Question:
Why are setuid shell scripts inherently unsafe?
Jimmy
2011-03-20 17:16:57 UTC
In, Linux and Ubuntu, people keep telling me that setuid shell scripts are not safe so I must ask?

Why are setuid shell scripts inherently unsafe?

Thanks!
Three answers:
James Bond
2011-03-20 17:43:13 UTC
An executable file whose setuid bit set when executed by me, I get priveleges of the owner of that executable file!.



Consider, passwd command. I am sure you are aware that our password details are available in /etc/passwd or /etc/shadow. However, we can not change them directly using an editor as we are not owners of those files. However, when we run passwd command and change the password it is stored in these files. How it is happening?. Passwd command is having its setuid bit set and belongs to the root. Thus, when we run it we acquire root priveleges with that /etc/passwd or other configurations files are getting modified which we can not otherwise directly edit. This is the gimmick of setuid.



A normal user acquires root priveleges. So, those commands are dangerous.
?
2017-01-13 16:46:26 UTC
There are not any airplane that paranoid flyers ought to evade. Inherently hazardous airplane do not stay in use for extremely long. Inherently hazardous layout good factors at as quickly as disappear for the comparable reason. it truly is totally uncommon for any form of airplane to teach signs and indications of serious layout deficiencies that make it truly hazardous, yet while this surely takes place, the airplane is removed from provider very at as quickly as. A classic historic occasion is the De Havilland Comet, the 1st commercial jet airliner, which flew for a time interior the Fifties. The airplane had serious layout flaws that led to fatigue cracks to strengthen at as quickly as interior the fuselage, and a serious of injuries exceeded off while the airplane explosively decompressed in midair and have been destroyed. The airplane became into at as quickly as removed from provider and not in any respect flew returned in that particular type (a later type of the Comet corrected the layout flaws and flew for some years, and a few are nevertheless in provider). the story of the Comet, regardless of the indisputable fact that, is truly marvelous. 40 years in the past, with the get admission to of dissimilar T-tailed, rear-engined airliners into provider, it became into got here across that this way of airplane can enter an aerodynamic "superstall" from which no restoration is available. The existence of superstall had not before been popular, and countless different airplane have been lost before the phenomenon became into understood. immediately, airplane of this way have good factors which incorporate aggressive stick pushers that evade superstalls, and that's not a project, so one can not say that those airplane are hazardous immediately. besides, in precis, if it truly is hazardous, it would not fly for long. All civilian transport airplane at present in provider are truly secure. in case you sense compelled to rank airplane, i might propose keeping off new designs for a decade or so, until they have widespread a checklist. it truly is not likely that any new airplane will coach to be truly hazardous, yet no person truly is conscious until they have amassed extremely some time in provider. Older airplane, which incorporate 737s and 747s, have massive provider histories and, on the same time as they don't look to be appropriate, their protection has been shown with the help of time, and any quirks they might have are very properly popular and understood.
Mime School Dropout
2011-03-20 17:19:55 UTC
They operate will full rights to the OS. Outside and around the local logon


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...