chroot-jail ?? whats this

Ralf Hildebrandt R.Hildebrandt at tu-bs.de
Wed Mar 1 07:44:30 UTC 2000


On Tue, Feb 29, 2000 at 05:43:19PM +0000, Doug Siebert wrote:

> If root is acquired in the chroot filesystem, all is lost unless it is

Thus don't run BIND as user root -- perhaps it would make sense to enforce
"-u" when "-t" is used...

> There really is a reason why people keep saying that chroot() really
> doesn't buy you much security...

-- 
Ralf Hildebrandt <R.Hildebrandt at tu-bs.de> www.stahl.bau.tu-bs.de/~hildeb
Real programmers never work 9 to 5. If any real programmers are around
at 9 am, it's because they were up all night. 


-- Attached file included as plaintext by Listar --

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 5.0i for non-commercial use
MessageID: Img41zB2X0r5uxw0h7oHf/NEYQZBXs9P

iQCVAwUBOLzKW0nh/jPvZzKNAQEPqQP+PvtXnNqrMb9xbFekQqsEDjk69OAThk1e
YCPZx8ivn/A4Iu++cLhHH0LCBSmDovKu7zI8mEiUeSa3cfUYGTKFqP6FGHkIXT89
86lhaWAMggDFzVQJFwzCtkyQkMLhdfvGULn/PwGX2owbNFtuexNyFPa/2QiB6les
r0VNxltC7x8=
=LvIR
-----END PGP SIGNATURE-----




More information about the bind-users mailing list