-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I'm reposting this as no one has responded. Is there something in here
in particular that would have caused a problem? I guess I use multiple
commands, but there is no use of % variables inside my one script that
formats the date.

Jeremy Allison wrote:
> On Mon, Feb 11, 2008 at 11:04:25AM -0800, Robert wrote:
>
>> Is this perhaps related to the folowing bug:
>>
>> https://bugzilla.samba.org/show_bug.cgi?id=4812
>
> Yes, this is certainly it. We're not going to
> fix this though - the security change was painful enough
> that I don't feel safe in allowing arbitrary characters
> in smb.conf scripts - remember the % substitution can
> allow client input here. The best solution is to rewite
> prexecs to use a single script.

I'm not sure if I got nailed by this one, but I'm doing this:

root preexec=/bin/sh -c 'echo C:
\%u,\%m,%I::`/etc/opt/samba/scripts/getdate`' >> /var/opt/samba/accounting

root postexec=/bin/sh -c 'echo X:
\%u,\%m,\%I::`/etc/opt/samba/scripts/getdate`' >> /var/opt/samba/accounting

...and it seems to have stopped working when I upgraded from 3.0.11 to
3.0.22-ish. I suspect that nesting that script like that might be the
problem.

It's not clear to me what actually changed -- anyone have a link about
this? I haven't been able to find it in the release notes.

- --
 ---- _  _ _  _ ___  _  _  _
 |Y#| |  | |\/| |  \ |\ |  | |Ryan Novosielski - Systems Programmer II
 |$&| |__| |  | |__/ | \| _| |[EMAIL PROTECTED] - 973/972.0922 (2-0922)
 \__/ Univ. of Med. and Dent.|IST/AST - NJMS Medical Science Bldg - C630
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFH0bcumb+gadEcsb4RAsF/AKChsZpi4+XD62rdsoye/d/G3big0QCgqoS0
sA9/eOGp1pbHMx388l8NcEw=
=pNro
-----END PGP SIGNATURE-----
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba
-- 
To unsubscribe from this list go to the following URL and read the
instructions:  https://lists.samba.org/mailman/listinfo/samba

Reply via email to