home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.unix.sysv386
- Path: sparky!uunet!pipex!demon!constant.demon.co.uk!slangley
- From: slangley@constant.demon.co.uk (Simon Langley)
- Subject: Re: setuid problem on SCOUnix v 3.2.2
- Message-ID: <Bt3Mqn.49q@constant.demon.co.uk>
- Organization: Home
- X-Newsreader: Tin 1.1 PL5
- References: <1992Aug11.171250.6254@informix.com>
- Distribution: ca
- Date: Sun, 16 Aug 1992 23:03:58 GMT
- Lines: 19
-
- Arturo Vega (arturo@informix.com) wrote:
- : Hi,
- :
- : I have the following problem on SCOUnix V/386 v 3.2.2:
- :
- : Setuid programs revert to normal executables after any
- : update, e.g. running "strip" on such a program will convert it
- : back from setuid to normal.
- :
- My SVR4 system does the same thing. It also does this if I copy a suid
- program (but not move). Although I don't know for sure, I would have thought
- that this was a security feature. If you could copy a suid program into your
- own directory and then edit it to create you own suid program this would be a
- serious security hole; this would be a faff with a binary program on a system
- that didn't allow suid shell scripts but it would be perfectly possible.
-
- --
- Simon Langley (preferred) slangley@constant.demon.co.uk
- Hampstead, London slangley@cix.compulink.co.uk
-