[5989] in RedHat Linux List
Re: problems with /usr/X11/bin/SuperProbe being setuid
daemon@ATHENA.MIT.EDU (Steve \"Stevers!\" Coile)
Mon Nov 25 11:17:43 1996
Date: Mon, 25 Nov 1996 10:59:56 -0500 (EST)
From: "Steve \"Stevers!\" Coile" <scoile@patriot.net>
To: Wojtek Pilorz <wpilorz@celebris.bdk.lublin.pl>
cc: Borg <vladimip@iceonline.com>, redhat-list@redhat.com
In-Reply-To: <Pine.BSF.3.91.961125120644.8727A-100000@celebris.bdk.lublin.pl>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
On Mon, 25 Nov 1996, Wojtek Pilorz wrote:
[...]
>>At a college where I study paranoid sysadmins got so bad that disabled
>>not only SuperProbe and mount but also disabled find, locate and
>>removed setuid bit from pppd. Does removing setuid really solve overflow
>>exploits frequently found in "u+s" chmod'ed programs? Suppose root chmoded
>>SuperProbe not to be setuid anymore. Then user Luser takes a binary of
>>SuperProbe fron his home computer, tars and gzips it to preserve root
>>ownership and "u+s" permission, then uploads it to his home directory
>>and "explores". The same about other programs where setuid situation is
>>frequently used to crack systems. Am I missing something?
>
>Yes, definitely; setting 'set user id' bit required root priviledges
>(also when you are using tar, of course). had been that so simple,
>there would have been no security in *nix at all!!!
Actually, I believe it is the changing ownership of a file to root that
requires privileges, not setting the set user ID bit. I believe every
user can make an executable they own setuid (or setgid, for that matter).
Unless you're root, tar won't be able to change the ownership of files
unpacked from an archive to root, even if they were owned by root on
the system on which the archive was made. In other words, privileges
from other systems don't transfer.
--
Steve Coile P a t r i o t N e t Systems Engineering
scoile@patriot.net Patriot Computer Group (703) 277-7737
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null