In <1992Nov14.074521.17444@ccds3.ntu.edu.tw> ywtsay@aquarius.ce.ntu.edu.tw (Yi-Hwai Tsai) writes:
>Hi..
> There may have '/usr/diag/bin/DUI' in many HP-UX 8.0 machines. It is setuid by root. I don't think it should be run by everyone in host. because it can be used to empty any file in system. Am I right ?
I do not know DUI but *beware*: the /usr/diag directory do contains
**SUID'ed SCRIPTS** and this is a terrible security hole: due a bug
in the kernel everyone can become root in a matter of seconds. Please
`chmod u-s` the SUID'ed scripts you get: there should be not SUID'ed
script to root in your whole file system.
Regards,
David
--
David Vincenzetti := {system, security} administrator
Dept of CS, via Comelico 41, Email : vince@ghost.dsi.unimi.it