note 23566 deleted from security.apache by bjori
| From: | bjori@php.net | Date: | Wed, 12 Apr 2006 14:39:30 +0000 |
| Subject: | note 23566 deleted from security.apache by bjori | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-107880@lists.php.net to get a copy of this message | ||
Note Submitter: de dot uxp at anthem dot BACKWARDS
----
In response to xwolf@xwolf.de
>On bigger sites, users for virtual not
>only have ftp / scp, but also access
>to the filesystem.
Well - If chrooting is cool and stuff.. why don't you chroot your users ?
Give them a /dev/null+zero, /bin/bash+cat+ldconfig+ls ,
/etc/group+ld.so.cache+localtime+passwd+profile,
/lib/ld-linux+libc+lidl+libhistory+libncurses+libnss+libreadline and all additional tools you think
they might need (vi or whatever)
Granted - this is some work to do. But you only have to do it once. Works for me. Not chrooting your
users is IMO a lack in security, too.