Re: Executing Esql-C pgm
Posted in 1997
In article <62ldvk$3u6@cssun.mathcs.emory.edu>, Jonathan Leffler <johnl@informix.com> writes >On Tue, 21 Oct 1997 saabtoo@aol.com wrote: > >> I have run into an unusual problem that I could use some help with. We >> are executing an Esql-C program on our Sun Sparc 2000 server (OS 2.5.1) >> from an informix stored procedure (Online 7.20). > >OK so far. > >> This Esql-C program contains code that issues commands on a remote Sun >> server using rsh. > >That's going to be tricky; the user of the SP will have to have rsh >privileges on the remote machine, of course. That tends to mean either you >will need .rhost files in everyone's home directory (or /etc/hosts.equiv on >each machine), with consequential loose security problems. > >> For these commands to work we must set the permission on the executable >> of to the "setuid" bit (ie "rwsrwxrwx" pgm_name). > >Never, ever, have a SUID program writable by anyone other than the owner! >I can write what ever I like over your program, and become the relevant >user. Eg, I could copy /bin/ksh over your program, and then I'm in as the >owner of the program. Always ensure that the code is rwsr-xr-x at most; No, unless you are root, setuid and set group id bits are REMOVED when a file is written to! This happens on most version of UNIX! >group and others do not need read permissions, and most of the time neither >does the owner (once the program is stable), so --s--x--x is a good set of >permissions to use; I tend to want to read stuff so I use r-s--x--x. If >others don't need to run the program (only group members), then don't let >them run it. The other point is to ensure that the directory containing >the program is secure; ultimately, you need all the directories leading to >the program to be secure else a hacker can work their evil. > >That's basic SUID program writing security. > >Which user ID is is SUID to? root? I sincerely hope not! But I rather >suspect it is... > >> But when the stored procedure that calls the esql-c program is run, the >> system call fails with -668 sqlcode, -172 isam error. > >When I do 'finderr -172', it says that there should be some information in >the OnLine log file; what does yours have to say? > >> When we set the permission to "rwxrwxrwx" the esql-c program runs but the >> "rsh" commands fail. > >This is why the info in the OnLine log file should be helpful. I suspect >that your program is SUID root and linked with shared libraries. On many >machines (eg SVR4 based machines), SUID root programs do not look for >shared libraries using LD_LIBRARY_PATH -- they only look in /usr/lib (or, >perhaps, in directories specified with the -R option on the linker line). >Try relinking the program with static libraries (esql -static), or adding >-R$INFORMIXDIR/lib -R$INFORMIXDIR/lib/esql to the command line. When it is >not SUID root, then the libraries are found, but the setuid() calls made to >allow the rsh commands to work fail -- why isn't the program diagnosing >these errors. I may be maligning your code unwarrantedly here -- it may be >that it is all SUID programs which do not look for shared libraries with >LD_LIBRARY_PATH (because the malicious intruder could set their >LD_LIBRARY_PATH to include their own library ahead of the intended >library), and that is all that is the trouble. > >Yours, >Jonathan Leffler (johnl@informix.com) #include <witticism.h> > -- David Williams