Great Circle Associates Firewalls
(July 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Chrooted home directories ?
From: felipe @ avatar . pty . com (Ing. Felipe Tribaldos)
Date: Tue, 2 Jul 1996 23:05:46 +0500 (GMT)
To: firewalls @ greatcircle . com

Hello;

Please reply directly by emails, as I'm on the digest list, and don't always
get to it on a timely basis.  Also, not entirely a Firewall, question however
could be used on Bastion Hosts :-), so please forgive the noise.

I'm trying to create chrooted home directories to allow restricted shells, and
FTP on our system.

I created a user with a home dire /export/home/user.
Then I copied the /etc /usr/bin /usr/lib from the anon ftp directories.
Also copied sh to /export/home/user/bin/sh

Then I created a script as follows, and set it as the users shell

/etc/chroot /export/home/user usr/bin/sh

This runs OK, when I run it from the prompt as root, however when I try to login
as the user I get a chroot: not super-user error.

I tried setting the login script to owner root, and permission to u+s SUID, but
that didn't work either.

TIA for any tips.

Felipe


-- 
 ___________________________________________________________________________
| Ing. Felipe Tribaldos                                                     |
| Gerente de Operaciones / Operations Manager   Tel. +(507)269-3571/223-5111|
| CyberMedia Panama                             Fax. +(507)264-6082         |
| Internet Access - Web Publishing              Res. +(507)269-7330         |
| url: http://www.pty.com/                      email: felipe @
 pty .
 com       |
| __________________________________________________________________________|

Indexed By Date Previous: New version of Java, JavaScript, ActiveX screening http-gw patch
From: carl @ hdshq . com
Next: OS/2 firewalls?
From: Uldis Bojars <uldis @ lda . gov . lv>
Indexed By Thread Previous: New version of Java, JavaScript, ActiveX screening http-gw patch
From: carl @ hdshq . com
Next: OS/2 firewalls?
From: Uldis Bojars <uldis @ lda . gov . lv>

Google
 
Search Internet Search www.greatcircle.com