Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: FD's 0..2 and suid/sgid procs (Was: Crash a redhat 5.1 linux
From: alan () LXORGUK UKUU ORG UK (Alan Cox)
Date: Thu, 30 Jul 1998 18:41:28 +0100


Alan Cox actually is the first person who highlighted this sort of
vulnerability to me.  Does anyone know if the OpenBSD approach is

Im certainly not its discoverer however.

suid/sgid program bogus stdin/stdout/stderr)?  Also, is a similar patch
in the works for Linux?  (I ask, because I'm a Linux user myself.)

Someone was working on one yes

And, is there any overwhelming reason why you wouldn't make the same
guarantee that fd's 0..2 are open for all processes, rather than just
suid/sgid processes?

Actually for the general case you shouldnt do it. Passing a closed fd
is valid Unix behaviour, so you cease to really be "unix" by doing it.

Obviously there are sometimes advantages to not following unix tradition
totally



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]