Re: [SLUG] suid woes

From: Eben King (eben1@tampabay.rr.com)
Date: Sun Nov 23 2003 - 23:18:00 EST


On Sun, 23 Nov 2003, Andrew M. Hoerter wrote:

> On Sun, 23 Nov 2003, Eben King wrote:
>
> > I do this:
> > vmware &
> > ps ax -o user,command | grep vmware
> >
> > and see
> >
> > root /usr/bin/vmnet-dhcpd -cf /etc/vmware/vmnet8/dhcpd/dhcpd.conf -lf /etc/v
> > eben vmware
> > eben vmware-ui -A 7 -B 4 -S -L /tmp/vmware-eben-2883.log -E none
> > eben vmware-mks -A 8 -B 5 -S -L /tmp/vmware-eben-2883.log -P 2883 -E none
> >
> > Why is the OS not honoring the suid bit?
>
> Is 'vmware' a shell script? Suid/sgid bits usually aren't honored on
> those (for good reason).

No it's not.

> Otherwise, it's possible that the program is dropping root privs on
> purpose.

I guess so.

> I'm not familiar with VMware under Linux, but is it possible to give
> ownership of the virtual disks to your regular UID and then run it
> normally (non-suid)?

I don't know why it was suid. Hang on, I'll try without it. ...

VMware Workstation Error:
VMware Workstation must be set-UID root, "vmware" is not. Are you running
vmware from its distribution directory? That copy of the program is not
set-UID root.

Guess it has to be suid. Probably to grab those ports <1024 Windows
Networking wants. VMware supports any OS you want, so it probably grabs
all of the ports, just in case.

Anyhow, changing the ownership of /usr/lib/vmware/win2000/* to me fixed
the problem. Thanks. I don't know how it got changed. Probably improper
tar usage.

VMware wants shared disks. Got to get Samba beaten into shape, then inn, ...

-- 
-eben    ebQenW1@EtaRmpTabYayU.rIr.OcoPm    home.tampabay.rr.com/hactar

Every normal man must be tempted at times to spit upon his hands, hoist the black flag, and begin slitting throats. -- H.L. Mencken

----------------------------------------------------------------------- This list is provided as an unmoderated internet service by Networked Knowledge Systems (NKS). Views and opinions expressed in messages posted are those of the author and do not necessarily reflect the official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 18:06:58 EDT