Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 25 Jun 2002 11:49:01 +0200
From:      Thomas Seyrat <thomas@glou.net>
To:        freebsd-security@FreeBSD.ORG
Subject:   Re: How to check if "UsePrivilegeSeparation" works in OpenSSH?
Message-ID:  <20020625094900.GA13755@lise.hsc.fr>
In-Reply-To: <902312FB-8813-11D6-919D-0030654D97EC@patpro.net>
References:  <20020625195333.U69343-100000@a2> <902312FB-8813-11D6-919D-0030654D97EC@patpro.net>

next in thread | previous in thread | raw e-mail | index | archive | help
patpro wrote:
> >I don't see the [priv] bit on the second one.
> >Can you confirm with lsof that the chroot has taken effect?
> well in fact no, nothing about /var/empty in lsof

  While sshd is waiting for password, I have :

sshd      32666  0,0  0,3  3496 1596  ??  I    11:42     0:00,09 sshd: seyrat [net] (sshd)

  and lsof -p 32666 | grep rtd gives :

sshd    32666 sshd  rtd   VDIR  13,131078      512      4 /var/empty

  This untrusted sshd process is indeed correctly chrooted.

-- 
Thomas Seyrat.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020625094900.GA13755>