Unix Technical Forum

Re: drop privileges to nobody is pinging as root

This is a discussion on Re: drop privileges to nobody is pinging as root within the lucky.openbsd.tech forums, part of the OpenBSD category; --> Theo de Raadt wrote: > Han wrote: > > Theo de Raadt wrote: > > > I still do ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-22-2008, 01:09 PM
Han Boetes
 
Posts: n/a
Default Re: drop privileges to nobody is pinging as root

Theo de Raadt wrote:
> Han wrote:
> > Theo de Raadt wrote:
> > > I still do not agree at all with doing this. Sorry. "nobody"
> > > is special, and should not be misused like this.

> >
> > OK, I can get along with that idea. Is there a more suitable
> > account for dropping privileges?

>
> No. Of course not. Any account has some privilege.
>
> > Should a `_drop' account be
> > created for this and other instances of dropping privileges for
> > dangerous actions by root?

>
> Oh, so that if 2 programs are running at the same time, they now
> have the same uid, and they can now "play with each other"?
>
> Every uid still has some permissions.
>
> > Or is this construction really not necessary?

>
> I really don't see what is gained.


Alright, thanks for your time.

On a sidenote, I would like to recommend choosing neutral
formulations.



# Han

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:26 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com