RE: allowing ordinary users to open privileged ports
"Alan W. Rateliff, II" <[email protected]> Sat, 4 Sep 2004 10:07:25 -0400
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Message-ID | <[email protected]> |
> -----Original Message----- > From: randy calma repasa [mailto:[email protected]] > Sent: Thursday, September 02, 2004 10:41 AM > To: [email protected] > Subject: allowing ordinary users to open privileged ports > > Hello all, > > Has anyone in the list successfully tried allowing ordinary > users to open privileged (< 1024) ports? We have a solaris 8 on sparc > machine running an (java) application that normally uses ports > 1024; > however a client requested the application to use privileged ports > instead. Check this out: http://www.sean.de/Solaris/soltune.html Look at the /dev/tcp option "tcp_smallest_nonpriv_port". There's a lot of tweaking you can do with privileged ports, just BE VERY CAREFUL. If you were to make any of the well-known services (http, smtp, etc.) non-privileged, you run the risk of becoming a security problem to yourself and the rest of the Internet. (Well, allowing users to set up listeners PERIOD could be construed as a security risk, but all of this has been and could be topic for debate.) Also have a look at the Solaris Tunable Parameters Reference guides which are linked in the introduction. All very good references to have handy. -- Alan W. Rateliff, II : RATELIFF.NET Independent Technology Consultant : [email protected] (Office) 850/350-0260 : (Mobile) 850/559-0100 ------------------------------------------------------------- [System Administration][IT Consulting][Computer Sales/Repair]