[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: putting Apache into chroot()-prison



On Thu, Dec 28, 2000 at 01:35:50PM +0400, Rino Mardo wrote:
> On Wed, Dec 27, 2000 at 03:57:27PM -0800 or thereabouts, Nate Amsden wrote:

[ 21 lines deleted ]

> > not to discourage youb ut its pretty well known chroot() is not
> > an ultimate solution for security, it has been in the past
> > rather easy to break out of it, from what i remember you
> > may be better off running freebsd and it's jail() (??) 
> > function which is a suped up chroot(). all im trying to say
> 
> what about OpenBSD (OAMP)?
 
What about it?  If OpenBSD has jail() I expect the same reasoning
applies.
 
[ 19 lines deleted + 9 for sig ]

Do you realise you quoted 40 lines of the original message and added 1
meaningful line?  What a waste of bandwidth.

-- 
Nathan Norman - Staff Engineer | A good plan today is better
Micromuse Inc.                 | than a perfect plan tomorrow.
mailto:nnorman@micromuse.com   |   -- Patton

Attachment: pgpE3qz_7gqaG.pgp
Description: PGP signature


Reply to: