Skip to content

Instantly share code, notes, and snippets.

@garywill
Created January 27, 2025 13:12
Show Gist options
  • Save garywill/09a878e2e5c4d5f662dc1cdd52d08d97 to your computer and use it in GitHub Desktop.
Save garywill/09a878e2e5c4d5f662dc1cdd52d08d97 to your computer and use it in GitHub Desktop.
Bind (listen) <1024 ports without whole root (cap_net_bind_service), with capsh
sudo capsh --caps='cap_net_bind_service+eip cap_setpcap,cap_setuid,cap_setgid+ep' \
--keep=1 --user=non-root-user --addamb=cap_net_bind_service -- \
-c '/path/to/your/command'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment