Security Basics mailing list archives

White Paper - Chrooting sshd


From: Paul Sebastian Ziegler <psz () observed de>
Date: Fri, 13 Jul 2007 23:49:09 +0200

Sometimes it may become profitable or necessary to jail the ssh daemon
within a chroot. Unluckily there aren't many papers out there that
explain the process of creating an appropriate jail and resolving all
the necessary dependencies and errors.

This paper will show you how to successfully jail sshd itself. Opposed
to many other papers out there it does not try to jail the users after
logging in but rather put the entire daemon into the jail. This approach
is interesting for anybody paranoid enough to want to protect against
remotely exploitable flaws in the used sshd.

Blog-Entry:
https://observed.de/?entnum=55

Download-Area:
https://observed.de/index.html?download

Paper:
https://observed.de/upfiles/chroot_sshd_linux.pdf

Feedback, corrections and constructive criticism are always welcome.

Many Greetings
Paul Sebastian Ziegler


Current thread: