Re: [arch-dev-public] Snort UID / GID

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



The problem of using the user "nobody" is that if it is used for
various services, and one of these is compromised it can also affect
snort.

IMHO, we have two options:

1) Create a "snort" user/group and provide a package with fewer
privileges by default (users can change that if they want)
2) Run snort as "nobody" and put a message in snort.install showing
how to change the user/group that snort runs.

I think the first option is better.

-- Hugo



[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux