[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: chroot ssh users



Hannah Schroeter wrote:

> On Sun, Jan 19, 2003 at 11:34:21AM +0100, Markus Friedl wrote:
>
> > chroot to a directory owned by the user is dangerous.
>
> Now I'm curious: Why?

The  user  can  modify  it's chroot  environment. There  must  be  other
details, which I can't grasp; but see below for an example:

http://packetstormsecurity.nl/0001-exploits/mi009en.htm

-- 
I'm frequently appalled by the low regard you Earthmen have for life.
		-- Spock, "The Galileo Seven", stardate 2822.3



Visit your host, monkey.org