Re: putting Apache into chroot()-prison

2000-12-31 Thread brian moore
On Sun, Dec 31, 2000 at 12:01:48AM -0800, Nate Amsden wrote: > Nathan E Norman wrote: > > > Do you realise you quoted 40 lines of the original message and added 1 > > meaningful line? What a waste of bandwidth. > > hah. my 1meg dsl line runs average at 2.8% for the past week, > i got plenty of b

Re: putting Apache into chroot()-prison

2000-12-31 Thread Nate Amsden
Nathan E Norman wrote: > Do you realise you quoted 40 lines of the original message and added 1 > meaningful line? What a waste of bandwidth. hah. my 1meg dsl line runs average at 2.8% for the past week, i got plenty of bandwidth to spare :P http://portal.aphroland.org/mrtg/ nate -- ::: ICQ:

Re: putting Apache into chroot()-prison

2000-12-29 Thread JoshNarins
From what I've been able to gather, chroot can be secure,   but only if the user can never get root. FreeBSD's jail had a recent problem. Mounting /proc inside the chroot is not a good idea. In a message dated 12/27/00 7:01:21 PM Eastern Standard Time, [EMAIL PROTECTED] writes: not to dis

Re: putting Apache into chroot()-prison

2000-12-29 Thread Wayne Topa
Subject: Re: putting Apache into chroot()-prison Date: Thu, Dec 28, 2000 at 03:19:53PM -0600 In reply to:Nathan E Norman Quoting Nathan E Norman([EMAIL PROTECTED]): > > No, it's a company as demonstrated by the "Micromuse Inc.". `whois > micromuse.

Re: putting Apache into chroot()-prison

2000-12-28 Thread Nathan E Norman
On Thu, Dec 28, 2000 at 04:02:03PM -0500, [EMAIL PROTECTED] wrote: > > Hey Norman, The name's Nathan ... I realize it's a difficult name to parse. >As an unbiased observer I will comment on your > comment concerning the quote/content ratio of the other > poster. You have your preference

Re: putting Apache into chroot()-prison

2000-12-28 Thread Nathan E Norman
On Thu, Dec 28, 2000 at 01:35:50PM +0400, Rino Mardo wrote: > On Wed, Dec 27, 2000 at 03:57:27PM -0800 or thereabouts, Nate Amsden wrote: [ 21 lines deleted ] > > not to discourage youb ut its pretty well known chroot() is not > > an ultimate solution for security, it has been in the past > > rat

Re: putting Apache into chroot()-prison

2000-12-28 Thread Rino Mardo
On Wed, Dec 27, 2000 at 03:57:27PM -0800 or thereabouts, Nate Amsden wrote: > "R. M. Lampert" wrote: > > > > Hi, folks! > > > > Due to some very unpleasant experience in the company > > I'm working at (rootshell attack due to a buffer overflow > > intrusion in httpd...) there's a great need with

Re: putting Apache into chroot()-prison

2000-12-27 Thread Nate Amsden
"R. M. Lampert" wrote: > > Hi, folks! > > Due to some very unpleasant experience in the company > I'm working at (rootshell attack due to a buffer overflow > intrusion in httpd...) there's a great need with us > to inform thoroughly about changing to a safer environment, > that is LAMP or even

Re: putting Apache into chroot()-prison

2000-12-27 Thread JoshNarins
Here are a couple links which should help you get on your way. (Thanks to Stas Bekman, just another mod_perl hacker) http://www.securityfocus.com/focus/sun/articles/apache-inst.html http://forum.swarthmore.edu/epigone/modperl/stimlorthen

putting Apache into chroot()-prison

2000-12-27 Thread R. M. Lampert
Hi, folks! Due to some very unpleasant experience in the company I'm working at (rootshell attack due to a buffer overflow intrusion in httpd...) there's a great need with us to inform thoroughly about changing to a safer environment, that is LAMP or even better NAMP (NetBSD, Apache ... there a