The ntpd daemon does not run as root. So, how is it able to change the time of the system? Does it use setuid, or caps, or something else?
I wonder because this would also affect what arbitrary code could be run as the ntp user.
I wonder because this would also affect what arbitrary code could be run as the ntp user.
$ ps u 561
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
ntp 561 0.0 0.0 5856 780 ? Ss Jul14 22:37 /usr/sbin/ntpd -p /var/run/ntpd.pid -g -u 103:107
$ /sbin/getpcaps 561
Capabilities for `561': = cap_net_bind_service,cap_sys_time+epGenerally, at any time, it's safer to assume there's at least one active local root exploit in any system.