If anyone uses native addons this is irrelevant. Also, if process spawning of any tool that uses the restricted resources it is irrelevant. I have spent a lot of time trying to restrict what ports a process can work with and the only somewhat safe solutions come from passing between parent and child and overriding cstdlib etc. Even after those chamges port jacking is a problem if you have services on nonprivileged ports.
- [node-dev] "Hardened" node MikeS
- Re: [node-dev] "Hardened" node Ben Noordhuis
- Re: [node-dev] "Hardened" node MikeS
- Re: [node-dev] "Hardened" node Bradley Meck
- Re: [node-dev] "Hardened" node MikeS
- Re: [node-dev] "Hardened" ... Bradley Meck
- Re: [node-dev] "Hardened&qu... Isaac Schlueter
- Re: [node-dev] "Hardene... Gustavo Machado
- Re: [node-dev] "Hardene... Tim Caswell
- Re: [node-dev] "Hardene... Bradley Meck
- Re: [node-dev] "Hardene... Dominic Tarr