On Mon, Jan 01, 2001 at 09:08:26PM +0100, Anders Nordby wrote:
> Are people actually using uid type rules heavily? I'm having trouble matching
> the packets generated by programs like Apache and ProFTPD. I believe that may
> be because of root binding the ports these programs use before they setuid() or
> something, I'm not sure. Particularly I have trouble matching the packets of
> active FTP, since I have random ports on both ends to deal with and can't match
> them by port either. Does anyone have a solution to this?
sockstat is your friend, look at the 'user' that is defined per program,
thats who is going to be charged for packets on that socket.
--
Bill Fumerola - security yahoo / Yahoo! inc.
- [EMAIL PROTECTED] / [EMAIL PROTECTED]
To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-net" in the body of the message