Can I hide a part of the text by a "More..." link?
setuid question:
Hello Guest
  
  • Login
• Register…
• Start blog
  • Who, Where, When
• What is interesting here?
• Duels
  • Polls
• Avatars
• Interests
  • Cities and Countries
• Random blog
• Users search
  • Search
• Games
• Tests
• QAIX
  • Сообщества
• Talxy Chat
• Horoscope
• Online
 
Register!

QAIX > Perl web-programming > setuid question: "insecure dependency"? 8 May 2009 13:13:57

  Top users: 
  Recent blog posts: 
  They have birthday today: 
  Forums:   
  Discuss: 
  Recent forum topics: 
  Recent forum comments:
  Модератор:

setuid question: "insecure dependency"?

Andria Thomas 20 September 2001 00:14:28
 Hi all --

I'm trying to write a setuid script to change passwords on a machine via
the web. I am not trying to change the local passwords (i.e. *not*
modifying /etc/password), but I do need the script to be run as root so
it can call another password-changing utility which is doing the actual
work.

When run from the command line as root, the script works fine. However,
when run as myself (after setting the script to be setuid root) I get
the following error generated from the script's system call:

"Insecure dependency in system while running setuid at ./chpass_web.pl
line 159."

Perl is installed on this system to use suid emulation, so it's calling
the 'suidperl' binary. The problem originates from the following line
of code:

system "/bin/echo $new_password1 | /usr/local/sbin/sas­lpasswd -p
$in_username";

The documentation I've seen implies that variables can't be passed
directly into the shell, as they are above, but I couldn't reword the
system call in any way that still enabled it to work.

Can anyone help with this? Or lead me to any pointers on suidperl?
I've already read the perlsec manpage, and searched through the mailing
list archives...

Thanks!
Andria

--
-------------------­--------------------­-------
Andria Thomas andria@tovaris.com
System Administrator -- Tovaris, Inc.
(434) 245-5309 x 105

Add comment
Guest 8 May 2009 13:13:57 permanent link ]
 My kernel is 2.4.20-20.9
Apache version is 1.3.24
Insecure dependency in system while running with -T switch at /usr/local/apache/c­gi-bin/omail.pl line 2736.

Would please help me any one.
Add comment
 

Add new comment

As:
Login:  Password:  
 
 
  
 
Пожалуйста, относитесь к собеседникам уважительно, не используйте нецензурные слова, не злоупотребляйте заглавными буквами, не публикуйте рекламу и объявления о купле/продаже, а также материалы нарушающие сетевой этикет или законы РФ. Ваш ip-адрес записывается.


QAIX > Perl web-programming > setuid question: "insecure dependency"? 8 May 2009 13:13:57

see also:
[JBoss AOP] - intercepting EJB calls
[JBoss jBPM] - how to generate a .war…
[JBoss Portal] - Re: Problems with…
pass tests:
How objective you are
see also:
wholesale burberry t shirt afficiton…
replica louis vuitton clothing burberry…

  Copyright © 2001—2010 QAIX
Идея: Монашёв Михаил.
Авторами текстов, изображений и видео, размещённых на этой странице, являются пользователи сайта.
See Help and FAQ in the community support.qaix.com.
Write in the community about the bugs you have noticedbugs.qaix.com.
Write your offers and comments in the communities suggest.qaix.com.
Information for parents.
Пишите нам на .
If you would like to report an abuse of our service, such as a spam message, please .
Если Вы хотите пожаловаться на содержимое этой страницы, пожалуйста .