[2067] in WWW Security List Archive
Re: chroot-ed httpd
daemon@ATHENA.MIT.EDU (Pierre-Yves Bonnetain)
Mon May 13 05:04:45 1996
Date: Mon, 13 May 96 08:56:27 +0100
From: pyb@silogic.fr (Pierre-Yves Bonnetain)
To: tauzell@math.umn.edu
Cc: jerryb@howpubs.com, www-security@ns2.rutgers.edu
In-Reply-To: <199605012133.QAA18177@aspen.math.umn.edu> (tauzell@math.umn.edu)
Errors-To: owner-www-security@ns2.rutgers.edu
>
> We run NCSA httpd chrooted on our server. The main reason was so
> that students could write CGI programs. How much extra security it
> gives us is hard to say, but it can't hurt. I am now trying to
> install NCSA httpd 1.5.1 on Solaris and run it chrooted, but am having
> problems. Anyone out there done this? Specifically , it can't create
> sockets for the children.
>
we run the CERN httpd in chrooted environment, on Solaris. No trouble. So
check your /dev directory (in the chrooted tree, of course). It may lack some
devices files.
--
-+-+ Pierre-Yves BONNETAIN (aka Pyb)
Consultant Internet