[Full-disclosure] White Paper - Chrooting sshd



Sometimes it may become profitable or necessary to jail the ssh daemon
within a chroot. Unluckily there aren't many papers out there that
explain the process of creating an appropriate jail and resolving all
the necessary dependencies and errors.

This paper will show you how to successfully jail sshd itself. Opposed
to many other papers out there it does not try to jail the users after
logging in but rather put the entire daemon into the jail. This approach
is interesting for anybody paranoid enough to want to protect against
remotely exploitable flaws in the used sshd.

Blog-Entry:
https://observed.de/?entnum=55

Download-Area:
https://observed.de/index.html?download

Paper:
https://observed.de/upfiles/chroot_sshd_linux.pdf

Feedback, corrections and constructive criticism are always welcome.

Many Greetings
Paul Sebastian Ziegler

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • White Paper - Chrooting sshd
    ... Sometimes it may become profitable or necessary to jail the ssh daemon ... This paper will show you how to successfully jail sshd itself. ... to many other papers out there it does not try to jail the users after ...
    (Security-Basics)
  • Re: Acasuso
    ... IIRC he got a fine, public humilliation, but no jail time. ... SORRY!", the mayor says some words, local media gets it all, done. ... Public apology on courthouse. ...
    (rec.sport.tennis)
  • Re: OT: Geez, what a crook!
    ... Nonnymus wrote: ... jail right now? ... nor do I know why Stanford wasn't picked up yesterday when the FBI served him papers. ...
    (alt.vacation.las-vegas)