469,322 Members | 1,615 Online
Bytes | Developer Community
New Post

Home Posts Topics Members FAQ

Post your question to a community of 469,322 developers. It's quick & easy.

perl "Insecure dependency in `` while running setuid"

When I ran a perl script named script.pl which have the the follwing line:
system("echo hostname = $HOSTNAME > /tmp/myinfo");
I have another shell script script.ksh which simply call script.pl within the script. the permission on script.ksh is: -rwsr-sr-x
WHen I ran script.ksh, I got the error message:
Insecure dependency in `` while running setuid at script.pl line 4.
If I do not use $HOSTNAME in script.pl, I have no trouble at all.
Could someone help me on this? Looks like setuid and $HOSTNAME variable cannot work together.

Thanks in advance.
Aug 29 '06 #1
2 9005
bharad
7
make sure you untaint the data before executing the scripts.

try this
if ($HOSTNAME =~ /^([ &:#-\@\w.]+)$/) {
$HOSTNAME = $1; #data is now untainted
} else {
print "bad data\n";
}

-bharad


When I ran a perl script named script.pl which have the the follwing line:
system("echo hostname = $HOSTNAME > /tmp/myinfo");
I have another shell script script.ksh which simply call script.pl within the script. the permission on script.ksh is: -rwsr-sr-x
WHen I ran script.ksh, I got the error message:
Insecure dependency in `` while running setuid at script.pl line 4.
If I do not use $HOSTNAME in script.pl, I have no trouble at all.
Could someone help me on this? Looks like setuid and $HOSTNAME variable cannot work together.

Thanks in advance.
Aug 30 '06 #2
Thank you so much! it works.
Aug 30 '06 #3

Post your reply

Sign in to post your reply or Sign up for a free account.

Similar topics

3 posts views Thread by John Spiegel | last post: by
2 posts views Thread by Wiktor Zychla | last post: by
3 posts views Thread by Claire | last post: by
4 posts views Thread by Mr BigSmoke | last post: by
5 posts views Thread by =?Utf-8?B?RGF2aWQgVGhpZWxlbg==?= | last post: by
reply views Thread by =?Utf-8?B?QmVybnJkIE5vcm1pZXI=?= | last post: by
1 post views Thread by CARIGAR | last post: by
reply views Thread by zhoujie | last post: by
reply views Thread by suresh191 | last post: by
reply views Thread by Gurmeet2796 | last post: by
reply views Thread by harlem98 | last post: by
By using this site, you agree to our Privacy Policy and Terms of Use.