Firewall Wizards mailing list archives
Re: chroot useful?
From: C Matthew Curtin <cmcurtin () research megasoft com>
Date: Fri, 21 Nov 1997 15:43:16 -0500 (EST)
"Steve" == Steven M Bellovin <smb () research att com> writes:
Steve> It is important to understand what chroot() is and what it Steve> isn't. Actually, this comment can be usefully abstracted to include any tool. Peter Honeyman gave a talk at Ohio State earlier this week, and we briefly discussed the utility of syslogd, and how common attacks against are syslog daemons really are. Based on the comments I heard, it sounds like I'm more paranoid than most about the threat of knocking out a site's logging capability by writing garbage to syslog. Nevertheless, I'm not in the camp that finds it useless. Things like chroot(), syslog, and packet filtering routers are tools that we have available in securing our systems and networks. None are perfect, but by understanding the utility and limitations of the tools available to us, we can come up with relatively comprehensive security schemes that keep unpleasant surprises to a minimum. -- Matt Curtin Chief Scientist Megasoft Online cmcurtin () research megasoft com http://www.research.megasoft.com/people/cmcurtin/ I speak only for myself Keywords: Crypto Security Privacy Unix Internet Perl Java Death-to-spam
Current thread:
- chroot useful? Claudio Telmon (Nov 08)
- Re: chroot useful? Darren Reed (Nov 09)
- Re: chroot useful? Claudio Telmon (Nov 09)
- Re: chroot useful? Joseph S. D. Yao (Nov 10)
- Re: chroot useful? Andreas Siegert (Nov 12)
- Re: chroot useful? chuck+fwwiz (Nov 10)
- <Possible follow-ups>
- Re: chroot useful? Paul McNabb (Nov 12)
- Re: chroot useful? Steven M. Bellovin (Nov 13)
- Re: chroot useful? C Matthew Curtin (Nov 21)
- Re: chroot useful? Steven M. Bellovin (Nov 13)
- Re: chroot useful? Paul McNabb (Nov 12)
- Re: chroot useful? Douglas R. Steinbaum (Nov 13)
- Re: chroot useful? Darren Reed (Nov 14)
- Re: chroot useful? Steven M. Bellovin (Nov 14)
- Re: chroot useful? Aleph One (Nov 14)
- Re: chroot useful? Steven M. Bellovin (Nov 15)
- Re: chroot useful? Bernhard Schneck (Nov 14)
- Re: chroot useful? Darren Reed (Nov 09)
- Re: chroot useful? Paul McNabb (Nov 14)
- Re: chroot useful? Paul McNabb (Nov 14)
- Re: chroot useful? Paul McNabb (Nov 14)