Re: www user than root

From: Jeremie Le Hen (jeremie_at_le-hen.org)
Date: 06/23/05

  • Next message: Jeremie Le Hen: "Re: www user than root"
    Date: Thu, 23 Jun 2005 15:30:02 +0200
    To: Abu Khaled <khaled.abu@gmail.com>
    
    

    Hi Khaled,

    > Is it a good idea to run daemons on non privileged ports as a normal
    > user (eg. www) then have natd or a firewall redirect the traffic
    > targetting the privileged port.
    >
    > For example:
    >
    > A web server running as user www on port 8000.
    > IPFW, IPNAT, PF or NATD redirecting port 80 to port 8000.
    >
    > Is such a soloution a good idea?
    > I read in man natd that one can redirect traffic comming on the
    > gateway on port 80 to one or many servers running daemons on non
    > privileged ports.

    Yes it might be a good idea, but again, it depends on your security
    requirements : any user is able to bind port 8000, so if you have
    other users on the system, this may not be something to avoid.
    But FWIW, this would totally remove the need to make a privileged part
    in your application.

    Regards,

    -- 
    Jeremie Le Hen
    < jeremie at le-hen dot org >< ttz at chchile dot org >
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Jeremie Le Hen: "Re: www user than root"

    Relevant Pages

    • Re[2]: sshd port number ?
      ... >> version of ssh and do some nasty stuff. ... >> privileges can bind to a privileged port. ... D> configure what proc is assigned to what privileged port? ... If the superuser does want to bind to the ...
      (freebsd-questions)
    • Re: www user than root
      ... then change the effective UID after binding to the port. ... > privileged port lately and you want security. ... IPFW, IPNAT, PF or NATD redirecting port 80 to port 8000. ... I read in man natd that one can redirect traffic comming on the ...
      (freebsd-net)
    • Re: What are these services ?
      ... >> Services used by hackers to DOS other peoples machines or yours. ... >> sending a UDP packet with source port echo-udp to destination port ... my Netgear router blocks all incoming external traffic ...
      (comp.os.linux.security)
    • Re: Hardening a Solaris system.
      ... >> The reason why a privileged port was chosen was presumably the ... >> environment) only trusted people have root. ... > That gets to another reason why it's important. ...
      (comp.unix.solaris)
    • Re: Hardening a Solaris system.
      ... >> The reason why a privileged port was chosen was presumably the ... >> environment) only trusted people have root. ... > That gets to another reason why it's important. ...
      (comp.security.unix)