From owner-freebsd-bugs Thu Feb 1 11:10:18 2001 Delivered-To: freebsd-bugs@hub.freebsd.org Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by hub.freebsd.org (Postfix) with ESMTP id 6617537B698 for ; Thu, 1 Feb 2001 11:10:01 -0800 (PST) Received: (from gnats@localhost) by freefall.freebsd.org (8.11.1/8.11.1) id f11JA1S07569; Thu, 1 Feb 2001 11:10:01 -0800 (PST) (envelope-from gnats) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by hub.freebsd.org (Postfix) with ESMTP id 9AA6A37B503 for ; Thu, 1 Feb 2001 11:02:23 -0800 (PST) Received: (from nobody@localhost) by freefall.freebsd.org (8.11.1/8.11.1) id f11J2Ng04677; Thu, 1 Feb 2001 11:02:23 -0800 (PST) (envelope-from nobody) Message-Id: <200102011902.f11J2Ng04677@freefall.freebsd.org> Date: Thu, 1 Feb 2001 11:02:23 -0800 (PST) From: gabriel_ambuehl@buz.ch To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-1.0 Subject: misc/24784: Why isn't bind always running as -u bind -g bind Sender: owner-freebsd-bugs@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org >Number: 24784 >Category: misc >Synopsis: Why isn't bind always running as -u bind -g bind >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: wish >Submitter-Id: current-users >Arrival-Date: Thu Feb 01 11:10:01 PST 2001 >Closed-Date: >Last-Modified: >Originator: Gabriel Ambuehl >Release: 4.2 STABLE >Organization: >Environment: >Description: I've been wondering why bind isn't run as user bind group bind by default. I mean it's widely known that this isn't the most secure piece of software outthere so I'd say it really make sense to run it with the least permissions possible. /etc/defaults/rc.conf got the corresponding line commented out in favor of a normal running bind... >How-To-Repeat: Wait for the exploits to see why I mention this. >Fix: Kill the comment before #named_flags="-u bind -g bind" # Flags for named in /etc/defaults/rc.conf >Release-Note: >Audit-Trail: >Unformatted: To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message