[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] profile of a bind worm

From: "Jabie Gray" <apollo@xxxxxxxxxx>

> My named is running as root too.

Bad idea.

> I see two instances of the daemon function in the /etc/rc.d/init.d/named
> script. One is for start, the other is for hard restart.
> Do I need to change both of them to use -u & -g options?

Yes you should.

> Do I need to create the user and group of named?

Maybe. Check your /etc/passwd file. My guess is probably not.
