Re: set-UID

From: eŽik (et57__DELETE__THIS___at_hotmail.com)
Date: 09/09/03


Date: Tue, 09 Sep 2003 11:45:53 +0200

On Mon, 08 Sep 2003 21:07:37 GMT, the right honourable alun@texis.com
(Alun Jones [MS MVP]) wrote:

>In article <tgqplvgugmp1sp7j9ta6rfdv6rprv39538@4ax.com>, eŽik
><et57__DELETE__THIS__@hotmail.com> wrote:
>>What is a set-UID progam and why is it baaaaad from a security
>>standpoint ?
>
>Put very simply, it's a program that has been created with special flags
>that make it run, not under the security context of the user who starts it
>up, but under the security context of the user who created / installed it.
>
>That user context is usually the "root" account - the superuser account in
>Unix, and which can do anything.
>
>The reason it's bad is that all programs have bugs. Some of those bugs are
>"exploitable" - they can be used to run a piece of code that an attacker
>creates. If you have an exploitable program that automatically sets the
>user ID (hence, "setuid") to "root", then you are handing the keys to your
>system over to an attacker.
>
>Alun.
>~~~~
>
>[Please don't email posters, if a Usenet response is appropriate.]

thank you for the enlightenment.
most appreciated.

frgr
Erik



Relevant Pages

  • Re: Word 2008 love of the left
    ... therefore not bugs. ... CyberTaz wrote: ... Bob Jones [MVP] Office:Mac ...
    (microsoft.public.mac.office.word)
  • I thought MVPs were here to help with update problems, including SP2
    ... If Carey Frisch, a so-called MVP, can't help posters who are having ... problems with SP2, then she/he has no business being an MVP. ... release with so many bugs, after many delays, is nothing to be proud of. ...
    (microsoft.public.windowsupdate)
  • Re: In VC++7.1 How do I...
    ... that is a wonderful feature. ... truly weird bugs that either fail to compile with VC7 or get runtime checks that VC6 ... Joseph M. Newcomer ... MVP Tips: http://www.flounder.com/mvp_tips.htm ...
    (microsoft.public.vc.mfc)
  • Re: looking for a simple GridControl
    ... >What is wrong with a CListCtrl in report mode? ... >No known bugs that I am aware of except a limit of 260 displayable ... >> bit complex to use on simple tabular data display) ... MVP Tips: http://www.flounder.com/mvp_tips.htm ...
    (microsoft.public.vc.mfc)
  • Re: Frage zu Resoucefile
    ... Martin Richter [MVP] WWJD ... "In C we had to code our own bugs. ...
    (microsoft.public.de.vc)