Unix Technical Forum

Re: Ethereal 0.10.12

This is a discussion on Re: Ethereal 0.10.12 within the lucky.openbsd.misc forums, part of the OpenBSD category; --> The patch for tethereal(1) is at http://www.linbsd.org/setuid_tethereal.patch This only works for capture mode. It takes an extra -u option ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.misc

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-17-2008, 07:09 AM
ober
 
Posts: n/a
Default Re: Ethereal 0.10.12

The patch for tethereal(1) is at
http://www.linbsd.org/setuid_tethereal.patch

This only works for capture mode. It takes an extra -u option for the
user. So create user _ethereal then run
tethereal -Nn -tad -u _ethereal -w foo
or decode the output. Either way this should remove the issue of root.
Same can be applied to ethereal for capture.
Every other condition of just reading traces files should not be done as
root.

I use OpenBSD because on the misc@ and tech@ mailing lists I get to see
more *'s-holes than a Turkish Customs Agent. -Ober

On Thu, 8 Sep 2005, Bruno Rohee wrote:

> On Thu, Sep 08, 2005 at 03:10:41PM +0200, Sebastian .Rother wrote:
>>>
>>> surely, but has security improved? does it have privsep? until that
>>> has changed, ethereal will not come back. sorry.
>>>
>>> jakob

>>
>>
>> Then drop all ports!
>> Has Gnome Priv-Sep? hydra? nmap? KDE? xpdf? XMMS? mplayer?

>
> No one remotely sane run those as root. Another uninformed post of yours.
>
> Capturing traffic by some other mean then analysing it with Ethereal
> under an unprivileged account might be safe, actually capturing an analysing
> traffic with Ethereal is definitely not, given its architecture and
> history of sloppy coding...


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 11:26 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
www.UnixAdminTalk.com