Mombu the Programming Forum

Go Back   Mombu the Programming Forum > Programming > taint: system vs. backticks and permissions
User Name
Password
REGISTER NOW! Mark Forums Read




Reply Bookmark and Share
1 13th November 02:34
kristina clair
External User
 
Posts: 1
Default taint: system vs. backticks and permissions



Hi,

I have a perl script running suid root (thus running in taint mode), and
I'm trying to execute a shell command. Usually I do this using
backticks so I can get the output, and usually it is not a problem.

However, in this instance I am trying to execute a python script, and
the python script does not seem to be running as root, but as the apache
user.

Interestingly, using system() changes this and the python script runs
appropriately as root. But, I'm having the following problems:

- if I use system("/python/command args") then the python script
executes appropriately but the output from the python script is being
sent to httpd and i'm getting an internal server error due to malformed
headers

- if I use system("/python/command args >/dev/null") perl does not like
this at all and it seems to not only not execute the python script, but
it runs the perl script again from the beginning (!?!?!?!)

So I'm very confused by this behavior. Does anyone have any ideas about
what is going on? What is the difference between using backticks and
system() in terms of how the perl script is calling the python script?
And is there a way for system() to be happy but not send output to httpd?

Thanks for any help.
Kristina
  Reply With Quote


 


Reply


Thread Tools
Display Modes


Some other forums that might be of your interest : Development, Ada, Apple script, Assembler, Awk, Beos, Basic, C, C++, C#, C# .net, .net, .net frameworks, Asp .net, Clarion, Clipper, Clos, Clu, Cobol, Coldfusion, Delphi, Dylan, Eiffel, Forth, Fortran, Haskell, Hermes, Icon, Idl, Java, Java script, Jscript .net, Jcl, Linoleum, Lisp, Lotus, Limbo, Logo, Ml, Mumps, Oberon, Postscript, Pop, Pl1, Prolog, Python, Ruby, Pascal, Perl, Php, Rebol, Rexx, Sed, Sather, Scheme, Smalltalk, Tcl, Vhdl, Vrml, Visual basic, Visual basic .net, Yorick, Mysql, Omnis, Postgresql, Xbase, Access, Oracle, Adabas, Berkeley, Btrieve, Filemaker, Gupta, Db2, Informix, Ingres, Mssql server, Object, Olap, Paradox, Rdb, Revelation, Sybase, Theory, Dbase, Html, Java script, Css, Flash, Photoshop, Corel script, Xml, Tech, Beos, Gem, Hp48, Hpux, Linux, Mac, Ms-dos, Os2, Palm, Solaris, Ti99, Windows, Xenix, Aos, Chorus, Geos, Inferno, Lantastic, Lynx, Mach, Minix, Netware, Os9, Parix, Plan9, Psos, Qnx, Xinu, Sco, Unix, Aix, Aux, 386bsd, Bsdi, Freebsd, Netbsd, Openbsd, Ultrix, Amd, Intel, Aptiva, Buz, Deals, Homebuilt, Overclocking, Programming, Extra forums


Copyright © 2006 SmartyDevil.com - Dies Mies Jeschet Boenedoesef Douvema Enitemaus -
666