Gentoo Archives: gentoo-hardened

From: Jan Klod <janklodvan@×××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] to chroot or not to chroot
Date: Tue, 09 Jun 2009 20:44:43
Message-Id: 200906092044.36854.janklodvan@gmail.com
1 Hello,
2 I would like to see some opinions on chrooting -
3
4 1) how big are possible risks of hardened gentoo system compromise, if apache
5 is run normally, therefore a need of chrooting?
6
7 2) suppose I chroot Apache: what chances it still has to harm something in the
8 outside OS? My knowledge about various system capabilities, network etc is
9 too little, so enlighten me... And how big is an Apache chroot?
10
11 And by the way, how big are the risks for sshd and ntpd to open up a way into
12 the hardened gentoo system? Can that recent ntp glsa be ignored, if its
13 hardened with memory protections?
14
15 Jan

Replies

Subject Author
Re: [gentoo-hardened] to chroot or not to chroot "Michał Janke" <jankeso@×××××.com>
Re: [gentoo-hardened] to chroot or not to chroot Patrick Grieshaber <sysspoof@××××××.org>
Re: [gentoo-hardened] to chroot or not to chroot RB <aoz.syn@×××××.com>
[gentoo-hardened] Re: to chroot or not to chroot 7v5w7go9ub0o <7v5w7go9ub0o@×××××.com>