*BSD News Article 17367


Return to BSD News archive

Path: sserve!newshost.anu.edu.au!munnari.oz.au!news.Hawaii.Edu!ames!elroy.jpl.nasa.gov!usc!cs.utexas.edu!uunet!psgrain!ee.und.ac.za!tplinfm
From: barrett@lucy.ee.und.ac.za (Alan Barrett)
Newsgroups: comp.os.386bsd.bugs
Subject: Re: Strange behavier on #! interpretation (Secure SUID scripts)
Date: 21 Jun 1993 14:29:12 +0200
Organization: Elec. Eng., Univ. Natal, Durban, S. Africa
Lines: 9
Message-ID: <2049io$hmk@lucy.ee.und.ac.za>
References: <1vjtib$725@lucy.ee.und.ac.za>
NNTP-Posting-Host: lucy.ee.und.ac.za

In article <1vjtib$725@lucy.ee.und.ac.za> I wrote:
>I recommend Maarten Litmaath's "indir" wrapper, available from all good
>comp.sources.unix archives.  indir is a small SUID root program, and

Oops.  indir should not be installed suid or sgid to anything.  It
relies on the operating system to honour the suid and sgid bits on the
script.  (It seems to work under NetBSD 0.8.)

--apb (Alan Barrett)