Re: tcpdump privsep design

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Otto Moerbeek
Date: Saturday, January 16, 2010 - 12:28 am

On Fri, Jan 15, 2010 at 10:21:15PM -0500, Ted Unangst wrote:


Alternatively, you could force -w to always write to stdout and use
sudo. But remember that you might NOT want to allow -r to read
arbitrary files. As you can see, before you know it pretty
"interesting" problems pop up.

It was a conscious decision to only allow root. The beast is just too
complex to trust as a setuid program.

	-Otto
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
tcpdump privsep design, Denis Doroshenko, (Fri Jan 15, 11:21 am)
Re: tcpdump privsep design, Abel Abraham Camaril ..., (Fri Jan 15, 2:37 pm)
Re: tcpdump privsep design, Stuart Henderson, (Fri Jan 15, 2:49 pm)
Re: tcpdump privsep design, Abel Abraham Camaril ..., (Fri Jan 15, 4:59 pm)
Re: tcpdump privsep design, Ted Unangst, (Fri Jan 15, 8:21 pm)
Re: tcpdump privsep design, Otto Moerbeek, (Sat Jan 16, 12:28 am)