If anybody has access to a complete mirror of the Debian Wheezy release, and was willing to share a list of all setuid/setgid binaries that would be greatly appreciated.
It doesn't seem to be something you can find online, so you need to manually unpack each .deb file and look at the permissions.
I don't have access to a (complete) local mirror, and so I cannot easily build such a thing, unless I go to ebay and buy a random DVD-archive.
This list would be useful for folk wanting to direct their audits ..
Tags: setgid, setuid, wheezy 13 comments
Some suggestions have been made above on how to arrive at at least some kind of initial list, which would perhaps need to be enlarged by doing codesearch for the right chmod patterns in postinst scripts; some manual work will in the end be involved so it makes sense to create the list one place and have it edited collaboratively.
I think the security tracker repository can be a good place for such a list. It could also be a good list for the hardened build flags effort to concentrate on; in parallel to any auditing going on.