Nmap Development mailing list archives

Re: Limit WinPcap use by unprivileged users


From: David Fifield <david () bamsoftware com>
Date: Fri, 24 Sep 2010 18:30:49 -0700

On Fri, Sep 24, 2010 at 08:23:46PM -0500, DePriest, Jason R. wrote:
Wouldn't stopping npf would also prevent regular users from using
anything else that uses winpcap like Wireshark / tshark / windump.

Yes but that's the point of the TODO: to see if it's possible to limit
sniffing to certain users as is possible on other operating systems. I
don't think that stopping NPF is a good solution but it's the best I've
been able to think of.

David Fifield
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: