<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>Within Reason: New release of tcpdrop for Solaris</title>
    <link>http://typo.submonkey.net/articles/2008/05/16/new-release-of-tcpdrop-for-solaris</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>I do what I want</description>
    <item>
      <title>New release of tcpdrop for Solaris</title>
      <description>&lt;p&gt;Some years ago &lt;a href="http://typo.submonkey.net/articles/2006/07/31/tcpdrop-for-solaris"&gt;I ported tcpdrop to Solaris&lt;/a&gt; from the FreeBSD version.  I did it very quickly as a proof of concept and never got round to quite getting the error handling right or worrying about Solaris 10 &lt;a href="http://blogs.sun.com/gbrunett/entry/top_5_solaris_10_security"&gt;privileges&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;After spending the required 14 seconds looking at the privileges stuff, it became pretty clear that the required privilege for using tcpdrop was &lt;code&gt;PRIV_SYS_IP_CONFIG&lt;/code&gt;.  This cannot be asserted in a non-global zone, so if you are one of the many people who have emailed me asking if it can work in a non-global zone, the answer is &amp;#8220;no, it can&amp;#8217;t&amp;#8221;.  Not only that, but there&amp;#8217;s nothing I can do about it.&lt;/p&gt;

&lt;p&gt;Also in this release, I fixed up the error messages so that they are at least correct :)&lt;/p&gt;

&lt;p&gt;The next release will feature a manpage in man format, rather than the current mdoc one which can&amp;#8217;t actually be formatted on Solaris.  Anyone who knows an automated method to convert from mdoc to man, please shout.&lt;/p&gt;

&lt;p&gt;Anyway, the new release is &lt;a href="http://typo.submonkey.net/pages/tcpdrop-solaris"&gt;available for download&lt;/a&gt;, knock yourselves out.&lt;/p&gt;</description>
      <pubDate>Fri, 16 May 2008 21:09:00 +0000</pubDate>
      <guid isPermaLink="false">urn:uuid:62bae70f-be57-4e2e-a364-d76884e3cee3</guid>
      <author>Ceri Davies</author>
      <link>http://typo.submonkey.net/articles/2008/05/16/new-release-of-tcpdrop-for-solaris</link>
      <category>Software</category>
      <category>Solaris</category>
    </item>
  </channel>
</rss>
