RE: securety related question...

[email protected]
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Mon, 7 Oct 2002, Soft Skulled Person wrote:

> Perhaps I should chime in, as the soft-skulled person who first suggested
> this idea.  While I am frequently soft-skulled about many topics, including
> Linux (which is the reason I ask questions on groups like this), and while
> agreeing with the analysis above concerning the trade-off between cost and
> benefit, I would like to add that, even when one is looking for the salt
> mine thousands of feet below ground et.al. solution, it is not entirely
> clear how to achieve it.  For example, one of the apps I am running is
> qmail.  Someone has posted some helpful suggestions on how to chroot
> several of the qmail programs in a traditional fashion, although, to my
> eye, it looks like this requires modification of the source code, and a
> soft-skulled person probably shouldn't do that.  Furthermore, at least
> one of the programs doesn't seem to be suitable for traditional chrooting
> (since it accesses user directories), and the proposed non-soft-skulled
> solution of copying the files needed by the app into the chroot jail
> wouldn't work, since the user directory files need to be accessed and
> modified by the users.  An alternative, of course, is not to chroot this
> app at all, but it is hard for me to see how this is less soft-skulled than
> the original idea (it seems, in the worst case, that the chroot with --bind
> would be completely ineffective, giving the app access to the entire file
> system, which is what happens if you don't chroot, making the don't-chroot-
> at-all solution equally soft-skulled).  To sum up, I am perfectly willing
> to consider any non-soft-skulled solution for how to deal with something
> like qmail, and, while one person has provided a helpful solution that gets
> me part way there, no one has given me a solution that is completely non-
> soft-skulled.  And it looks like I am too soft-skulled to think of a
> solution on my own.  So, in the absence of further guidance, I am going to
> try the soft-skulled solution, at least on a temporary basis, since none
> of the alternatives seem less soft-skulled.

For future reference, I keep special reserves of contempt for
passive-aggressive behaviour such as this.

I can only suppose it's voluntary soft-skulledness that's kept you from
being able to figure out which portions of qmail could be chrooted and
which portions can't be because there'll be no point in doing so.

Chroot jails are _not_ a panacea.  They are only a tool.  Use them if you
can, but if you can't, be smart enough to recognize that you're trying to
use the _wrong tool for the job_.




-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.