Re: pserver user id's

From: Larry Jones
Subject: Re: pserver user id's
Date: Thu, 7 Jul 2005 11:05:09 -0400 (EDT)

foomonkey writes:
> I may be missing something but that's the way things appear to me. Is
> there any danger in having pserver run as root? inetd.conf contains
> many other services running as root. I realize that ANY service running
> as root or otherwise introduces certain vulnerabilities.

You've got it.  Pserver runs as root just long enough to authenticate
the user and then it switches to the actual user to run everything else
so there's very little risk.

-Larry Jones

