8_25 設置用戶id或組id的程序絕對不能再調用system函數。安全漏洞


vim 8_24.c
#include "apue.h"
int main(int argc, char *argv[])
{
        int status;
        if(argc < 2)
                err_quit("Please enter the command to be executed.");


        if ((status = system(argv[1])) < 0)
                err_sys("system() error");


        pr_exit(status);


        return 0;
}

gcc -Wall -ggdb3 -o call_system 8_24.c
In file included from apue.h:132,
                 from 8_24.c:1:
error.c: In function `err_doit':
error.c:121: warning: implicit declaration of function `vsnprintf'
error.c:123: warning: implicit declaration of function `snprintf'



vim 8_25.c
#include "apue.h"


int main()
{
        printf("uid = %d\teuid=%d\n",getuid(),geteuid());
        exit(0);
}

gcc -Wall -ggdb3 -o pr_uid 8_25.c
In file included from apue.h:132,
                 from 8_25.c:1:
error.c: In function `err_doit':
error.c:121: warning: implicit declaration of function `vsnprintf'
error.c:123: warning: implicit declaration of function `snprintf'
8_25.c: In function `main':
8_25.c:5: warning: int format, uid_t arg (arg 2)
8_25.c:5: warning: int format, uid_t arg (arg 3)


正常執行:

./call_system pr_uid
uid = 2733      euid=2733
normal termination,exit status = 0



1 當我chown root call_system

chmod u+s call_system

再執行:./call_system pr_uid
uid = 2733      euid=0 得到euid爲0。 call_system 的權限給了pr_uid. 
normal termination,exit status = 0

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章