【问题标题】:How to enable suidperl in Debian wheezy?如何在 Debian wheezy 中启用 suidperl?
【发布时间】:2014-02-09 18:37:55
【问题描述】:

我有一个 Perl 脚本,它由 root 拥有并具有 setuid。

在此脚本中,我正在更改作为参数传递的文件的所有者。

但是在运行这个脚本时我得到了

chown: changing ownership of `file': Operation not permitted

有人告诉我,如果启用,则默认情况下使用 suidperl 运行带有 setuid 的脚本。

但我不认为这发生在我的案例中。

有人可以帮我解决这个问题吗?我正在使用 Debian wheezy。我的 Perl 版本是 5.14.2。我试过了

apt-get install perl-suid

但它不起作用。

apt-cache search perl

在 Perl 中没有给我与 suid 相关的候选人。

这是我的 Perl 程序

#! /usr/bin/perl -T

use Cwd 'abs_path';

sub check_path {
  my $file = $_[0];

  $file = abs_path($file);
  if ($file =~ /^\/home\/abc\/dir1\//) {
    return 1;
  }
  else {
    return 0;
    print("You can only update permissions for files inside /home/abc/dir1/ directory\n");
  }
}

if (@ARGV == 1) {
  if (&check_path($ARGV[0]) == 1) {
    $ENV{PATH} = "/bin:/usr/bin";
    my $command = "chown abc:abc " . $ARGV[0];
    if ($command =~ /^(.*)$/) {
      $command = $1;
    }

    $result = `$command`;
  }
}
elsif ((@ARGV == 2) && ($ARGV[0] eq "-R")) {
  if (&check_path($ARGV[1]) == 1) {
    $ENV{PATH} = "/bin:/usr/bin";
    my $command = "chown -R abc:abc " . $ARGV[1];
    if ($command =~ /^(.*)$/) {
      $command = $1;
    }
    $result = `$command`;
  }
}
else {
  print("Sorry wrong syntax. Syntax: perl /home/abc/sbin/update_permission.pl [-R] file_path");
}

【问题讨论】:

  • 请出示你的节目。
  • @Borodin 我已经添加了我的代码
  • 在这段代码中我检查文件的绝对路径,如果它包含 /home/abc/dir1 那么只有我想执行 chown 命令(作为安全措施)。根据没有参数,它将执行 chown 或 chown -R
  • @SteffenUllrich 感谢您的评论。但是你有什么办法解决我的问题吗?

标签: perl debian suid


【解决方案1】:

对你来说可能为时已晚,但我遇到了同样的问题并使用了以下简单的 C 包装器(无耻地取自 http://www.blyberg.net/downloads/suid-wrapper.c):

#include <unistd.h>
#include <errno.h>

main( int argc, char ** argv, char ** envp )
{
    if( setgid(getegid()) ) perror( "setgid" );
    if( setuid(geteuid()) ) perror( "setuid" );
    envp = 0; /* blocks IFS attack on non-bash shells */
    system( "/path/to/bash/script", argv, envp );
    perror( argv[0] );
    return errno;
}

将C代码中的路径替换为你的脚本的路径,编译为

gcc -o suid-wrapper suid-wrapper.c

并设置权限

chmod 6755 suid-wrapper

suidperl ist 不再是一个选项,它在 perl 5.12 中已被删除而无需替换(参见 perl5120delta,即http://search.cpan.org/~shay/perl-5.20.2/pod/perl5120delta.pod)。

【讨论】:

  • 这是错误的。你不应该打电话给setgid/setuid,因为这会设置真正的 GID/UID(你可能不想要)。另外,system 不是这样工作的(它只需要一个参数),你可能想要execve/execle
  • 我已经通过使用asprintf(&amp;command, "script.sh %s", argv[1]); 在命令中包含参数来使这个解决方案工作,但我知道这不安全。您能否提出执行此操作的最佳实践方法?谢谢。 @Timmermans @yadutaf
  • system() is declared as int system(const char *string); 这段代码比错误更糟糕 - 它声称阻止 IFS 攻击,但没有这样做。
猜你喜欢
  • 2015-01-25
  • 1970-01-01
  • 1970-01-01
  • 2014-07-17
  • 1970-01-01
  • 2014-08-07
  • 1970-01-01
  • 2014-09-28
  • 1970-01-01
相关资源
最近更新 更多