Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 31 May 2001 03:31:02 -0400 (EDT)
From:      "Dan Mahoney, System Admin" <danm@prime.gushi.org>
To:        Mark Sergeant <msergeant@snsonline.net>
Cc:        questions@FreeBSD.ORG
Subject:   Re: Setuid Shell/Perl scripts
Message-ID:  <Pine.BSF.4.21.0105310325300.63890-100000@prime.gushi.org>
In-Reply-To: <200105310720.f4V7K9V36772@xyzzy.intranet.snsonline.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On 31 May 2001, Mark Sergeant wrote:

> Why not configure sudo so you can run command as user (nobody whatever web serv
> er runs as) without requiring a password.

Lessee, I give the webserver access to "kill" as root...unrestricted, so
that a user can upload a cgi that does 'kill -9 1'...

Although I assume the more sensible approach would probably be to write
give the webserver access to the "restart radius" command (which is really
just a shell script that finds the PIDs and HUPs them).

But my point is that I'm looking to migrate things more or less
seamlessly.  We're upgrading freeBSD for binary compatibility with some
software that's not available in source form, I'd rather just upgrade,
deal with fixing sendmail and whatever moves, instead of fixing everything
that will break that worked fine (and relatively securely) before.

-Dan

> 
> 
> On Thu, 31 May 2001 03:12:01 -0400 (EDT), Dan Mahoney, System Admin said:
> 
> :: I've noticed that recently FreeBSD made it so that setuid shell and perl
> ::  scripts no longer work, and while I can compile a wrapper for some of the
> ::  applications, I'd like to know if there's any way to turn this
> ::  "feature" back off.  I'm planning to upgrade my servers from 3.2-R to
> ::  4.3-R, and the systems are secure (no users have shell access, other than
> ::  admins), but a lot of the web scripting relies on setuid scripts (for
> ::  example, scripts that allow our users to modify our radius entries, or our
> ::  web-editor, or even our change-your-password-via-the-web interface).
> ::  
> ::  Thanks in Advance, please CC any messages regarding this to me, I'm not
> ::  subscribed.
> ::  
> ::  -Dan Mahoney
> ::  
> ::  --
> ::  
> ::  "Happy, Sad, Happy, Sad, Happy, Sad, Happy, Intruiged!  I've never been so
> ::  in touch with my emotions!"
> ::  
> ::  -AndrAIa as Hexadecimal, Reboot Episode 3.2.3
> ::  
> ::  --------Dan Mahoney--------
> ::  Techie,  Sysadmin,  WebGeek
> ::  Gushi on efnet/undernet IRC
> ::  ICQ: 13735144   AIM: LarpGM
> ::  Web: http://prime.gushi.org
> ::  finger danm@prime.gushi.org 
> ::  for pgp public key and tel#
> ::  ---------------------------
> ::  
> ::  
> ::  
> ::  To Unsubscribe: send mail to majordomo@FreeBSD.org
> ::  with "unsubscribe freebsd-questions" in the body of the message
> ::  
> ::  
> 
> 

--

"She's been getting attacked by these leeches, they're leaving these marks
all over her neck. You gotta keep her out of those woods.  If one more
leech gets her, she's gonna get a smack."

-Someone's Mother, December 18th, 1998

--------Dan Mahoney--------
Techie,  Sysadmin,  WebGeek
Gushi on efnet/undernet IRC
ICQ: 13735144   AIM: LarpGM
Web: http://prime.gushi.org
finger danm@prime.gushi.org 
for pgp public key and tel#
---------------------------



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0105310325300.63890-100000>