Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: chroot cgi
From: Bob Beck <beck @ cs . ualberta . ca>
Date: Fri, 20 Sep 1996 10:48:30 -0600 (MDT)
To: ryan @ pcslink . com (Ryan Mooney)
Cc: firewalls @ GreatCircle . COM
In-reply-to: <199609192305 . QAA13922 @ pcslink . com> from "Ryan Mooney" at Sep 19, 96 04:05:16 pm

> I am looking at giving some of my users access to putting
> up thier own cgi scripts (ugh), and I was looking for a
> safe way to do that.  I have the cgiwrap program that
> does a suid to the user.

	First of all, I assume you *have* to do this. An option not to
do that would be to provide a mirror of the server inside for them to
develop CGI scripts on, and a procedure whereby they vett them through
some knowledgeable people to make sure they're not giving away the
farm. At that point you move their script to the appropriate place on
your server. Obviously you need some rules about what they can use for
CGI development, etc, but this is usually preferable to having it wide
open.

> 
> What I would like to do is have it also chroot to a 
> protected area where it could only do limited damage.  
> (The problem with just cgiwrap is that while my users 
> won't be intentionally malicous they may be incompetent 
> and someone else may be malicious).
> 

	I'd probably just chroot the whole web server (I.E. make a hole
for the daemon to run in) That and if your users can just write stuff
I'd probably want to make this just a "sacrificial" machine. I.E. not
even your real web server with your corporate image, etc. on it.  Put it
outside, protect it the best you can, and bring it back when it 
gets clobbered.

	-Bob



References:
  • chroot cgi
    From: Ryan Mooney <ryan @ pcslink . com>
Indexed By Date Previous: FW-1 NAT problem -Reply
From: Richard Gilman <rgilman @ vortexdata . com>
Next: RE: Re[2]: FW: NT vs. UNIX white paper (fwd)
From: Dave Wreski <tel1dvw @ is . ups . com>
Indexed By Thread Previous: chroot cgi
From: Ryan Mooney <ryan @ pcslink . com>
Next: Draft NT/UNIX Network Security Whitepaper posted
From: Bill Stout <bill . stout @ hidata . com>

Google
 
Search Internet Search www.greatcircle.com