If anyone uses native addons this is irrelevant. Also, if process spawning
of any tool that uses the restricted resources it is irrelevant. I have
spent a lot of time trying to restrict what ports a process can work with
and the only somewhat safe solutions come from passing between parent and
child and overriding cstdlib etc. Even after those chamges port jacking is
a problem if you have services on nonprivileged ports.

Reply via email to