Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 21 Dec 2004 14:33:48 +0100
From:      DanGer <danger@wilbury.sk>
To:        Nigel Houghton <nigel@sourcefire.com>, freebsd-security@freebsd.org
Subject:   Re[2]: chroot-ing users coming in via SSH and/or SFTP?
Message-ID:  <993621639.20041221143348@wilbury.sk>
In-Reply-To: <20041220221928.GA2698@sourcefire.com>
References:  <6.2.0.14.2.20041220142255.06260ca0@localhost> <20041220212304.GV792@sourcefire.com> <6.2.0.14.2.20041220145924.0624c328@localhost> <20041220221928.GA2698@sourcefire.com>

index | next in thread | previous in thread | raw e-mail

Hi Nigel,

Monday, December 20, 2004, 11:19:29 PM, si napisal:

> On  0, Brett Glass <brett@lariat.org> allegedly wrote:
>> At 02:23 PM 12/20/2004, Nigel Houghton wrote:
>> 
>> >Is there something wrong with using the scponly shell for the users?
>> 
>> Mainly that I hadn't heard of it until you mentioned it. ;-)
>> Thank you! (I knew I could get a quick answer, if there was one,
>> from the list.)

> aha, ok, good.

>> I just tried building it (twice, because the first time I didn't
>> realize that it required a special variable to be defined before 
>> it would set itself up to chroot users). I'll be testing it shortly
>> to be sure that the "jails" created by its sample script (which
>> creates both the user ID and the jail) have everything needed for 
>> FreeBSD.
>> 
>> It'd be nice if there were a more centralized "chroot" facility
>> that covered SSH, FTP, and other things as well.
>> 
>> --Brett

> Take a look at the Jail project, you'll find it here...

>  http://www.jmcresearch.com/projects/jail/

> ..and in ports/sysutils/ along with some other jail tools, it may 
> provide some of the features you are looking for.

> +-----------------------------------------------------------------+
>     Nigel Houghton      Research Engineer       Sourcefire Inc.
>                   Vulnerability Research Team

>  Stewie: You know, I rather like this God fellow. Very theatrical, 
>          you know. Pestilence here, a plague there. Omnipotence 
>                                  ...gotta get me some of that.
> _______________________________________________
> freebsd-security@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to
> "freebsd-security-unsubscribe@freebsd.org"

maybe somebody should port this:

http://chrootssh.sourceforge.net/index.php

it seems good :-)

-- 
Sincerely

+----------==/\/\==----------+       (__)      FreeBSD
| DanGer <danger@wilbury.sk> |    \\\'',)      The
| DanGer@IRCnet ICQ261701668 |      \/  \ ^    Power
|   http://danger.rulez.sk   |      .\._/_)    To
+----------==\/\/==----------+                 Serve


help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?993621639.20041221143348>