named under a different userid

David Jonsson david.jonsson at interactiveinstitute.se
Wed Jan 5 15:30:44 UTC 2000


All hacks and cracks could be avoided if the named run under uid other than
root. Right? No one would be interested in breaking in through named if it
ran as nobody (just like httpd does).

Would it suffice to use setuid just after the socket has opened?

David




More information about the bind-users mailing list