<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Frecovering suid programs in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575679#M858360</link>
    <description>Thanks Guys,&lt;BR /&gt;&lt;BR /&gt;I am trying to recover files owned by the ingres user as the ingres user.  I understand the security implecations of letting users recover other users suid programs but what is the problem with recovering your own?</description>
    <pubDate>Thu, 06 Sep 2001 07:51:50 GMT</pubDate>
    <dc:creator>Chris Evans_1</dc:creator>
    <dc:date>2001-09-06T07:51:50Z</dc:date>
    <item>
      <title>Frecovering suid programs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575676#M858357</link>
      <description>Hi all,&lt;BR /&gt;&lt;BR /&gt;I am suffering a little at the moment with a problem using frecover.&lt;BR /&gt;&lt;BR /&gt;As root I can frecover any file with the suid bit set but as a non root user the file is recovered with just the execute bits set.   Is this the standard behaviour?  Am I doing something stupid?  &lt;BR /&gt;&lt;BR /&gt;I have tried this on 10.20 and on 11.00 so I don't think it is a patch level problem.</description>
      <pubDate>Wed, 05 Sep 2001 15:19:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575676#M858357</guid>
      <dc:creator>Chris Evans_1</dc:creator>
      <dc:date>2001-09-05T15:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: Frecovering suid programs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575677#M858358</link>
      <description>Chris,&lt;BR /&gt;&lt;BR /&gt;It makes perfect sense to me frecover not recovering SUID programs for ordinary user. So the case, I can restore an SUID program from  the back myself and become a super user.&lt;BR /&gt;&lt;BR /&gt;I believe it's a feature of frecover though officially I am not sure :-)&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Wed, 05 Sep 2001 15:26:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575677#M858358</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2001-09-05T15:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Frecovering suid programs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575678#M858359</link>
      <description>Hi Chris,&lt;BR /&gt;&lt;BR /&gt;This is perfectly normal behavior otherwise there would be a huge security problem. In fact, try this: Create a file my.exe owned by root and make it 4755 \via chmod. Nexp cp -p my.exe my2.exe as an ordinary user. You will see that the setuid bit is cleared in the copy.&lt;BR /&gt;If it worked any other way, it would be trivially easy for any user to create a setuid program owned by root.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Sep 2001 17:19:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575678#M858359</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2001-09-05T17:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Frecovering suid programs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575679#M858360</link>
      <description>Thanks Guys,&lt;BR /&gt;&lt;BR /&gt;I am trying to recover files owned by the ingres user as the ingres user.  I understand the security implecations of letting users recover other users suid programs but what is the problem with recovering your own?</description>
      <pubDate>Thu, 06 Sep 2001 07:51:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575679#M858360</guid>
      <dc:creator>Chris Evans_1</dc:creator>
      <dc:date>2001-09-06T07:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: Frecovering suid programs</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575680#M858361</link>
      <description>&lt;BR /&gt;fbackup / frecover seem not to support non-root users quite well. (I get a "fbackup(1010): semget failed for the semaphore" if I try fbackup).&lt;BR /&gt;&lt;BR /&gt;You can use tar -px to recover the setuid bit of a file owned by yourself. I do not see a security hole there, because it is possible to set the bit to the original file as well. cp -p works this way, too.&lt;BR /&gt;&lt;BR /&gt;Klaus</description>
      <pubDate>Thu, 06 Sep 2001 08:29:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/frecovering-suid-programs/m-p/2575680#M858361</guid>
      <dc:creator>Klaus Crusius</dc:creator>
      <dc:date>2001-09-06T08:29:20Z</dc:date>
    </item>
  </channel>
</rss>

