Age | Commit message (Collapse) | Author |
|
|
|
starts, do a chroot to /var/empty and change to user nobody.
hi mom, i'm in jail!
|
|
|
|
|
|
nobody. While I do not like running things as nobody since the step
up is very small, we use this for other daemons in inetd. And it is
still a small step.
|
|
|
|
deploy it can we see such issues
|
|
|
|
|
|
obfuscate, and confuses some software.
derradt + millert concur.
|
|
them from going out of sync (like additional option flag to daemon).
|
|
|
|
these days
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Running anything as nobody.kmem allows any "nobody" process to get into
the kmem group through ptrace(). Kmem is a privileged enough group that
we might as well just run identd as root.
|
|
also, always enable identd -- many things expect it now
|
|
|
|
disable walld/1 by default for security (as pointed out by Chris Cappuccio)
|
|
|