Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #228020
| From | The Wanderer <wanderer@fastmail.fm> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: rsync --delete |
| Date | 2020-10-20 14:50 +0200 |
| Message-ID | <B1Zfs-GD-13@gated-at.bofh.it> (permalink) |
| References | <B0Gox-2vP-7@gated-at.bofh.it> <B12yK-7sb-13@gated-at.bofh.it> <B1BZw-3oQ-13@gated-at.bofh.it> <B1QlQ-3Rv-3@gated-at.bofh.it> <B1Yjn-7a-11@gated-at.bofh.it> |
| Organization | This space intentionally left blank. |
[Multipart message — attachments visible in raw view] - view raw
On 2020-10-20 at 07:49, Greg Wooledge wrote:
> On Mon, Oct 19, 2020 at 08:11:01PM -0700, David Christensen wrote:
>
>> On 2020-10-19 05:00, Greg Wooledge wrote:
>> > using an explicit /usr/bin/rsync is sketchy at best. You
>> > should already have /usr/bin in your PATH
>>
>> AIUI using absolute paths for tools in shell scripts is a security best
>> practice -- it helps defend against attacks where PATH is compromised and/or
>> trojaned system tools are inserted into directories at the front of PATH.
>
> It's not "best practice", and it does not provide any security against
> a malevolent execution environment. All it really does is introduce
> failures when the location of a tool changes. (See all the instances
> of failures when new buster installations moved some tools from /bin
> to /usr/bin, and scripts were updated to use things like /usr/bin/mkdir,
> which then fails on *upgraded* buster systems.)
>
> To illustrate why it doesn't provide any security protection:
>
> unicorn:~$ function /bin/rm { echo "haha loser"; }
> unicorn:~$ /bin/rm xyzzy
> haha loser
>
> Remember, bash can accept functions that are imported from the environment,
> and bash's functions have an extremely liberal allowed set of characters.
From a quick test, that seems to only matter if you actually import the
functions from the environment somehow.
$ cat /tmp/test-function-script.sh
#/bin/bash
/home/wanderer/bin/abecedarian.sh
$ function /home/wanderer/bin/abecedarian.sh { echo "nope"; }
$ abecedarian.sh
Usage: /home/wanderer/bin/abecedarian.sh /path/to/wordlist
$ /home/wanderer/bin/abecedarian.sh
nope
$ /tmp/test-function-script.sh
Usage: /home/wanderer/bin/abecedarian.sh /path/to/wordlist
If I'm parsing that correctly, the full-path invocation from within the
script doesn't seem to pick up the function definition from the outside
session.
I imagine there's probably some scenario that might occur outside of
intentional arrangement in which that definition would in fact be picked
up within the script; can you outline an exact reproducer scenario for
what you're thinking of?
--
The Wanderer
The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man. -- George Bernard Shaw
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-17 00:30 +0200
Re: rsync --delete Klaus Singvogel <deb-user-ml@singvogel.net> - 2020-10-17 00:40 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 13:40 +0200
Re: rsync --delete ellanios82 <ellanios82@gmail.com> - 2020-10-17 00:40 +0200
Re: rsync --delete Charles Curley <charlescurley@charlescurley.com> - 2020-10-17 04:10 +0200
Re: rsync --delete Will Mengarini <seldon@eskimo.com> - 2020-10-17 08:40 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 13:50 +0200
Re: rsync --delete <tomas@tuxteam.de> - 2020-10-17 10:40 +0200
Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-17 14:20 +0200
Re: rsync --delete <tomas@tuxteam.de> - 2020-10-17 15:30 +0200
Re: rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-17 20:30 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 13:50 +0200
Re: rsync --delete Andrei POPESCU <andreimpopescu@gmail.com> - 2020-10-18 12:50 +0200
Re: rsync --delete Andy Smith <andy@strugglers.net> - 2020-10-17 17:30 +0200
Re: rsync --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-18 00:10 +0200
Re: rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-19 01:40 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 14:00 +0200
Re: rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-19 21:10 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 21:20 +0200
Re: rsync --delete Tixy <tixy@yxit.co.uk> - 2020-10-19 23:20 +0200
Re: rsync --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-20 05:10 +0200
Re: rsync --delete Tixy <tixy@yxit.co.uk> - 2020-10-20 09:30 +0200
Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-20 10:00 +0200
Re: rsync --delete Tixy <tixy@yxit.co.uk> - 2020-10-20 10:20 +0200
Re: rsync --delete Andrei POPESCU <andreimpopescu@gmail.com> - 2020-10-20 11:10 +0200
Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-19 23:20 +0200
Re: rsync --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-20 05:20 +0200
Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-20 06:10 +0200
Re: rsync --delete Nicolas George <george@nsup.org> - 2020-10-20 12:10 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-20 13:50 +0200
Re: rsync --delete The Wanderer <wanderer@fastmail.fm> - 2020-10-20 14:50 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-20 15:10 +0200
Re: rsync --delete The Wanderer <wanderer@fastmail.fm> - 2020-10-20 15:50 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-20 16:10 +0200
define (or translate, or substitute for) "interpolate": Re: rsync --delete rhkramer@gmail.com - 2020-10-19 14:30 +0200
Re: define (or translate, or substitute for) "interpolate": Re: rsync --delete rhkramer@gmail.com - 2020-10-19 14:50 +0200
Re: define (or translate, or substitute for) "interpolate": Re: rsync --delete <tomas@tuxteam.de> - 2020-10-19 15:00 +0200
Re: define (or translate, or substitute for) "interpolate": Re: rsync --delete rhkramer@gmail.com - 2020-10-20 02:10 +0200
Re: define (or translate, or substitute for) "interpolate": Re: rsync --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-20 05:50 +0200
Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 14:10 +0200
csiph-web