ããã¯ãUbuntu OnlineãFedora OnlineãWindows ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒããŸã㯠MAC OS ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒãªã©ã®è€æ°ã®ç¡æãªã³ã©ã€ã³ ã¯ãŒã¯ã¹ããŒã·ã§ã³ã® XNUMX ã€ã䜿çšããŠãOnWorks ç¡æãã¹ãã£ã³ã° ãããã€ããŒã§å®è¡ã§ããã³ãã³ã capsh ã§ãã
ããã°ã©ã ïŒ
NAME
capsh - æ©èœã·ã§ã«ã©ãããŒ
SYNOPSIS
ãã£ãã·ã¥ [ãªãã·ã§ã³] ...
DESCRIPTION
ãã®ããŒã«ã䜿çšãããšãLinux æ©èœã®ãµããŒããšäœ¿çšã調æ»ããå¶éããããšãã§ããŸãã ãã®ããŒã«
ç¹å®ã®ã¿ã€ãã®æ©èœãã¹ããšç°å¢äœæã®ããã®äŸ¿å©ãªã©ãããŒãæäŸããŸãã
ãŸããæ©èœã®ç¶æ ãèŠçŽããã®ã«åœ¹ç«ã€ããã€ãã®ãããã°æ©èœãæäŸããŸãã
OPTIONS
ãã®ããŒã«ã¯å€æ°ã®ãªãã·ã§ã³ã®åŒæ°ãåãåãããããã®åŒæ°ãæå®ãããé åºã§åŠçããŸãã
æäŸãããã ãããã¯æ¬¡ã®ãšããã§ãã
-å°å· äžè¬çãªæ©èœãšé¢é£ããç¶æ ã衚瀺ããŸãã
-- [åŒæ°] å®è¡ãã /bin/bash æ«å°ŸåŒæ°ä»ãã 泚ã䜿çšã§ããŸã -c
'æå³ ããž å®è¡ããã ç¹å®ã®ã³ãã³ãã®å Žåã
== å®è¡ãã ãã£ãã·ã¥ æ®ãã®åŒæ°ã䜿çšããŠå床å®è¡ããŸãã ãã¹ãã«äŸ¿å©
execïŒïŒ è¡åã
--caps=ãã£ããã»ãã äžè¬çãªããã»ã¹èœåããã«ãã£ãŠæå®ããããã®ã«èšå®ããŸãã ãã£ãã-
ã»ãã·ã§ã³ã«ã ã©ã㧠ãã£ããã»ãã æ©èœç¶æ ã®ããã¹ãè¡šçŸã§ãã
以äžã®ããã« ãã£ããããã®ããã¹ããšããŸãã
--ãããã=ãã£ãããªã¹ã ãªã¹ããããæ©èœããäžè¬çãªå¢çã»ããããåé€ããŸãã ã®
æ©èœã¯ã次ã®ãããªæ©èœã®ã«ã³ãåºåãã®ãªã¹ãã§ãã
ã«ãã£ãŠèªèãããŸã ãã£ããããã®åå(3) æ©èœã ãã®æ©èœã®äœ¿çš
capsh ããã°ã©ã ãåäœããŠããå¿ èŠããããŸã CAP_SETPCAP ãã®äžã§
å¹æçãªã»ããã
--inh=ãã£ãããªã¹ã çŸåšã®ããã»ã¹ã®ç¶æ¿å¯èœãªæ©èœã»ããã次ã®ããã«èšå®ããŸãã
ã«ã³ãåºåãã®ãªã¹ãã§æå®ããããã®ãšåãã§ãã ãã®ã¢ã¯ã·ã§ã³ã®ããã«ã
æåããå Žåãäžè¬çãªããã»ã¹ã«ã¯ãããã®ããããããã§ã«ååšããŠããã¯ãã§ã
çŸåšç¶æ¿å¯èœãªæ©èœãšèš±å¯ãããæ©èœãçµåããæ©èœ
æ©èœã»ããããŸã㯠capsh ããã°ã©ã ãåäœããŠãã CAP_SETPCAP
å¹æçãªã»ããã§ã
--user =ãŠãŒã¶å æå®ããããŠãŒã¶ãŒã® ID ãæ³å®ããŸãã ã€ãŸãããŠãŒã¶ãŒã®
UID ããã³ ã®ãã ã getpwid(3) ããã³ãã®ã°ã«ãŒãã®ã¡ã³ããŒã·ãã
ã°ã«ãŒããªã¹ããååŸãã(3) å šãŠèšå®ããŸãã
--uid=id ãã¹ãŠã匷å¶ãã UID çããå€ id setuidïŒ2ïŒã·ã¹ãã ã³ãŒã«ã
--gid= ãã¹ãŠã匷å¶ãã ã®ãã çããå€ id ã»ããã®ããïŒ2ïŒã·ã¹ãã ã³ãŒã«ã
--ã°ã«ãŒã= è£è¶³ã°ã«ãŒããæäŸãããæ°å€ãªã¹ãã«èšå®ããŸãã ã®
ã°ã«ãŒã㯠ã»ããã°ã«ãŒãïŒ2ïŒã·ã¹ãã ã³ãŒã«ã
--keep=<0 | 1> éçŽç²æ©èœã¢ãŒãã§ã¯ãã«ãŒãã«ã¯èªç±ãªç¹æš©ãæäŸããŸã
ã¹ãŒããŒãŠãŒã¶ãŒã«ã ãã ããéåžžã次ã®ãããªå ŽåãåœãŠã¯ãŸããŸãã
ã¹ãŒããŒãŠãŒã¶ãŒã®å€æŽ UID äžéšã®å°èŠæš¡ãªãŠãŒã¶ãŒã«å¯ŸããŠã¯ãæ©èœã¯æ¬¡ã®ããã«ãªããŸãã
èœãšããã ãã®ãããªç¶æ³ã§ã¯ãã«ãŒãã«ã¯ããã»ã¹ã«æ¬¡ã®ããšãèš±å¯ã§ããŸãã
åŸããã®æ©èœãç¶æãã setuid(2) ã·ã¹ãã ã³ãŒã«ã ãã®æ©èœ
ãšããŠç¥ãããŠããŸã ããŒããã£ãã ãµããŒãã ããã䜿ã£ãŠã¢ã¯ãã£ããŒãããæ¹æ³
ã¹ã¯ãªããã«ã¯ãã®åŒæ°ãä»ããŠããŸãã å€ã 1 ã«èšå®ãããšã
ããŒããã£ãã ã¢ã¯ãã£ãã«ãªãããšã 0 ã«èšå®ãããšãããŒããã£ããã
çŸåšã®ããã»ã¹ãéã¢ã¯ãã£ãåããŸãã ãã¹ãŠã®å Žåã«ãããŠã ããŒããã£ãã is
éã¢ã¯ãã£ãåããã execïŒïŒ ã¯çºè¡šãããã èŠã --secbits ïœããæ¹æ³ã«ã€ããŠ
ãã®æ©èœãç¡å¹ã«ããŸãã
--secbits=N XXX - ãã®æ©èœãææžåããå¿ èŠããããŸãã
--chroot =path å®è¡ãã chroot(2) æ°ããã«ãŒããã£ã¬ã¯ããª(/)ãæå®ããã·ã¹ãã ã³ãŒã«
ã«çãã pathã ãã®æäœã«ã¯å¿ èŠãªãã®ããããŸã CAP_SYS_CHROOT å ¥ãããã«
å¹æã
--forkfor=ãã©ã€
--killit=SIG
--ãã³ãŒã=N ããã¯äŸ¿å©ãªæ©èœã§ãã èŠãŠã¿ããš /proc/1/ã¹ããŒã¿ã¹ ãã
ã¯ã次ã®åœ¢åŒã®ããã€ãã®æ©èœé¢é£ãã£ãŒã«ãã§ãã
ãã£ããã³: 0000000000000000
CapPrm: ffffffffffffffff
CapEff: fffffffffffffff
CapBnd: ffffffffffffffff
ãã®ãªãã·ã§ã³ã¯ãèœåãã¯ãã«ãè¿ éã«ãã³ãŒãããæ¹æ³ãæäŸããŸãã
ãã®åœ¢ã§è¡šãããŸãã ããšãã°ãäžè¶³ããŠããæ©èœã¯ã
ãã®æå¹ãªã»ãã㯠0x0100 ã§ãã å®è¡ãããš:
capsh --decode=0x0100
äžè¶³ããŠããæ©èœã¯æ¬¡ã®ãšããã§ããããšãããããŸãã cap_setpcap.
--ãµããŒã=XXX ã«ãŒãã«ãé²åããã«ã€ããŠãããå€ãã®æ©èœãè¿œå ãããŸãã ãã®ãªãã·ã§ã³ã§ã§ããããšã¯ã
ã·ã¹ãã äžã®æ©èœã®ååšã確èªããããã«äœ¿çšãããŸãã ããã«
äŸã --ãµããŒã=cap_syslog capsh ãããã«çµäºããŸã
ã«ãŒãã« 1 ã§å®è¡ãããšã¹ããŒã¿ã¹ã¯ 2.6.27 ã«ãªããŸãã ãã ããå®è¡ãããš
ã«ãŒãã« 2.6.38 ã§ã¯ãé»ã£ãŠæåããŸãã
EXIT ã¹ããŒã¿ã¹
å®è¡ãæåãããšãããŒã«ã¯ã¹ããŒã¿ã¹ 0 ã§çµäºããŸãããšã©ãŒãçºçãããšã
ããŒã«ã¯ã¹ããŒã¿ã¹ 1 ã§çŽã¡ã«çµäºããŸãã
onworks.net ãµãŒãã¹ã䜿çšããŠãªã³ã©ã€ã³ã§ Capsh ã䜿çšãã