Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: chroot cgi
From: Ryan Mooney <ryan @ pcslink . com>
Date: Thu, 19 Sep 1996 16:05:16 -0700 (MST)
To: firewalls @ GreatCircle . COM

This may or may not be the correct place to ask this...
but I think it has some relevance so here goes...

I am looking at giving some of my users access to putting
up thier own cgi scripts (ugh), and I was looking for a
safe way to do that.  I have the cgiwrap program that
does a suid to the user.

What I would like to do is have it also chroot to a 
protected area where it could only do limited damage.  
(The problem with just cgiwrap is that while my users 
won't be intentionally malicous they may be incompetent 
and someone else may be malicious).

Instead of running out and writing something... I was 
wondering if anyone else had anything like this, or
had any suggestions for something that I could use
as a good building block. (or an ideas beyond the
obvious as to how it should work).

Thanks

----------------------------------------------------------------------------
Ryan Mooney             Phone (602)265-9188            PCSLink
ryan @
 pcslink .
 com        Fax   (602)265-9357         Internet Services

The world needs more bitter, twisted souls. It would be a much better place.
-----------------------------------------------------------------------------


Follow-Ups:
Indexed By Date Previous: Re: CIA Firewalls?
From: Robert Hanson <roberth @ cet . com>
Next: Re: C-class net, netmask 255.255.255.128 = trouble?
From: Todd Truitt <Todd . Truitt @ evolving . com>
Indexed By Thread Previous: CIA Site News
From: David Eisenstein <davide @ acekids . com>
Next: Re: chroot cgi
From: Bob Beck <beck @ cs . ualberta . ca>

Google
 
Search Internet Search www.greatcircle.com