomon@bn.com - --------------------------+
|------------------- Bulletin Board Announcement ----------------------|
| Congregants will please note that the bowl at the back of the church |
| bearing the sign "For the Sick" is for monetary contributions only. |
+----------------------------------------------------------------------+
Sent via Deja.com http://www.deja.com/
Before you buy.
I don't think shell scripts can have the suid bits set ... only binaries. I
suppose you could set the suid flags for the oncheck executable.
--
Jay Aymond
Community Coffee
Jacob Salomon <JSalomon@bn.com> wrote in message
news:8i63ck$ebb$1@nnrp1.deja.com...
> Hi Family.
>
> I'm working on another utility shell script. As part of the algorithm,
> it invokes oncheck -pP - dump a page given the chunk and page number
> (relative to the chunk). If I were to try running this as myself, I get
> the message:
> $ oncheck -pP 0x009 0x00024>
> Must be user informix to run this program.
>
> Now I tried embedding this command in a shell script and set the "set-
> uid" flags for it:
> $ chown informix:informix myscript.sh
> $ chmod 6755 myscript.sh>
> The classical result of this SHOULD be that the program/script can
> access any file that is accssible by user informix because, for the
> duration of the process, the effective user-id *is* informix. As I
> have understood the process control system calls, if the process were
> to run a getproc() call, the effective user-id returned would be
> informix. However, the *real* user-id would still be lil' ol' me.
>
> Result: my set-uid script fails when calling oncheck -pP.
>
> Conlusion: oncheck is deliberately checking the real user-id instead of
> the emminently more logical (IMHO) effective user-id.
>
> Corrolary: Only user informix will be able to run this new script.
>
> Impact: YAAARGHHHhhhhhh......!!!!
>
> Can anyone come up with some unix chicanery that will get around this?
> I am running on HP-UX 10.20 and 11.0
>
> Thanks.
> --
> +----- Jacob Salomon - DBA JSalomon@bn.com - --------------------------+
> |------------------- Bulletin Board Announcement ----------------------|
> | Congregants will please note that the bowl at the back of the church |
> | bearing the sign "For the Sick" is for monetary contributions only. |
> +----------------------------------------------------------------------+
>
>
> Sent via Deja.com http://www.deja.com/
> Before you buy.
Hey Jake,
Note that some shells, bash in particular, do not support the SUID bit on
scripts for security reasons. If you are running bash, and other users
might as well, you may want to start the script with the header:
#! /usr/bin/ksh
or
#! /bin/sh
These shells 'usually' support SUID scripts.
Art S. Kagel
Jacob Salomon wrote:
>
> Hi Family.
>
> I'm working on another utility shell script. As part of the algorithm,
> it invokes oncheck -pP - dump a page given the chunk and page number
> (relative to the chunk). If I were to try running this as myself, I get
> the message:
> $ oncheck -pP 0x009 0x00024>
> Must be user informix to run this program.
>
> Now I tried embedding this command in a shell script and set the "set-
> uid" flags for it:
> $ chown informix:informix myscript.sh
> $ chmod 6755 myscript.sh>
> The classical result of this SHOULD be that the program/script can
> access any file that is accssible by user informix because, for the
> duration of the process, the effective user-id *is* informix. As I
> have understood the process control system calls, if the process were
> to run a getproc() call, the effective user-id returned would be
> informix. However, the *real* user-id would still be lil' ol' me.
>
> Result: my set-uid script fails when calling oncheck -pP.
>
> Conlusion: oncheck is deliberately checking the real user-id instead of
> the emminently more logical (IMHO) effective user-id.
>
> Corrolary: Only user informix will be able to run this new script.
>
> Impact: YAAARGHHHhhhhhh......!!!!
>
> Can anyone come up with some unix chicanery that will get around this?
> I am running on HP-UX 10.20 and 11.0
>
> Thanks.
> --
> +----- Jacob Salomon - DBA JSalomon@bn.com - --------------------------+
> |------------------- Bulletin Board Announcement ----------------------|
> | Congregants will please note that the bowl at the back of the church |
> | bearing the sign "For the Sick" is for monetary contributions only. |
> +----------------------------------------------------------------------+
>
> Sent via Deja.com http://www.deja.com/
> Before you buy.