Re: What are "security implications" of FTP chroot jails?



On Mon, 30 Oct 2006 14:22:06 -0600, Moe Trin wrote:

Do you trust the individuals? (If not, why are they granted access?)

The users are either employees or customers. No one else is supposed to
get access EXCEPT via HTTP since we have a public-access website running
on that machine.

Do I trust them not to be malicious? Sure.

Do I trust them not to do something stupid out of ignorance? Uh.. not
really.

Is your system updated such that root exploits are going to be Day Zero
type exploits? The later means you have to stay on top of the system,
patching problems as soon as they are known.

And, therein lies the problem. I cannot do that on this machine, at least
not right now. It is what it is, we're stuck with FC2, and there is
nothing we can do about it for the near or mid-term future.

Believe me I have fought this fight and it's not a fight that can be won
any time soon.

One thing... you mention that it's relatively simple to break out of jail.
The only access that non-trusted users have is HTTP and FTP, and the FTP
users are chroot'd. No telnet for anybody, and no ssh for anyone but
employees, all of whom are trusted, and all of whom need to access via
more-or-less-trusted networks.

Still a problem?

.



Relevant Pages

  • Re: why use ftp if http provides the same services???
    ... >> when downloading a file often the websites give two option..either ... >> download it from a ftp site or http.. ... >> html.eg.word,spreadsheet file) from http server and ftp server.? ...
    (comp.lang.java.programmer)
  • Re: Overview Of New Intel Core i7(Nehalem) Processor
    ... FTP wins on all counts. ... Check the RFCs. ... HTTP, thus the need for a downloader tool to replace much of the ... Most HTTP download managers are a scam; if you fell for it, ...
    (sci.electronics.design)
  • RE: Size checking?
    ... > of OOP. ... >> way to go at least for the HTTP files. ... >> won't) provide the same file via FTP, ... >> protocols to their common factors. ...
    (perl.beginners)
  • Re: Opentextfile TriStateMixed
    ... If it doesn't work you might also try using HTTP. ... I find that if I use winsock and talk directly to an FTP server, ... The FTP server just sends the file to me with an HTTP ... "The GetHeader method is used to retrieve header text from an HTTP file" ...
    (microsoft.public.vb.general.discussion)
  • Re: Questions on secure remote access to Fedora Core 2
    ... After most of a day of research on iptables, and a bunch of trial and ... Keep HTTP and HTTPS open for everybody ... Open inbound SSH, FTP, and mail for everybody ... ... users who for whatever reason can't use SFTP. ...
    (comp.os.linux.security)