Unix Technical Forum

Re: drop privileges to nobody is pinging as root

This is a discussion on Re: drop privileges to nobody is pinging as root within the mailing.openbsd.tech forums, part of the OpenBSD category; --> > IIRC OpenBSD usually uses separate users for each app that drops/separates > privileges. So a consequential implementation would ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 08:22 AM
Theo de Raadt
 
Posts: n/a
Default Re: drop privileges to nobody is pinging as root

> IIRC OpenBSD usually uses separate users for each app that drops/separates
> privileges. So a consequential implementation would use a user _ping
> instead of reusing nobody in a questionable way. But of course the
> question is valid whether that's worthwhile compared to the theoretical
> risk (low under OpenBSD anyway) that root runs ping and the other host
> could exploit it using crafted response packets.


You have not understood the difference between priv-revocation and
priv-seperation.

Your diff does not help anything.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 07:53 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com