From: Matthew Dharm <mdharm-kernel@one-eyed-alien.net>
To: Jesse Pollard <jesse@cats-chateau.net>
Cc: Keith Owens <kaos@ocs.com.au>,
Kernel Developer List <linux-kernel@vger.kernel.org>
Subject: Re: using mount from SUID scripts?
Date: Tue, 7 Aug 2001 22:17:08 -0700 [thread overview]
Message-ID: <20010807221708.C31439@one-eyed-alien.net> (raw)
In-Reply-To: <27034.997233173@kao2.melbourne.sgi.com> <01080721385400.15022@tabby>
In-Reply-To: <01080721385400.15022@tabby>; from jesse@cats-chateau.net on Tue, Aug 07, 2001 at 09:29:07PM -0500
[-- Attachment #1: Type: text/plain, Size: 2320 bytes --]
Actually, a strace of mount shows that mount asks for the UID and the EUID,
and seems to exit of it's own accord when they differ.
Tho, if I can force the UID to the EUID, this may work also.
Unfortunately, the snippit of code here doesn't do the job... after the
first two lines, the UID is unchanged, while the EUID is still 0 (root). I
used system "/usr/bin/id" to verify this. /bin/mount is still complaining.
Oh, wait... $> is effective and $< is real. So that first line should be
($r, $e) = ($<, $>); -- this makes everything happy!
Thanks tons, folks!
Matt Dharm
On Tue, Aug 07, 2001 at 09:29:07PM -0500, Jesse Pollard wrote:
> On Tue, 07 Aug 2001, Keith Owens wrote:
> >On Tue, 7 Aug 2001 16:29:39 -0700,
> >Matthew Dharm <mdharm-kernel@one-eyed-alien.net> wrote:
> >>I've got an SUID perl script (yes, it's EUID is really 0) which I'd like to
> >>use mount from to mount a file via loopback...
> >>
> >>Unfortunately, it looks like mount refuses to actually mount anything if
> >>the EUID and UID aren't the same....
> >
> >Are you sure the problem is mount? Some versions of bash drop euid(0)
> >when they execute scripts from setuid programs.
> >
>
> not mount, and likely not the shell - the thing is that perl doesn't like it
> when the effective uid is not equal to the real uid. Perl is very good at
> limiting the damange an unsuspecting script does. This is to prevent passing
> a "confused" environment to the shell.
>
> The following can work around this:
>
> ($r,$e) = ( $>, $< ); # save real and effective uid's
> $< = $e; # force real uid to the effective
> `/bin/mount ....`
> ($>, $<) = ($r,$e); # restore mixed state
>
> Remember, the options to mount should come from a fixed table with user
> selected input used to select which table entry to use... or a strictly
> fixed mount command.
>
> Otherwise you have an even bigger security hole.
>
> --
> -------------------------------------------------------------------------
> Jesse I Pollard, II
> Email: jesse@cats-chateau.net
>
> Any opinions expressed are solely my own.
--
Matthew Dharm Home: mdharm-usb@one-eyed-alien.net
Maintainer, Linux USB Mass Storage Driver
You suck Stef.
-- Greg
User Friendly, 11/29/97
[-- Attachment #2: Type: application/pgp-signature, Size: 232 bytes --]
next prev parent reply other threads:[~2001-08-08 5:17 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2001-08-07 23:29 Matthew Dharm
2001-08-08 1:12 ` Keith Owens
2001-08-08 2:29 ` Jesse Pollard
2001-08-08 5:17 ` Matthew Dharm [this message]
2001-08-08 12:31 Jesse Pollard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20010807221708.C31439@one-eyed-alien.net \
--to=mdharm-kernel@one-eyed-alien.net \
--cc=jesse@cats-chateau.net \
--cc=kaos@ocs.com.au \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®