Blame SOURCES/arpwatch-drop-man.patch

83d119
--- arpwatch.8.orig	Sun Oct  8 23:31:28 2000
83d119
+++ arpwatch.8	Mon Oct 16 16:46:19 2000
83d119
@@ -36,13 +36,16 @@
83d119
 .I interface
83d119
 ]
83d119
 .br
83d119
-.ti +8
83d119
+.ti +9
83d119
 [
83d119
 .B -n
83d119
 .IR net [/ width
83d119
 ]] [
83d119
 .B -r
83d119
 .I file
83d119
+] [
83d119
+.B -u
83d119
+.I username
83d119
 ]
83d119
 .ad
83d119
 .SH DESCRIPTION
83d119
@@ -94,10 +97,26 @@
83d119
 .B arpwatch
83d119
 does not fork.
83d119
 .LP
83d119
+If 
83d119
+.B -u 
83d119
+flag is used, 
83d119
+.B arpwatch
83d119
+drops root privileges and changes user ID to
83d119
+.I username
83d119
+and group ID to that of the primary group of 
83d119
+.IR username .
83d119
+This is recommended for security reasons.
83d119
+.LP
83d119
 Note that an empty
83d119
 .I arp.dat
83d119
 file must be created before the first time you run
83d119
-.BR arpwatch .
83d119
+.BR arpwatch . 
83d119
+Also, the default directory (where arp.dat is stored) must be owned
83d119
+by 
83d119
+.I username
83d119
+if 
83d119
+.BR -u
83d119
+flag is used.
83d119
 .LP
83d119
 .SH "REPORT MESSAGES"
83d119
 Here's a quick list of the report messages generated by