[Full-disclosure] Re: Root password change



Once upon a time, Michael Holstein <michael.holstein@xxxxxxxxxxx> said:
if you're chrooted under /tmp (as it sounds from your email) you're out
of luck, unless you have a way to escape the chroot due to a
misconfiguration of that environment in the first place.

If you are root, chroot is easy to break (that's why chroot is not
secure for root-owned processes).

--
Chris Adams <cmadams@xxxxxxxxxx>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: CHROOT Tutorial?
    ... I followed that with a few modifications to make the chroot ... environment look a little bit more like the natural environment. ... One change I made was to put the jailed shell in ... login: pajaro ...
    (Fedora)
  • Re: RHEL 4 AS
    ... > environment (BIND and chroot'd BIND were installed during the OS ... These servers serving DNS without issue. ... Do you have a duplicate key file in the chroot environment? ...
    (linux.redhat)
  • Re: Security by hiding processes
    ... > Personally I'm a bit sceptic towards this kind of security through ... Hiding /proc is trivial in a chroot environment, ... The problem with this is that some applications need to see what is in /proc ...
    (Focus-Linux)
  • Re: CHROOT Tutorial?
    ... I followed that with a few modifications to make the chroot ... environment look a little bit more like the natural environment. ... login: pajaro ... bash-2.05b# pwd ...
    (Fedora)
  • Re: CHROOT Tutorial?
    ... environment look a little bit more like the natural environment. ... One change I made was to put the jailed shell in ... login: pajaro ... once for the user and once for sudo to execute the chroot. ...
    (Fedora)