Re: alarm?

From: Philip Blundell <pb.a.t.nexus.co.uk>
Date: Thu Sep 12 2002 - 15:41:07 EDT

On Thu, 2002-09-12 at 20:04, Nils Faerber wrote:
> This is ow security holes are born ;)
> It is some time ago since I read this but I think you can get the user
> ID out of out-of-band data after opening (accepting) the socket. I have
> to check this again. But I have no idea how realiable/secure this is.
> Does anyone know this in some more detail?

The most direct way to do this is to use SO_PEERCRED to retrieve the
remote process's credentials.

p.
Received on Thu Sep 12 19:41:27 2002

This archive was generated by hypermail 2.1.8 : Tue May 04 2004 - 09:41:29 EDT