Re: What are "security implications" of FTP chroot jails?



On Tue, 31 Oct 2006, in the Usenet newsgroup comp.os.linux.security, in article
<1162320026.2277.40.camel@xxxxxxxxxxxxxxxx>, Johny be Good wrote:

Moe Trin wrote:

A 'chroot() jail' is only as secure as the lack of skills of the chroot'ed
user. There are a number of _relatively_ simple mechanisms to break out of
jail - and this becomes easier when they have the ability to grab software
from "outside". They need only to obtain 'root' access through some local
exploit and they're out.

FUD.

Moe, he is talking about *FTP* Jail/Chroot environment.

I'm glad to hear that you are sure it's impossible. Please note that FTP
is not the only access that the O/P is granting.

I would love if you can demonstrate or reference how to escape
ftp-jail-chroot in vsftpd.

With FTP access _alone_ on a properly configured system, I'll agree it is
not an easy task. But there are two assumptions - FTP only, and properly
configured. If either is not true, then vsftpd (or any other single
application) does not control everything, especially when the sole purpose
of having FTP access is to upload files for use elsewhere on the system.

Thank you for your future enlightenment.

The world does not exist in splendid isolation. Look at the rest of the
picture.

Old guy
.



Relevant Pages

  • RE: SBS2003 Premium and ISA2004 SP3 FTP and POP3 problems
    ... Then try to access FTP. ... Test the FTP access and let me know the result. ... Disable web proxy on client computer and SBS: ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • pf FTP ftp-proxy rules question for a firewall
    ... to allow FTP access to only certain hosts on my ... the network and allow access only to certain hosts, ...
    (comp.unix.bsd.openbsd.misc)
  • Re: ISA 2004 - FTP allowed, then denied on "unidentified IP traffic"
    ... > My customer has a nicely organized ISA 2004 Firewall Policy. ... > FTP is not set to read-only. ... > FTP Access Filter is enabled, though I have tried it with and without ... > Browser shows a connection to FTP site, can view the FTP SERVER WELCOME ...
    (microsoft.public.isa)
  • FTP access issues
    ... We are having restrcicted ftp access setup on HP-UX server having HP-UX ...
    (SunManagers)
  • vsftpd doesnt start - subsytem locked
    ... I have a RedHat 9 box with vsftpd installed. ... I am starting vsftpd as a service, and there is nothing about ftp in the ... # Uncomment this to allow the anonymous FTP user to upload files. ... # mangling on files when in ASCII mode. ...
    (linux.redhat)