Re: allowing ordinary users to open privileged ports

Brian Hatch <[email protected]> Fri, 10 Sep 2004 16:40:53 -0700
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>

> 	Has anyone in the list successfully tried allowing ordinary
> users to open privileged (< 1024) ports? We have a solaris 8 on sparc
> machine running an (java) application that normally uses ports > 1024;
> however a client requested the application to use privileged ports
> instead.


Could you keep the app running on it's existing high numbered
port and have a process redirect traffic to it from the low
numbered port?  rinetd listening on port 800, redirecting to
port 8888 for example.  Could do the same thing with tcp
stack games depending on what you have available too, or on
a firewall/etc that's in front of it.

-- 
Brian Hatch                  The Schroedinger petshop
   Systems and                is currently closed, due
   Security Engineer          to unforseen circumstances.
http://www.ifokr.org/bri/

Every message PGP signed
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQFBQjuFP+Nf30gFDwERAubeAJ9T7Wg/LIXoxL0LNH/1+Ik7rqZvVwCfYqZO
kuOPlNLZYLRG4nCeGE+WPBA=
=Vg8c
-----END PGP SIGNATURE-----