Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 15 Dec 1998 08:44:16 +0200
From:      Mark Murray <mark@grondar.za>
To:        Joe Abley <jabley@clear.co.nz>
Cc:        Kevin Day <toasty@home.dragondata.com>, freebsd-current@FreeBSD.ORG
Subject:   Re: modification to exec in the kernel? 
Message-ID:  <199812150644.IAA67338@greenpeace.grondar.za>
In-Reply-To: Your message of " Tue, 15 Dec 1998 12:48:18 %2B1300." <19981215124818.A22526@clear.co.nz> 
References:  <19981215120357.B11837@clear.co.nz> <199812142331.RAA17203@home.dragondata.com>   <19981215124818.A22526@clear.co.nz> 

next in thread | previous in thread | raw e-mail | index | archive | help
Joe Abley wrote:
> I looked at that; however, remember the users will have chrooted access
> to their directories, and within the chrooted tree will be /usr and
> descendants containing controlled binaries (owned by someone else, e.g.
> "root") like perl, awk, sh, etc.

Your security model is flawed. A user can do anything she wants
(justabout) with shellscript and perl. Picking on compiled binaries
is not going to make you that much safer.

M
--
Mark Murray
Join the anti-SPAM movement: http://www.cauce.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-current" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199812150644.IAA67338>