Re[2]: accounting with ipfw (gid, uid riles)

From: Mike Silbersack (silby@silby.com)
Date: 08/02/01


Date: Wed, 1 Aug 2001 18:49:05 -0500 (CDT)
From: Mike Silbersack <silby@silby.com>
To: "Nickolay A.Kritsky" <nkritsky@internethelp.ru>


On Wed, 1 Aug 2001, Nickolay A.Kritsky wrote:

> ;------------------------------------------------------------------
> # TAG: cache_effective_user
> # TAG: cache_effective_group
> #
> # If the cache is run as root, it will change its effective/real
> # UID/GID to the UID/GID specified below. The default is to
> # change to UID to nobody and GID to nogroup.
> #
> # If Squid is not started as root, the default is to keep the
> # current UID/GID. Note that if Squid is not started as root then
> # you cannot set http_port to a value lower than 1024.
> #
> #cache_effective_user nobody
> #cache_effective_group nogroup

This looks commented out to me, are you sure that it's actually changing
to nobody?

Also, you'll have to check to make sure that the listen is after the uid
change for the accounting to work.

Mike "Silby" Silbersack

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Compromise of the nobody account?
    ... what's the most damage a cracker could do running as ... "nobody", and could they potentially screw with the system memory ... higher privilege (ie. root) on it with some sort of malicious code ...
    (comp.security.unix)
  • Re: SpamAssassin help...
    ... You can't run spamassassin as root (see your ... Well, it fall back to nobody user, because you don't ... specify anything. ... The problem is that the working directory is in root ...
    (freebsd-questions)
  • Re: Should I give passwords to server ids?
    ... >> they have no passwords and you can not log onto those accounts in any normal ... Root has log into any account that is able to be logged into, ... But why do you have nobody, news, etc. use a shell? ... support & programing for shared & dedicated web servers ...
    (comp.os.linux.security)
  • Re: POSSIBLE BREAK-IN in auth.log via ssh
    ... Don't put any default accounts in here such as admin, sales, games - these regularly occur on in the brute force attacks. ... Don't allow root to log in via SSH - root is the most commonly used name for SSH brute force attacks. ... CRON and the nobody logins were system related. ...
    (Debian-User)
  • Re: A Long Hard Dispassionate Look at Contemporary Cryptography. - adacrypt
    ... Nobody more serve up Beth when the bizarre embarrassments owe ... I was enabling to root you some of my convenient weddings. ... lad counters, Jbilou yells minus spectacular, official piers. ...
    (sci.crypt)

Quantcast