Great Circle Associates Firewalls
(September 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Privileged ports and root was Re: qmail
From: Matthew Patton <patton @ sysnet . net>
Date: Thu, 4 Sep 1997 23:48:18 -0400
To: firewalls @ GreatCircle . COM
In-reply-to: <Pine . LNX . 3 . 96 . 970904154816 . 3493F-100000 @ Bunuel . tii . matav . hu>
References: <199709041033 . MAA21536 @ saris . unipo . sk>

ok, I'm deviating slightly from the firewall charter but how hard would it
be to yank the idea of privileged ports having to belong to root (or for
that matter anybody)? In this day and age when people run their own Linux
boxen and have root access at will, trusting anything because it's
originating from <1025 seems specious at best.

So as it applies to qmail. What if the mail spool was constructed such that
the owner of mail had RW as did the mail daemon but everybody else was 0
(ie 660)? If you have a scenario whereby a mailer would be filing incoming
letters DIRECTLY into a user's home directory you have another problem but
if the directory ACL is 755 and the incoming mailbox had 660 then you
wouldn't have a problem. Right?

Surely I can't be the only one who's thought about stripping out the overly
common use of root for daemons and force them to run as normal users to
include binding to low ports. (yes kernel hacking is involved) What if we
had a portbind group that contained all of the listening daemons? inetd
would have to be looked at as well. Could those who have tried this sort of
project fill me/us in on the problems encountered? When I'm done with my NT
project I might take some time and play with my OpenBSD box.

KeyID = E6A285A2  FingerPrint = 3B1ACE7A081E926C2B4B  8E745FC748ACE6A285A2

Windows95: noun. 32-bit extensions and a graphical shell for a 16-bit
  patch to an 8-bit operating system originally coded for a 4-bit
  microprocessor, written by a 2-bit company that can't stand 1 bit of
  competition. (author unknown)




References:
  • qmail
    From: Martin Marusak <marusak @ unipo . sk>
  • Re: qmail
    From: "Magossa'nyi A'rpa'd" <mag @ bunuel . tii . matav . hu>
Indexed By Date Previous: Re: LocalDirector question (was: Gauntlet Performance)
From: "R. Todd Truitt" <ttruitt @ cisco . com>
Next: Re: about sendmail security
From: sedwards @ cts . com
Indexed By Thread Previous: Re: qmail
From: "Magossa'nyi A'rpa'd" <mag @ bunuel . tii . matav . hu>
Next: Re: qmail
From: James Croall <jcroall @ foo . org>

Google
 
Search Internet Search www.greatcircle.com