RE: allowing ordinary users to open privileged ports

"Alan W. Rateliff, II" <[email protected]> Sat, 4 Sep 2004 10:07:25 -0400
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
> -----Original Message-----
> From: randy calma repasa [mailto:[email protected]] 
> Sent: Thursday, September 02, 2004 10:41 AM
> To: [email protected]
> Subject: allowing ordinary users to open privileged ports
> 
> Hello all,
> 
> 	Has anyone in the list successfully tried allowing ordinary
> users to open privileged (< 1024) ports? We have a solaris 8 on sparc
> machine running an (java) application that normally uses ports > 1024;
> however a client requested the application to use privileged ports
> instead.

Check this out:

http://www.sean.de/Solaris/soltune.html

Look at the /dev/tcp option "tcp_smallest_nonpriv_port".  There's a lot of
tweaking you can do with privileged ports, just BE VERY CAREFUL.  If you
were to make any of the well-known services (http, smtp, etc.)
non-privileged, you run the risk of becoming a security problem to yourself
and the rest of the Internet.  (Well, allowing users to set up listeners
PERIOD could be construed as a security risk, but all of this has been and
could be topic for debate.)

Also have a look at the Solaris Tunable Parameters Reference guides which
are linked in the introduction.  All very good references to have handy.

-- 
       Alan W. Rateliff, II        :       RATELIFF.NET
 Independent Technology Consultant :    [email protected]
      (Office) 850/350-0260        :  (Mobile) 850/559-0100
-------------------------------------------------------------
[System Administration][IT Consulting][Computer Sales/Repair]