mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-08 06:29:08 +02:00
Place the Windows VNC agent socket under SystemTemp, falling back to Windows\Temp where it does not exist
This commit is contained in:
@@ -14,9 +14,10 @@ import (
|
||||
// rests on three other measures, none of which assume the socket path is
|
||||
// secret:
|
||||
//
|
||||
// - the socket lives in a dedicated directory (agentSocketDir) created
|
||||
// with a DACL granting only SYSTEM and Administrators, so an
|
||||
// unprivileged local user cannot create or squat a socket there;
|
||||
// - the socket lives in a dedicated directory (agentSocketDirPath) under
|
||||
// %SystemRoot%\SystemTemp, created with a DACL granting only SYSTEM and
|
||||
// Administrators, so an unprivileged local user cannot create or squat a
|
||||
// socket there;
|
||||
// - each spawn uses a cryptographically random socket name, so the path
|
||||
// is unguessable before the agent binds it;
|
||||
// - the daemon publishes the path only after confirming the spawned
|
||||
|
||||
Reference in New Issue
Block a user