Date: Fri, 24 Sep 2004 09:38:40 +0100 From: Matthew Seaman <m.seaman@infracaninophile.co.uk> To: Robert Huff <roberthuff@rcn.com> Cc: questions@freebsd.org Subject: Re: Speaking of Bind: installworld changed directory owner Message-ID: <20040924083840.GE8309@happy-idiot-talk.infracaninophile.co.uk> In-Reply-To: <16723.38380.9533.249086@jerusalem.litteratus.org> References: <16723.14911.322906.824692@jerusalem.litteratus.org> <20040923212837.GA876@happy-idiot-talk.infracaninophile.co.uk> <16723.38380.9533.249086@jerusalem.litteratus.org>
next in thread | previous in thread | raw e-mail | index | archive | help
--0hHDr/TIsw4o3iPK Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Sep 23, 2004 at 11:35:08PM -0400, Robert Huff wrote: >=20 > Matthew Seaman writes: >=20 > > Why do you think /etc/namedb should be owned by the bind user? >=20 > Because I read - not sure where, might have been the O'Reilly > book - a) the first step in securing bind is running as !root > (i.e. user "bind") and b) the bind directory needs to be owned by > that user. > Now maybe I'm mis-remembering, or mis-read in the first place > ... but I'm not pulling this out of thin air. Certainly running bind as a non root user is essential, as is clearly stated in the O'Reilly DNS and Bind book. However I can't see any specific instructions on what ownership and permissions that directory should have, although I don't claim to have managed to make a thorough search through that book this morning. =20 I'd tend to think about these things in terms of 'least privilege'. If someone can subvert your bind process by some sort of buffer overflow exploit (say), then what damage can they do? You can assume that they've got a process with all of the credentials of the bind user. That means they can write to any files that the bind user can write to, or read anything which bind has read permission on. Using the chroot features of bind and setting file ownerships and permissions carefully will minimise your exposure. =20 Cheers, =20 Matthew --=20 Dr Matthew J Seaman MA, D.Phil. 26 The Paddocks Savill Way PGP: http://www.infracaninophile.co.uk/pgpkey Marlow Tel: +44 1628 476614 Bucks., SL7 1TH UK --0hHDr/TIsw4o3iPK Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (FreeBSD) iD8DBQFBU90QiD657aJF7eIRAi93AJ44wOhO4FpVxjZIsAXz4Ud2xO3+JgCgmLFk aolD/JtMOUnQGPSVE1/POLc= =nSna -----END PGP SIGNATURE----- --0hHDr/TIsw4o3iPK--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040924083840.GE8309>