Re: Executing Esql-C pgm
Posted in 1997
On Thu, 23 Oct 1997, David Williams wrote:
> Jonathan Leffler <johnl@informix.com> wrote:
> >On Tue, 21 Oct 1997 saabtoo@aol.com wrote:
> >> I have run into an unusual problem that I could use some help with. [...]
> >> For these commands to work we must set the permission on the executable
> >> of to the "setuid" bit (ie "rwsrwxrwx" pgm_name).
> >
> >Never, ever, have a SUID program writable by anyone other than the owner!
> >I can write what ever I like over your program, and become the relevant
> >user. Eg, I could copy /bin/ksh over your program, and then I'm in as the
> >owner of the program. Always ensure that the code is rwsr-xr-x at most;
>
> No, unless you are root, setuid and set group id bits are REMOVED when
> a file is written to! This happens on most version of UNIX!
I started out by writing:
I don't know what your definition of 'most version (sic) of UNIX' is,
but, as a for instance, it excludes Solaris 2.5.1:
$ asroot su informix -c "cp /dev/null junk; chmod 4777 junk"
$ ls -l junk -rwsrwxrwx 1 informix informix 0 Oct 23 08:54 junk
$ cp /dev/null junk
$ ls -l junk -rwsrwxrwx 1 informix informix 0 Oct 23 08:55 junk
$
It also excludes any system I've ever worked on (HP-UX up to 9, AIX
3.x, SCO Xenix or Unix, AT&T SVR3, ICL PNX (Version 7, System III),
etc) and experimented with such issues. I probably didn't do the
experiments on all the machines, though.
Fortunately, I extended my experimentation to copy /bin/sh over junk, and
the SUID bit got reset as David said. Truss shows that junk was opened,
but when zero bytes were read from /dev/null, it was never written to.
Using /bin/sh instead, of course, meant that data was written, and the SUID
permission bit is reset. I live, I learn (though I'd still prefer the
permissions to be set very tightly on SUID executables -- not least so that
the outsider cannot read the file and work out what it does).
What's more curious is that I can find no documentation for this behaviour.
It isn't in the Solaris man pages for open(3) or write(3). It isn't a
requirement of POSIX (IEEE 1003.1-1996). From the information I have
available, it isn't required by FIPS 151-1 (April 1989). It makes perfect
sense, but I'd like to know where it is documented as the actual behaviour.
Yours,
Jonathan Leffler (johnl@informix.com) #include <witticism.h>