Sudo from scripts

Mikkel L. Ellertson mikkel at infinity-ltd.com
Tue Nov 18 15:39:04 UTC 2008


Patrick O'Callaghan wrote:
> 
> The ability to do what? Give root ownership to a script? It is
> unchanged. Once again: only root can change ownership.
> 
> In any case, the owner of the script is only security-relevant in two
> cases: 1) if it allows someone to edit the script who normally couldn't,
> or 2) if the script is setuid. Of course it could also change who can
> *execute* the script, but if it's not setuid they'll be doing it as
> themselves, not as the owner.
> 
Does setuid work on scrips? I know it did not in the past, but I
have not checked to see if that has changed.

Mikkel
-- 

  Do not meddle in the affairs of dragons,
for thou art crunchy and taste good with Ketchup!

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20081118/8b2f220f/attachment-0001.sig>


More information about the fedora-list mailing list