note 23566 added to security.apache

From: Date: Mon, 22 Jul 2002 23:50:18 +0000
Subject: note 23566 added to security.apache
Groups: php.notes 
Request: Send a blank email to php-notes+get-33391@lists.php.net to get a copy of this message
In response to xwolf@xwolf.de >On bigger sites, users for virtual not >only have ftp / scp, but also access >to the filesystem. Well - If chrooting is cool and stuff.. why don't you chroot your users ? Give them a /dev/null+zero, /bin/bash+cat+ldconfig+ls , /etc/group+ld.so.cache+localtime+passwd+profile, /lib/ld-linux+libc+lidl+libhistory+libncurses+libnss+libreadline and all additional tools you think they might need (vi or whatever) Granted - this is some work to do. But you only have to do it once. Works for me. Not chrooting your users is IMO a lack in security, too. -- http://www.php.net/manual/en/security.apache.php http://master.php.net/manage/user-notes.php?action=edit+23566 http://master.php.net/manage/user-notes.php?action=delete+23566 http://master.php.net/manage/user-notes.php?action=reject+23566

« previous php.notes (#33391) next »