Re: Multi-User Security

From: Norberto Meijome (freebsd_at_meijome.net)
Date: 05/18/04

  • Next message: Brian Keefer: "Re: Mail Server in the DMZ question"
    Date: Tue, 18 May 2004 14:41:20 +1000
    To: freebsd-security@freebsd.org
    
    

    Richard Coleman wrote:

    > Using a chroot or a jail is the way to go if possible. If you can't use
    > that, then unix permissions or ACL's is the next bet. Restricting
    > commands is the most fragile solution since in many cases it can be
    > subverted.

    Excuse my ignorance, could you quickly tell me the difference (or point
    me to a good reference article/book) between chroot + jail?
    is it that a jail is always chrooted but not the other way around?
    is a jail more encompassing than chroot only?

    thanks in advance,
    B

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Brian Keefer: "Re: Mail Server in the DMZ question"

    Relevant Pages

    • Re: chroot user programs
      ... The chroot command can only be run as root, ... >>run various commands with a pre-defined root. ... >>the jail and browse through the file system. ...
      (comp.os.linux.security)
    • Re: chroot user programs
      ... The chroot command can only be run as root, ... >>run various commands with a pre-defined root. ... >>the jail and browse through the file system. ...
      (comp.security.unix)
    • Re: FTP guest access chroot not working
      ... the "root" dir for the chroot is /home/someguy/ftp ... # chroot ftp users ... cannot get out of that jail. ... if you created a symlink inside the jail that points to some real ...
      (comp.unix.sco.misc)
    • Re: /devices jailbreak
      ... however as duplicating device special files does /not/ ... processes in a chroot env will ... duplicates in the chrootjail ultimately lead to the same actual ... But that path will be in the chrootjail, as far as the jailed process ...
      (comp.unix.solaris)
    • Re: /devices jailbreak
      ... processes in a chroot env will ... outside the chroot environment will of course report the device paths ... within the jail as a normal user with the restricted Korn ... directory tree, as expected, except for a couple /devices files ...
      (comp.unix.solaris)