Operating System - HP-UX
1833737 Members
2776 Online
110063 Solutions
New Discussion

restrict suid and sgid permissions

 
Dennis Handly
Acclaimed Contributor

Re: restrict suid and sgid permissions

>Laurent: if a non root user modify a program with SUID root set, the SUID is reset.

Hmm, what you say is true but where is it documented? This almost seems like a near useless feature since root shouldn't make the executables writable. But I guess it protects the uninformed. I.e.
>4) The program's permission list does not allow write access to users who do not require it.

There should be NOBODY that can write to these SUID root executables. (And root can just bypass the missing u+w.)

>Laurent: If you want to modify the rights of all those files, then you need to contact the various support:
HP support for /var/adm

I think just saying these files come from HP should be good enough for the auditors.