Great Circle Associates Firewalls
(August 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Mode 666 files... executable?
From: kevinbr @ NetComm . IE (Kevin Brown)
Date: Tue, 6 Aug 1996 23:39:41 +0300
To: John Mulligan <mulligan @ lafsun . lafayette . edu>
Cc: firewalls @ greatcircle . com

No, this is not posible......chmod defers to the owner of the file, so if
it owned by root, then root must make it suid.

Remember though, beware of the dreaded suid hack with Solaris 1.X and the
Bourn shell ( the infamous link to -i on a suid root owned Bourne Shell
script)

Does this hack work anywher anymore? ( the -i)

kevin



>If software creates mode 666 files (read and write by all) and owned by
>root, is it possible for a third party to edit the file (provided it is
>text) and do a `sh <filename>` to run it as root?  I know it is possible
>to edit it and run it, but it runs setuid to the third party user, not
>root.
>
>Remeber that files do not need the -x- in the permissions to be executable
>as scripts.
>
>Any comments?
>
>
>
>John P. Mulligan <mulligaj @
 lafayette .
 edu>
>PGP Public Key available at http://www.lafayette.edu/~mulligaj
>Excitement. Adventure. A Jedi craves not these things.
>                                     -- Silent Bob

////////////////////////////////////////////////////////////
     Kevin Brown            | N \  We operate in Ireland
       NetComm              | e /  and the Middle East
Unix Training, Consultancy  | t \  --IRELAND--
     Networking             | C /  Voice: 353-1-282-7342
                            | o \  Fax: 353-1-282-7342
                            | m /  --DUBAI--
  We will design and        | m \  Voice: 971-4-491476
 construct your Web Site.   |   /  Fax: 971-4-492957
Install a firewall Today!   |   \  email: kevinbr @
 netcomm .
 ie
                            |   /           (Internet)
                            |   \

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\



Indexed By Date Previous: Re: Mode 666 files... executable?
From: Brian Hatch <bri @ ifokr . org>
Next: Re: Syns against web
From: lists @ lina . inka . de (Bernd Eckenfels)
Indexed By Thread Previous: Re: Mode 666 files... executable?
From: Brian Hatch <bri @ ifokr . org>
Next: NT 3.51 FTP authentication bug
From: arager @ mcgraw-hill . com

Google
 
Search Internet Search www.greatcircle.com