1. ¹®Á¦Á¡
root# ping 127.0.0.1
socket: Permission denied
ÀÌ¿Í °°ÀÌ ping ÀÌ ¾ÈµÈ´Ù. (³»°¡ °æÇèÇÑ°Ç root´Â µÇ°í ÀϹÝÀ¯Àú°¡ ¾ÈµÊ)
2. È®ÀÎ ¹æ¹ý
1) ls -l /usr/bin/ping
-rwxr-xr-x. 1 root root 66168 May 22 2017 /usr/bin/ping
2) # getcap /usr/bin/ping
/usr/bin/ping = cap_net_admin,cap_net_raw+p
ÀÌ¿Í °°ÀÌ ¾ÈµÇ¾îÀÖ´Ù¸é ¼³Á¤À» ÇؾßÇÑ´Ù.
setcap cap_net_raw+ep /usr/bin/ping
Âü°í»çÇ× : ping À» ÇÒ¶§´Â ÀÏ¹Ý À¯Àúµµ root±ÇÇÑÀ» ȹµæÇÏ¿© ÇÏ´Â ÀÛ¾÷ÀÌ´Ù.
±×·¡¼ setuid ³ª 2¹ø°ú °°Àº ¼³Á¤ÀÌ µÇ¾îÀÖ¾î¾ßÇÑ´Ù.