Raw Sockets and Access Denied

From: Richard Chandler (richard.chandler.nospam_at_mapson.monactive.com)
Date: 06/12/03

  • Next message: Frazz Jarvis: "Two-factor authentication systems"
    Date: Thu, 12 Jun 2003 09:19:26 +0100
    
    

    Hi All,

    Having established that high security rights are required to use raw
    sockets, I'm unable to pin down exactly what is required in order to create
    a raw socket.

    I've got around the problem by (a) using the administrator account and (b)
    writing a COM object to do the socket work instead, both of which are
    undesirable solutions.

    What I really want to know is on what security object do I need rights on to
    do this with any user (that is granted that right)... ?

    I was under the false impression that it was to be in the TCB, but having
    checked my security policy that is not the case.

    Can anyone shed any light ?

    Thanks,

    Richard.


  • Next message: Frazz Jarvis: "Two-factor authentication systems"

    Relevant Pages

    • Re: Error when calling a webservice from a windows service
      ... security at server i am using HTTPWebRequest. ... "The remote server returned an error: ... System.IO.Stream httpRequestStream = null; ... connectFailure, Socket s4, Socket s6, Socket& socket, IPAddress& address, ...
      (microsoft.public.dotnet.framework.webservices)
    • Re: How to InitializeSecurity() in a Windows Service
      ... Microsoft MVP, MCSD ... the socket is in a thread. ... >>> I don't know how setting security for the service works for the socket. ... >> CoInitializeSecurity has nothing to do with socket security. ...
      (microsoft.public.vc.atl)
    • Re: not able to create socket ,coz of insufficient user rights
      ... including Ping, the ping function is openning Raw ... Socket is in System.Net.Sockets Namespace not in ... >> failing, I am not able to debug this code. ...
      (microsoft.public.security)
    • Re: [Slightly OT] - Socket Security
      ... > spamtotrash@toomuchfiction.com (Kevin Collins) wrote: ... >> I am working on a security project identifying, ... What are the issues if a socket is ... > I think most versions of Unix ignore the permissions on Unix domain ...
      (comp.unix.shell)
    • [patch 024/198] SELinux: add support for NETLINK_KOBJECT_UEVENT
      ... This patch adds SELinux support for the KOBJECT_UEVENT Netlink family, ... this family simply defaults to the default Netlink socket ... Security identifier indices for initial entities ... send the line "unsubscribe linux-kernel" in ...
      (Linux-Kernel)