note 23566 deleted from security.apache by bjori

From: Date: Wed, 12 Apr 2006 14:39:30 +0000
Subject: note 23566 deleted from security.apache by bjori
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-107880@lists.php.net to get a copy of this message
Note Submitter: de dot uxp at anthem dot BACKWARDS ---- In response to xwolf@xwolf.de >On bigger sites, users for virtual not >only have ftp / scp, but also access >to the filesystem. Well - If chrooting is cool and stuff.. why don't you chroot your users ? Give them a /dev/null+zero, /bin/bash+cat+ldconfig+ls , /etc/group+ld.so.cache+localtime+passwd+profile, /lib/ld-linux+libc+lidl+libhistory+libncurses+libnss+libreadline and all additional tools you think they might need (vi or whatever) Granted - this is some work to do. But you only have to do it once. Works for me. Not chrooting your users is IMO a lack in security, too.

« previous php.notes (#107880) next »