Dre4m Shell
Server IP : 127.0.0.2  /  Your IP : 3.16.10.2
Web Server : Apache/2.4.18 (Ubuntu)
System :
User : www-data ( )
PHP Version : 7.0.33-0ubuntu0.16.04.16
Disable Function : disk_free_space,disk_total_space,diskfreespace,dl,exec,fpaththru,getmyuid,getmypid,highlight_file,ignore_user_abord,leak,listen,link,opcache_get_configuration,opcache_get_status,passthru,pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,php_uname,phpinfo,posix_ctermid,posix_getcwd,posix_getegid,posix_geteuid,posix_getgid,posix_getgrgid,posix_getgrnam,posix_getgroups,posix_getlogin,posix_getpgid,posix_getpgrp,posix_getpid,posix,_getppid,posix_getpwnam,posix_getpwuid,posix_getrlimit,posix_getsid,posix_getuid,posix_isatty,posix_kill,posix_mkfifo,posix_setegid,posix_seteuid,posix_setgid,posix_setpgid,posix_setsid,posix_setuid,posix_times,posix_ttyname,posix_uname,pclose,popen,proc_open,proc_close,proc_get_status,proc_nice,proc_terminate,shell_exec,source,show_source,system,virtual
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /usr/share/doc/libcap2-bin/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ HOME SHELL ]     

Current File : /usr/share/doc/libcap2-bin/README.Debian
Please check http://www.friedhoff.org/posixfilecaps.html to get more
information on POSIX File Capabilities.


Example: how to remove the SUID root bit from /bin/ping?
--------------------------------------------------------

Make sure you have kernel 2.6.24 or newer you have
CONFIG_SECURITY_CAPABILITIES and CONFIG_SECURITY_FILE_CAPABILITIES
enabled. The Debian kernels are fine.

  $ ls -l /bin/ping
  -rwsr-xr-x 1 root root 30736 2007-01-31 00:10 /bin/ping
     ^
That is not good.

  $ sudo chmod 755 /bin/ping

Or use dpkg-statoverride.

  $ ls -l /bin/ping
  -rwxr-xr-x 1 root root 30736 2007-01-31 00:10 /bin/ping

That is better but ping fails.

  $ ping -c1 localhost
  ping: icmp open socket: Operation not permitted

Now set the missing capability:

  $ sudo setcap cap_net_raw+ep /bin/ping

... and ping will work again.

  $ ping -c1 localhost
  PING localhost (127.0.0.1) 56(84) bytes of data.
  64 bytes from localhost (127.0.0.1): icmp_seq=1 ttl=64 time=0.026 ms

  --- localhost ping statistics ---
  1 packets transmitted, 1 received, 0% packet loss, time 0ms
  rtt min/avg/max/mdev = 0.026/0.026/0.026/0.000 ms



Torsten Werner

Anon7 - 2022
AnonSec Team