5 ms·
How would you implement e.g. ping? I mean obviously you could have e.g. user accounts which were "sufficiently" locked down, but that seems like an even more li
by mnarayan01 10y ago
How would you implement e.g. ping? I mean obviously you could have e.g. user accounts which were "sufficiently" locked down, but that seems like an even more likely source of problems.
- justincormack 10y agoLinux supports non privileged ping. socket(PF_INET, SOCK_DGRAM IPPROTO_ICMP); (it needs a sysctl config to enable it, annoyingly)
- geofft 10y agoThree options: 1. ping hasn't needed to be setuid since Linux 3.0 (and isn't on most distros), the kernel lets you call socket(AF_INET, SOCK_DGRAM, IPPROTO_ICMP) without privileges, which lets you send ping packets and nothing else. Looks like Mac OS X and FreeBSD, at least, also support the same interface. This approach has successfully been used to eliminate other setuid binaries like pt_chown, which fixes ownership of a tty (the kernel now just sets the ownership correctly when you call open). 2. Use something like ForceCommand to allow "ssh root@localhost /sbin/ping", and make /bin/ping a shell script that does that. This carries strictly less complexity than making a setuid binary; any attack that applies to it also applies to setuid binaries, but the execution environment for setuid binaries is more open to the attacker's control. 3. Make a little ping server that you can request to conduct pings for you. For ping in particular this is probably silly, but for things like updating utmp (traditionally you make every program setgid utmp, or you use a helper setgid binary called utempter), there's probably some existing daemon like logind that can grow some small APIs.
- aaronmdjones 10y agoAlong with the aforementioned IPPROTO_ICMP; you can still use file capabilities(7) instead (or as well, in the case of older kernels): # chmod 0711 /bin/ping # setcap CAP_NET_RAW=eip /bin/ping
- geofft 10y agoFile capabilities are certainly better than setuid, but they still have the same problem of elevating privileges in a potentially-attacker-controlled environment. If setuid ping has a vulnerability that lets you get root, CAP_NET_RAW ping would also have a vulnerability that lets you read all traffic into the machine and spoof packets from privileged ports or existing connections. That's an uncomfortably large amount of access, even if it isn't quite root.