Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #228020

Re: rsync --delete

From The Wanderer <wanderer@fastmail.fm>
Newsgroups linux.debian.user
Subject Re: rsync --delete
Date 2020-10-20 14:50 +0200
Message-ID <B1Zfs-GD-13@gated-at.bofh.it> (permalink)
References <B0Gox-2vP-7@gated-at.bofh.it> <B12yK-7sb-13@gated-at.bofh.it> <B1BZw-3oQ-13@gated-at.bofh.it> <B1QlQ-3Rv-3@gated-at.bofh.it> <B1Yjn-7a-11@gated-at.bofh.it>
Organization This space intentionally left blank.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On 2020-10-20 at 07:49, Greg Wooledge wrote:

> On Mon, Oct 19, 2020 at 08:11:01PM -0700, David Christensen wrote:
>
>> On 2020-10-19 05:00, Greg Wooledge wrote:
>> > using an explicit /usr/bin/rsync is sketchy at best.  You
>> > should already have /usr/bin in your PATH
>> 
>> AIUI using absolute paths for tools in shell scripts is a security best
>> practice -- it helps defend against attacks where PATH is compromised and/or
>> trojaned system tools are inserted into directories at the front of PATH.
> 
> It's not "best practice", and it does not provide any security against
> a malevolent execution environment.  All it really does is introduce
> failures when the location of a tool changes.  (See all the instances
> of failures when new buster installations moved some tools from /bin
> to /usr/bin, and scripts were updated to use things like /usr/bin/mkdir,
> which then fails on *upgraded* buster systems.)
> 
> To illustrate why it doesn't provide any security protection:
> 
> unicorn:~$ function /bin/rm { echo "haha loser"; }
> unicorn:~$ /bin/rm xyzzy
> haha loser
> 
> Remember, bash can accept functions that are imported from the environment,
> and bash's functions have an extremely liberal allowed set of characters.

From a quick test, that seems to only matter if you actually import the
functions from the environment somehow.

$ cat /tmp/test-function-script.sh
#/bin/bash

/home/wanderer/bin/abecedarian.sh
$ function /home/wanderer/bin/abecedarian.sh { echo "nope"; }
$ abecedarian.sh
Usage: /home/wanderer/bin/abecedarian.sh /path/to/wordlist
$ /home/wanderer/bin/abecedarian.sh
nope
$ /tmp/test-function-script.sh
Usage: /home/wanderer/bin/abecedarian.sh /path/to/wordlist

If I'm parsing that correctly, the full-path invocation from within the
script doesn't seem to pick up the function definition from the outside
session.

I imagine there's probably some scenario that might occur outside of
intentional arrangement in which that definition would in fact be picked
up within the script; can you outline an exact reproducer scenario for
what you're thinking of?

-- 
   The Wanderer

The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man.         -- George Bernard Shaw

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-17 00:30 +0200
  Re: rsync --delete Klaus Singvogel <deb-user-ml@singvogel.net> - 2020-10-17 00:40 +0200
    Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 13:40 +0200
  Re: rsync --delete ellanios82 <ellanios82@gmail.com> - 2020-10-17 00:40 +0200
  Re: rsync --delete Charles Curley <charlescurley@charlescurley.com> - 2020-10-17 04:10 +0200
  Re: rsync --delete Will Mengarini <seldon@eskimo.com> - 2020-10-17 08:40 +0200
    Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 13:50 +0200
  Re: rsync --delete <tomas@tuxteam.de> - 2020-10-17 10:40 +0200
    Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-17 14:20 +0200
      Re: rsync --delete <tomas@tuxteam.de> - 2020-10-17 15:30 +0200
    Re: rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-17 20:30 +0200
      Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 13:50 +0200
    Re: rsync --delete Andrei POPESCU <andreimpopescu@gmail.com> - 2020-10-18 12:50 +0200
  Re: rsync --delete Andy Smith <andy@strugglers.net> - 2020-10-17 17:30 +0200
  Re: rsync --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-18 00:10 +0200
    Re: rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-19 01:40 +0200
    Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 14:00 +0200
      Re: rsync --delete Mike McClain <mike.junk.46@att.net> - 2020-10-19 21:10 +0200
        Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 21:20 +0200
          Re: rsync --delete Tixy <tixy@yxit.co.uk> - 2020-10-19 23:20 +0200
            Re: rsync --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-20 05:10 +0200
              Re: rsync --delete Tixy <tixy@yxit.co.uk> - 2020-10-20 09:30 +0200
                Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-20 10:00 +0200
                Re: rsync --delete Tixy <tixy@yxit.co.uk> - 2020-10-20 10:20 +0200
              Re: rsync --delete Andrei POPESCU <andreimpopescu@gmail.com> - 2020-10-20 11:10 +0200
        Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-19 23:20 +0200
      Re: rsync --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-20 05:20 +0200
        Re: rsync --delete David <bouncingcats@gmail.com> - 2020-10-20 06:10 +0200
          Re: rsync --delete Nicolas George <george@nsup.org> - 2020-10-20 12:10 +0200
        Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-20 13:50 +0200
          Re: rsync --delete The Wanderer <wanderer@fastmail.fm> - 2020-10-20 14:50 +0200
            Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-20 15:10 +0200
              Re: rsync --delete The Wanderer <wanderer@fastmail.fm> - 2020-10-20 15:50 +0200
                Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-20 16:10 +0200
    define (or translate, or substitute for) "interpolate": Re: rsync --delete rhkramer@gmail.com - 2020-10-19 14:30 +0200
      Re: define (or translate, or substitute for) "interpolate": Re: rsync --delete rhkramer@gmail.com - 2020-10-19 14:50 +0200
      Re: define (or translate, or substitute for) "interpolate": Re:  rsync --delete <tomas@tuxteam.de> - 2020-10-19 15:00 +0200
        Re: define (or translate, or substitute for) "interpolate": Re: rsync --delete rhkramer@gmail.com - 2020-10-20 02:10 +0200
          Re: define (or translate, or substitute for) "interpolate": Re: rsync  --delete David Christensen <dpchrist@holgerdanske.com> - 2020-10-20 05:50 +0200
  Re: rsync --delete Greg Wooledge <wooledg@eeg.ccf.org> - 2020-10-19 14:10 +0200

csiph-web