Subject: Re: Privilege Elevation with systrace
To: Niels Provos <>
From: Simon J. Gerraty <>
List: current-users
Date: 10/12/2002 01:16:55
>Using systrace, ping can run without any privileges and a policy

> netbsd-socket: sockdom eq "AF_INET" and socktype eq "SOCK_RAW" then \
> permit as root

I'm not familiar with systrace, but I _hope_ the policy can be more 
specific than that? 
The above looks like it would allow any program to open raw sockets
"as root".  Just what I'd need if wanting to run rawpkt or whatever to
spew fordged packets into the net ;-)