Vulnerability Development mailing list archives
Re: limited functionality accounts (was: Re: History Files)
From: einari () COMPLEX IS (Einar Indridason)
Date: Wed, 26 Apr 2000 16:17:12 +0000
Put them inside a chrooted environment that has only those things that you explicitly add. This requires a lot of care with what you add to ensure you understand exactly what each executable lets people do, and to ensure you have everything that is required. If necessary on your system, you can make sure all binaries are statically linked.
Unfortunately, the glibc stuff (even when "-static"-ically linked) *will* pull in additional libraries *at runtime* if needed :-/ and so you would need to provide those libraries *as well* in the chroot area! GRRRRRR........ -- einari () complex is
Current thread:
- Re: History Files, (continued)
- Re: History Files Dino Dai Zovi (Apr 15)
- Re: History Files Crispin Cowan (Apr 15)
- Re: History Files Rodrick Brown <System Administrator> (Apr 15)
- Re: History Files Tomas Westin (Apr 15)
- Re: History Files Blue Boar (Apr 15)
- Re: History Files audit (Apr 15)
- Re: History Files Blue Boar (Apr 15)
- Re: History Files Carson Gaspar (Apr 15)
- limited functionality accounts (was: Re: History Files) Marc Slemko (Apr 16)
- Re: limited functionality accounts (was: Re: History Files) Seth R Arnold (Apr 16)
- Re: limited functionality accounts (was: Re: History Files) Einar Indridason (Apr 26)
- Controlling a program's resource usage on Unix Bernie Cosell (Apr 16)
- Re: Controlling a program's resource usage on Unix Seth R Arnold (Apr 16)
- Re: Controlling a program's resource usage on Unix Isaac (Apr 21)
- Re: History Files Rodrick Brown <System Administrator> (Apr 15)
- Re: Controlling a program's resource usage on Unix Crispin Cowan (Apr 16)
- Re: Controlling a program's resource usage on Unix Matej Kovac (Apr 17)
- Re: Controlling a program's resource usage on Unix Pavel Kankovsky (Apr 18)
- Re: History Files David Taylor (Apr 16)
- Re: History Files Boris Sagadin (Apr 17)
- Fwd: RAZOR Analysis of dvwssr.dll Blue Boar (Apr 17)
- Re: History Files iconoclast (Apr 18)