SUID

1. suid/sgid did not work for bash/sh script, but only for binary executable file.

2.suid/sgid does not inherit to the child process. So before fork other process with the original file suid, we need setuid/setgid. 

3.wrapping the script with fellow binary file:

//test.c

#include <stdio.h>

#include <sys/types.h>

#include <unistd.h>

int main()

{

      If(0!=setuid(geteuid()))

Printf(“setuid error”);

      If(0!=setgid(getegid()))

Printf(“setgid error”);;

      system("/bin/sh ./firewall.sh");

      //execl("/bin/sh","./firewall.sh ",0);

      return 0;

}

 

For example, its binary file is test, then

sudo chown root test

sudo chgrp root test

sudo chmod u+s test

Then, execute test, firewall.sh will be executed well.

 

Reference:

http://www.softpanorama.org/Access_control/Permissions/controlling_suid_files.shtml

Practical UNIX and Internet Security, Second Edition - O'Reilly Media

http://en.wikipedia.org/wiki/Setuid

 


 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值