1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196
| #include <stdio.h> #include <stdlib.h> #include <unistd.h> #include <sys/types.h> #include <grp.h> #include <pwd.h> #include <string.h>
typedef struct { gid_t gid; char group_name[256]; int is_primary; int is_effective; int is_supplementary; } group_info_t;
int compare_gids(const void *a, const void *b) { gid_t gid_a = ((group_info_t*)a)->gid; gid_t gid_b = ((group_info_t*)b)->gid; return (gid_a > gid_b) - (gid_a < gid_b); }
void analyze_process_groups() { gid_t primary_gid, effective_gid; int sup_count; gid_t *sup_groups = NULL; group_info_t *all_groups = NULL; int total_groups = 0; printf("=== 进程组权限完整分析 ===\n"); // 获取基本信息 primary_gid = getgid(); effective_gid = getegid(); printf("进程基本信息:\n"); printf(" 真实用户 ID: %d\n", getuid()); printf(" 有效用户 ID: %d\n", geteuid()); printf(" 真实组 ID: %d\n", primary_gid); printf(" 有效组 ID: %d\n", effective_gid); // 获取用户信息 struct passwd *pwd = getpwuid(getuid()); if (pwd != NULL) { printf(" 用户名: %s\n", pwd->pw_name); } // 获取补充组 sup_count = getgroups(0, NULL); if (sup_count > 0) { sup_groups = malloc(sup_count * sizeof(gid_t)); if (sup_groups == NULL) { perror("内存分配失败"); return; } if (getgroups(sup_count, sup_groups) == -1) { perror("获取补充组失败"); free(sup_groups); return; } } // 创建完整的组信息列表 total_groups = 2 + sup_count; // primary + effective + supplementary all_groups = malloc(total_groups * sizeof(group_info_t)); if (all_groups == NULL) { perror("内存分配失败"); if (sup_groups) free(sup_groups); return; } int index = 0; // 添加主要组 all_groups[index].gid = primary_gid; all_groups[index].is_primary = 1; all_groups[index].is_effective = (primary_gid == effective_gid); all_groups[index].is_supplementary = 0; struct group *grp = getgrgid(primary_gid); if (grp != NULL) { strncpy(all_groups[index].group_name, grp->gr_name, sizeof(all_groups[index].group_name) - 1); } else { snprintf(all_groups[index].group_name, sizeof(all_groups[index].group_name), "group_%d", primary_gid); } index++; // 添加有效组(如果不同于主要组) if (effective_gid != primary_gid) { all_groups[index].gid = effective_gid; all_groups[index].is_primary = 0; all_groups[index].is_effective = 1; all_groups[index].is_supplementary = 0; struct group *grp = getgrgid(effective_gid); if (grp != NULL) { strncpy(all_groups[index].group_name, grp->gr_name, sizeof(all_groups[index].group_name) - 1); } else { snprintf(all_groups[index].group_name, sizeof(all_groups[index].group_name), "group_%d", effective_gid); } index++; } // 添加补充组 for (int i = 0; i < sup_count; i++) { // 检查是否已存在 int exists = 0; for (int j = 0; j < index; j++) { if (all_groups[j].gid == sup_groups[i]) { all_groups[j].is_supplementary = 1; exists = 1; break; } } if (!exists) { all_groups[index].gid = sup_groups[i]; all_groups[index].is_primary = 0; all_groups[index].is_effective = (sup_groups[i] == effective_gid); all_groups[index].is_supplementary = 1; struct group *grp = getgrgid(sup_groups[i]); if (grp != NULL) { strncpy(all_groups[index].group_name, grp->gr_name, sizeof(all_groups[index].group_name) - 1); } else { snprintf(all_groups[index].group_name, sizeof(all_groups[index].group_name), "group_%d", sup_groups[i]); } index++; } } total_groups = index; // 按组 ID 排序 qsort(all_groups, total_groups, sizeof(group_info_t), compare_gids); // 显示结果 printf("\n完整的组权限信息:\n"); printf("%-8s %-10s %-12s %-12s %-15s %s\n", "序号", "组ID", "主要组", "有效组", "补充组", "组名"); printf("%-8s %-10s %-12s %-12s %-15s %s\n", "----", "----", "----", "----", "----", "----"); for (int i = 0; i < total_groups; i++) { printf("%-8d %-10d %-12s %-12s %-15s %s\n", i + 1, all_groups[i].gid, all_groups[i].is_primary ? "是" : "否", all_groups[i].is_effective ? "是" : "否", all_groups[i].is_supplementary ? "是" : "否", all_groups[i].group_name); } // 统计信息 printf("\n统计信息:\n"); printf(" 总组数: %d\n", total_groups); int primary_count = 0, effective_count = 0, supplementary_count = 0; for (int i = 0; i < total_groups; i++) { if (all_groups[i].is_primary) primary_count++; if (all_groups[i].is_effective) effective_count++; if (all_groups[i].is_supplementary) supplementary_count++; } printf(" 主要组: %d\n", primary_count); printf(" 有效组: %d\n", effective_count); printf(" 补充组: %d\n", supplementary_count); // 特殊权限检查 printf("\n特殊权限检查:\n"); int has_root_group = 0; int has_admin_group = 0; for (int i = 0; i < total_groups; i++) { if (all_groups[i].gid == 0) { has_root_group = 1; } // 检查常见的管理员组 if (strcmp(all_groups[i].group_name, "wheel") == 0 || strcmp(all_groups[i].group_name, "sudo") == 0 || strcmp(all_groups[i].group_name, "adm") == 0) { has_admin_group = 1; } } printf(" Root 组权限: %s\n", has_root_group ? "是" : "否"); printf(" 管理员组权限: %s\n", has_admin_group ? "是" : "否"); // 清理内存 if (sup_groups) free(sup_groups); if (all_groups) free(all_groups); }
int main() { analyze_process_groups(); return 0; }
|