Re: IMPORTANT CORRECTION!!! IFS effective user

Patrick Botz <botz-r/[email protected]>
Newsgroups gmane.comp.systems.as400.security
Message-ID <OFFD939404.97FF172A-ON86256FC1.006B4527-86256FC2.0007F7E9@us.ibm.com>
> These should not remain in effect after the program that adds them
> completes (i.e. removed from the stack).  If you are convinced that they
> really do, you should probably report it as a bug....

I was flat-out wrong about this.  Thanks to Ed Fishel for reminding me how
this stuff works...(in a shameless attempt to provide a lousy reason for
being wrong, we designed and implemented

If the program does not reset the original contents, these changes DO
remain in affect!!!!!

Adopted authority is done by adding information to each stack-frame in a
process.  Therefore, when the stack-frame is removed, the adopted authority
goes away.

A swap (and setuid) changes the users and groups for a job.  Like a swap,
the setuid stuff is NOT removed when the program in a stack-frame that
caused the change is removed.

I apologize for providing incorrect information!!!!


Patrick Botz
Senior Technical Staff Member
eServer Security Architect
(507) 253-0917, T/L 553-0917
email: botz-r/[email protected]


_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.