[6028] in RedHat Linux List
Re: problems with /usr/X11/bin/SuperProbe being setuid
daemon@ATHENA.MIT.EDU (Borg)
Mon Nov 25 14:25:30 1996
Date: Mon, 25 Nov 1996 09:29:54 -0800
From: Borg <vladimip@iceonline.com>
To: Red Hat Mailing List <redhat-list@redhat.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
Wojtek Pilorz wrote:
..............
> >
> > At a college where I study paranoid sysadmins got
> > so bad that disabled not only SuperProbe and mount but also
> > disabled find, locate and removed setuid bit from pppd.
> > Does removing setuid really solve overflow exploits
> > frequently found in "u+s" chmod'ed programs? Suppose
> > root chmoded SuperProbe not to be setuid anymore.
> > Then user Luser takes a binary of SuperProbe fron his
> > home computer, tars and gzips it to preserve root ownership
^^^^^^^^^^^^^^^^^^
> > and "u+s" permission, then uploads it to his home directory
> > and "explores". The same about other programs where setuid
> > situation is frequently used to crack systems. Am I missing
> > something?
> >
> Yes, definitely;
> setting 'set user id' bit required root priviledges
> (also when you are using tar, of course).
> had been that so simple, there would have been no security
> in *nix at all!!!
Please re-read the underlined line above: of course, any user
has root priviledges on his/her home computer and can change
permissions as he pleases and then upload it.
--
#include <disclaimer.h> | *Good pings come in small packets*
Vlad Petersen | Linux: multiuser, multitasking,
Vancouver, B.C | multiplatform, 64-bit and free.
vladimip @ iceonline.com | Ceterum censeo Microsoftam delendam esse
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null