[Asterisk-Users] vmail.cgi: -rwsr-sr-x as root *still* won't read the files

Tzafrir Cohen tzafrir at cohens.org.il
Sun May 1 08:40:39 MST 2005


On Fri, Apr 29, 2005 at 10:50:42AM -0400, mike castleman wrote:
> On Fri, Apr 29, 2005 at 12:23:48AM -0500, Brian Capouch wrote:
> > 
> > Drat.  Perl screams bloody murder if you try to just set its SUID bit, 
> > which of course is dangerous as hell.
> 
> The perl-suid is *not* simply a version of perl with the suid bit set
> but rather a helper binary which allows perl to run suid scripts. Try
> it.

Note that this script does not use any of the standard safety mechanisms
perl provides to achive some safety. It does not use -w or -T or strict.
Nor is it simple to adapt it to use those.

-- 
Tzafrir Cohen         | tzafrir at jbr.cohens.org.il | VIM is
http://tzafrir.org.il |                           | a Mutt's  
tzafrir at cohens.org.il |                           |  best
ICQ# 16849755         |                           | friend



More information about the asterisk-users mailing list