Re: Executing Esql-C pgm
Posted in 1997
On Tue, 21 Oct 1997 saabtoo@aol.com wrote: > I have run into an unusual problem that I could use some help with. We > are executing an Esql-C program on our Sun Sparc 2000 server (OS 2.5.1) > from an informix stored procedure (Online 7.20). OK so far. > This Esql-C program contains code that issues commands on a remote Sun > server using rsh. That's going to be tricky; the user of the SP will have to have rsh privileges on the remote machine, of course. That tends to mean either you will need .rhost files in everyone's home directory (or /etc/hosts.equiv on each machine), with consequential loose security problems. > For these commands to work we must set the permission on the executable > of to the "setuid" bit (ie "rwsrwxrwx" pgm_name). Never, ever, have a SUID program writable by anyone other than the owner! I can write what ever I like over your program, and become the relevant user. Eg, I could copy /bin/ksh over your program, and then I'm in as the owner of the program. Always ensure that the code is rwsr-xr-x at most; group and others do not need read permissions, and most of the time neither does the owner (once the program is stable), so --s--x--x is a good set of permissions to use; I tend to want to read stuff so I use r-s--x--x. If others don't need to run the program (only group members), then don't let them run it. The other point is to ensure that the directory containing the program is secure; ultimately, you need all the directories leading to the program to be secure else a hacker can work their evil. That's basic SUID program writing security. Which user ID is is SUID to? root? I sincerely hope not! But I rather suspect it is... > But when the stored procedure that calls the esql-c program is run, the > system call fails with -668 sqlcode, -172 isam error. When I do 'finderr -172', it says that there should be some information in the OnLine log file; what does yours have to say? > When we set the permission to "rwxrwxrwx" the esql-c program runs but the > "rsh" commands fail. This is why the info in the OnLine log file should be helpful. I suspect that your program is SUID root and linked with shared libraries. On many machines (eg SVR4 based machines), SUID root programs do not look for shared libraries using LD_LIBRARY_PATH -- they only look in /usr/lib (or, perhaps, in directories specified with the -R option on the linker line). Try relinking the program with static libraries (esql -static), or adding -R$INFORMIXDIR/lib -R$INFORMIXDIR/lib/esql to the command line. When it is not SUID root, then the libraries are found, but the setuid() calls made to allow the rsh commands to work fail -- why isn't the program diagnosing these errors. I may be maligning your code unwarrantedly here -- it may be that it is all SUID programs which do not look for shared libraries with LD_LIBRARY_PATH (because the malicious intruder could set their LD_LIBRARY_PATH to include their own library ahead of the intended library), and that is all that is the trouble. Yours, Jonathan Leffler (johnl@informix.com) #include <witticism.h>