[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: suid script



Joey Hess writes:
> Because shell scripts are supposidly very often full of securitry holes when
> suid.

There's a bit more to it.  There is a race condition that would permit you
to substitute a script of your choice for the suid script and have it run
suid.
-- 
John Hasler                This posting is in the public domain.
john@dhh.gt.org		   Do with it what you will.
Dancing Horse Hill         Make money from it if you can; I don't mind.
Elmwood, Wisconsin         Do not send email advertisements to this address.


Reply to: