Path: utzoo!mnetor!uunet!husc6!cmcl2!brl-adm!brl-smoke!gwyn From: gwyn@brl-smoke.ARPA (Doug Gwyn ) Newsgroups: comp.unix.wizards Subject: Re: Guide to writing secure setuid programs? Message-ID: <7477@brl-smoke.ARPA> Date: 20 Mar 88 01:22:44 GMT References: <181@wsccs.UUCP> <722@rivm05.UUCP> <1037@woton.UUCP> <239@piring.cwi.nl> <127@heart-of-gold> Reply-To: gwyn@brl.arpa (Doug Gwyn (VLD/VMB) ) Organization: Ballistic Research Lab (BRL), APG, MD. Lines: 8 In article <127@heart-of-gold> jc@heart-of-gold (John M Chambers x7780 1E342) writes: -> And, of course, the general rule is not to write setuid programs -> in the first place, but that has been handled by other people. -One question I have: To my knowledge, there does not actually exist a way -to "write a setuid program". That phrase is just shorthand for "write a program that will have to have the resulting binary made set-UID to do its job properly".