Hello Hessu, hello all,


[listen actually works only under the root account]


>   As a small security measure which might save us from a part of the risk
> of buffer overflows, listen could 1) open the raw socket, 2) check if
> real uid != 0 and effective uid == 0 then set euid = real uid; since being
> root is only required in listen for opening the socket, right?

Really? Only for opening? Not for data interchange? Then things 
would be a lot easier I think.
But finally: How about closing the socket connection?


Just curious,

Gerd

Reply via email to