Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 12 Jul 1998 03:35:07 -0400 (EDT)
From:      Adam Shostack <adam@homeport.org>
To:        phk@critter.freebsd.dk (Poul-Henning Kamp)
Cc:        angelos@dsl.cis.upenn.edu, security@FreeBSD.ORG
Subject:   Re: chroot()
Message-ID:  <199807120735.DAA06281@homeport.org>
In-Reply-To: <2486.900138858@critter.freebsd.dk> from Poul-Henning Kamp at "Jul 11, 98 08:34:18 am"

next in thread | previous in thread | raw e-mail | index | archive | help


Poul-Henning Kamp wrote:
| In message <199807110241.WAA21195@adk.gr>, "Angelos D. Keromytis" writes:
| 
| >Keep in mind that it's trivial to escape from a root shell if you have
| >root (or can do certain things). chroot() is unfortunately far from
| >perfect.
| 
| A FreeBSD user has paid me to strengthen the chroot() concept, and the code
| will go into FreeBSD when he has had time to get his money back through
| the use of it.

Can you talk about what strengthening you've done?

Adam



-- 
"It is seldom that liberty of any kind is lost all at once."
					               -Hume



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199807120735.DAA06281>