Gary Winiger wrote:
>>> 1. Of course, you really mean that it requires sufficient privilege to 
>>> use a raw socket. Please confirm that there will be no geteuid() == 0 
>>> check in the code.
>> Yes, it requires sufficient privilege to use a raw socket.  The actual 
>> line is "if( geteuid() )", so it's not good.  The goal was to minimize 
>> the changes to the open source, however if that is not an option here I 
>> can make the changes that are needed.
> 
>       There's some cost to FOSS.  Perhaps this is one.  Consider
>       what architectural intent such a test has.  Is it motherhood?
>       Does fping make access control decisions because it is
>       privileged to do so?  Or is this something where it should
>       really be checking for sufficient privilege because there are
>       partial success semantics where fping could do part of a task
>       then fail for insufficient privilege and leave the system in
>       a compromised state?  Or is this something that can just
>       be done away with and system call failures reported with
>       perror and then exit?
> 
>       For Solaris use, should fping be added to a rights profile
>       with net_rawaccess?

I think we need to stop and consider if fping is even appropriate.  The 
OpenSolaris ping has been properly privilege bracketed and a lot of work 
has been done on securing it as it is a setuid root program.

Rather than integrating fping shouldn't we instead consider adding the 
additional functionality that fping brings to the existing ping source 
and if necessary include a link to fping.

-- 
Darren J Moffat

Reply via email to