Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248067

Re: Help with suid (bash)

From <tomas@tuxteam.de>
Newsgroups linux.debian.user
Subject Re: Help with suid (bash)
Date 2022-05-10 14:20 +0200
Message-ID <Elx0l-exEQ-3@gated-at.bofh.it> (permalink)
References <ElwGZ-exjv-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Tue, May 10, 2022 at 07:50:18AM -0400, rhkramer@gmail.com wrote:
> Aside: even though this is not a Debian specific question, I often use debian-
> user as my first resource in asking Linux questions.
> 
> Background: 8 years ago I wrote a set of scripts to help me mount and unmount 
> LUKS encrypted partitions as needed and as myself (<myuserid>) rather than as 
> root. 

TL;DR use sudo.

You must have had an outdated kernel version back then, I think.

The setuid bit has been ignored for scripts in Linux since like...
forever. If my memory doesn't fail me, it must have been around
kernel 2.x, perhaps 3.x, so around of before 2010.

I remember writing a setuid wrapper for a specific application
back with kernel 2.0.36, so it must already have been a topic
back then.

There are many places out there as to why -- my search engine
gave me this [1] one.

You can, of course, patch your kernel. You could write a setuid
wrapper (a small setuid C program written to call your script:
a good exercise in writing security sensitive stuff -- did I get
everything right? ;-)

Or you can use a setuid wrapper written for you (called sudo).
Even this one doesn't get everything right from the get-go.
I'd still recommend this latter options. The one I wrote Back
Then [TM] surely has more holes than sudo.

Cheers

[1] https://unix.stackexchange.com/questions/364/allow-setuid-on-shell-scripts
-- 
t

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Help with suid (bash) rhkramer@gmail.com - 2022-05-10 14:00 +0200
  Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-10 14:20 +0200
  Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-10 16:30 +0200
    Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 18:10 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-10 21:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 21:30 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-11 01:20 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-11 03:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 05:10 +0200
          Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 07:10 +0200
            Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 18:10 +0200
              Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 20:30 +0200
                Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-12 01:00 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Dan Ritter <dsr@randomstring.org> - 2022-05-11 14:10 +0200
    Re: Help with suid (bash) rhkramer@gmail.com - 2022-05-10 18:50 +0200

csiph-web