Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DROPPRIVS_USER in manpage is undefined #22

Open
cody-somerville opened this issue Feb 19, 2020 · 0 comments
Open

DROPPRIVS_USER in manpage is undefined #22

cody-somerville opened this issue Feb 19, 2020 · 0 comments

Comments

@cody-somerville
Copy link

In the ngrep manpage, in reference to the -R command line option, it reads

Do not try to drop privileges to the DROPPRIVS_USER

However, there is no other use of DROPPRIVS_USER in the man page and it is left undefined.

Written as is, due to conventions commonly used in some manpages and command line help text, a user may mistakenly assume that DROPPRIVS_USER can be specified at runtime such as via an argument to the option, environmental variable, or key in a configuration file despite it being statically set at compile time. Considering the potential unforeseen security implications of a user acting on that assumption (or time spent investigating), it may be prudent to update the manpage to remove the opportunity for confusion.

Potential options could be to remove the reference to DROPPRIVS_USER all together or instead elaborate that DROPPRIVS_USER is a compile time option and optionally mention the default value or insert the value used into the manpage at build time.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant