[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Logs and Permissions for Daemons



Previously Herbert Xu wrote:
> There is a very good reason that those things created new users, because they
> have to read/write files owned by those users.

Even when not reading/writing files, you can attack the running process
as well.

> As to the fact that we only have a limited number of users, I agree it's a
> problem.  Perhaps we should address it by allocating new chunks in the uid
> space for system users.

We have a whole range (60000-64999) of reserved static uids and gids..
So far only netplan and ftn are using it. (I want qmail moved to that
range as well btw).

Wichert.

-- 
   ________________________________________________________________
 / Generally uninteresting signature - ignore at your convenience  \
| wichert@liacs.nl                    http://www.liacs.nl/~wichert/ |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |

Attachment: pgpbh4DaP_biL.pgp
Description: PGP signature


Reply to: