Re: About DNS

From: The Unknown Hacker (jackassdennis@hotmail.nospam.com)
Date: 01/28/03


From: "The Unknown Hacker" <jackassdennis@hotmail.nospam.com>
Date: Tue, 28 Jan 2003 16:24:33 GMT

This is an easy one:
user bind is a privileged user (it can only handle this daemon)
This means that all associated files of named have owner permission for root
and bind
Conclusion: bind is an invoked user and cannot have a shell

"dragon" <siao@eastmail.com> schreef in bericht
news:b168eg$7u7@netnews.hinet.net...
> Fact : Only root can bind the privileged ports(0~1023)
> Fact : DNS service uses port 53
> Fact : In my system, the effective user of the process "named" is "bind"
> Question : How can this user "bind" uses port 53?
>
> Thanks!
>
>



Relevant Pages

  • Re: About DNS
    ... The Unknown Hacker wrote: ... > user bind is a privileged user (it can only handle this daemon) ...
    (comp.os.linux.security)
  • Re: Root cant delete files
    ... I'd say it's time to upgrade to a later version of BIND. ... I would personally recommend that you back up critical ... especially as 'root', it's very hard and very tedious to repair it. ... Make a great connection at Yahoo! ...
    (Focus-Linux)
  • Re: Adctive Directory and Unix DNS
    ... > the Active Directory root domain, ... You can host the AD domain on the BIND servers but without DDNS it can ... have members of the Root domain trying to find the DFS share using the LDAP ... > populate BIND DNS with the AD info if Dynamic DNS is not enabled? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Adctive Directory and Unix DNS
    ... > the Active Directory root domain, ... You can host the AD domain on the BIND servers but without DDNS it can ... have members of the Root domain trying to find the DFS share using the LDAP ... > populate BIND DNS with the AD info if Dynamic DNS is not enabled? ...
    (microsoft.public.windows.server.dns)
  • Re: /var/named Changes Ownership to Root on Boot
    ... It seems that FreeBSD defaults to a chroot of bind with ... the tree owned by root. ... You can run bind in a sandbox as the ... the confusion, you had better disable FreeBSD's attempt to make ...
    (freebsd-questions)