Re: Chroot breach in 2.1.100+

David Lang (dlang@diginsite.com)
Mon, 21 Sep 1998 11:33:00 -0700 (PDT)


-----BEGIN PGP SIGNED MESSAGE-----

what I am meaning by this question is that I have several machines where
aprocess is started chrooted from inetd. in order for the dhroot to
succeed the uid must be root. the process is now running as root and
unless it explicitly changes it's own uid, it sounds as if I am wasting my
time by doing the chroot. If all the software I run was written well
enough to change it's own uid I would have less of a need to put it in a
chroot sandbox.

David Lang

On Mon, 21 Sep 1998, Marc Slemko wrote:

> On Mon, 21 Sep 1998, David Lang wrote:
>
> > -----BEGIN PGP SIGNED MESSAGE-----
> >
> > along the same lines, is it possible to chroot in a way that also changes
> > the uid that the chrooted process is running under?
>
> You can execute whatever code you want, sure.
>
>
>

-----BEGIN PGP SIGNATURE-----
Version: PGP for Personal Privacy 5.0
Charset: noconv

iQEVAwUBNgab3z7msCGEppcbAQH4mgf8DyKG1Utz/+tYqyr10FvtbUie1A8L3dY1
IGZmlE6UPeaqod6fAkmkbw8UX19gfjbT2svtxZ+3AUCxLqGagsgpGZ4KDFEzrWvC
0jdMbZ9M1NOCzviuBMQR5f6aVclp7gDx+NA8jZc0oXi4e3YlUICzNZk4BvQT0wQu
zZbW4YRlRYCn7SWKXO3hZPhbEreIfMyqX1/aLva2jW/8I7InHEw+Lr08+gyPn4Iw
5AM29vaAMdCH0taXKR77amWtevwDMhtQHhj+W9nv8tpT+DVUdNO4H9FUeVpX3REh
I8CHyLD0K+gKnPS2UUE6rIhdyl2Hsdph8Bd9n83JEgCrhohIK6XAUA==
=wFWk
-----END PGP SIGNATURE-----

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/