note 23566 added to security.apache
| From: | de dot uxp at anthem dot BACKWARDS | Date: | Mon, 22 Jul 2002 23:50:18 +0000 |
| Subject: | note 23566 added to security.apache | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-33391@lists.php.net to get a copy of this message | ||
In response to xwolf@xwolf.de
>On bigger sites, users for virtual not
>only have ftp / scp, but also access
>to the filesystem.
Well - If chrooting is cool and stuff.. why don't you chroot your users ?
Give them a /dev/null+zero, /bin/bash+cat+ldconfig+ls ,
/etc/group+ld.so.cache+localtime+passwd+profile,
/lib/ld-linux+libc+lidl+libhistory+libncurses+libnss+libreadline and all additional tools you think
they might need (vi or whatever)
Granted - this is some work to do. But you only have to do it once. Works for me. Not chrooting your
users is IMO a lack in security, too.
--
http://www.php.net/manual/en/security.apache.php
http://master.php.net/manage/user-notes.php?action=edit+23566
http://master.php.net/manage/user-notes.php?action=delete+23566
http://master.php.net/manage/user-notes.php?action=reject+23566