SPS - a useful replacement for ps(1

gordon at sneaky gordon at sneaky
Tue Jul 9 11:38:00 AEST 1985


> /* Written  2:43 pm  Jul  3, 1985 by hslrswi.U!robert in sneaky:net.sources.bu */
> ...
> One solution, suggested by Jeffrey Mogul, is to renice sps only for root.
> This also means that sps need not be a setuid program.
> ...
> 
> (Robert Ward, Hasler AG, Belpstrasse 23, CH-3000 Bern 14, Switzerland).
> /* End of text from sneaky:net.sources.bu */

I sure hope sps still needs to be a privileged program!  Maybe on your system
you can get away with using setgid sys instead of setuid root, but if your
system has /dev/mem, /dev/kmem, and/or /dev/swap readable by everyone, you
are just asking to have your root password stolen by someone's "clist watcher"
program.

Sps, by the way, should do its setuid(getuid()) AFTER it gets /dev/mem, 
/dev/kmem, and /dev/swap open.


					Gordon Burditt
					...!convex!ctvax!trsvax!sneaky!gordon
					...!ihnp4!sys1!sneaky!gordon



More information about the Comp.sources.bugs mailing list