[5954] in RedHat Linux List
Re: problems with /usr/X11/bin/SuperProbe being setuid
daemon@ATHENA.MIT.EDU (Borg)
Mon Nov 25 03:10:29 1996
Date: Sun, 24 Nov 1996 23:05:10 -0800
From: Borg <vladimip@iceonline.com>
To: redhat-list@redhat.com
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
.......
>
> As per the below commit, SuperProbe is no longer setuid root on FreeBSD.
> I would highly recommend that you remove the setuid bit if it is installed
> on your system; it is normally in /usr/X11R6/bin/SuperProbe if you have X
> installed. 'chmod u-s /usr/X11R6/bin/SuperProbe' will do the trick.
.........
> According to Marc Slemko (marcs@alive.ampr.ab.ca) there are potential
> security holes in SuperProbe and it is not going to be setuid in the
> next release.
At a college where I study paranoid sysadmins got
so bad that disabled not only SuperProbe and mount but also
disabled find, locate and removed setuid bit from pppd.
Does removing setuid really solve overflow exploits
frequently found in "u+s" chmod'ed programs? Suppose
root chmoded SuperProbe not to be setuid anymore.
Then user Luser takes a binary of SuperProbe fron his
home computer, tars and gzips it to preserve root ownership
and "u+s" permission, then uploads it to his home directory
and "explores". The same about other programs where setuid
situation is frequently used to crack systems. Am I missing
something?
--
#include <disclaimer.h> | *Good pings come in small packets*
Vlad Petersen | Linux: multiuser, multitasking,
Vancouver, B.C | multiplatform, 64-bit and free.
vladimip @ iceonline.com | Ceterum censeo Microsoftam delendam esse
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null