[6034] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: problems with /usr/X11/bin/SuperProbe being setuid

daemon@ATHENA.MIT.EDU (Borg)
Mon Nov 25 14:47:46 1996

Date: Mon, 25 Nov 1996 09:54:15 -0800
From: Borg <vladimip@iceonline.com>
To: Red Hat Mailing List <redhat-list@redhat.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com

Steve "Stevers!" Coile wrote:
..................
> Actually, I believe it is the changing ownership of a file to root that
> requires privileges, not setting the set user ID bit.  I believe every
> user can make an executable they own setuid (or setgid, for that matter).
> Unless you're root, tar won't be able to change the ownership of files
> unpacked from an archive to root, even if they were owned by root on
> the system on which the archive was made.  In other words, privileges
> from other systems don't transfer.

Yes they do when you use tar. So, a user takes SuperProbe
binary, as root executes chmod u+s and chown root:root, tars
it up and uploads it on a box where he has only user privileges,
then untars and runs it.

Regards,

-- 
#include <disclaimer.h>  |   *Good pings come in small packets*
     Vlad Petersen       |     Linux: multiuser, multitasking,
     Vancouver, B.C      |     multiplatform, 64-bit and free.
vladimip @ iceonline.com | Ceterum censeo Microsoftam delendam esse


--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post