04-17-2009
How to start a chroot jail?
I was reading an article on how it is very important to setup a chroot jail to run bind. I can follow what the article says but one thing I am unclear about is now on system boot the BIND process in the chroot jail will start since it the owner will no longer be root but some other user. Can someone explain how to configure for this?
9 More Discussions You Might Find Interesting
1. Linux
I created a user
useradd -d /disk2/ftpfiles me
How would i beable to jail me so he could not move arround my file system? (4 Replies)
Discussion started by: byblyk
4 Replies
2. UNIX for Dummies Questions & Answers
I use Mac OSX and have been given all of my video editing software... illegally. I don't want to use it anymore and heard that Unix was the way to go. So that is why I am here. What video editing software is out there for Unix. I think I have Unix. Do I?
I am sorry and if all anyone can... (0 Replies)
Discussion started by: moz1979
0 Replies
3. UNIX for Advanced & Expert Users
I'm trying to establish a jail on a FBSD 6.1 system and have a couple of questions on bringing up the daemon.
Under the jail man page there are two user flags that I am unclear on,
-u username The user name from host environment as whom the command
should run.
-U... (1 Reply)
Discussion started by: thumper
1 Replies
4. Debian
Firstly Hi everyone :)
I setup SFTP and SSH jail using this tutorial:
http://www.howtoforge.com/chrooted-ssh-sftp-tutorial-debian-lenny
SFTP jail works however now when I try to SSH it accepts my password and then just goes to a blank screen. Type any command and the shell session is... (11 Replies)
Discussion started by: pokey144
11 Replies
5. UNIX for Advanced & Expert Users
I have a simple sandbox program which runs a command as user "nobody" in a chroot jail. It sets resource limits with setrlimit, changes the user id with setuid, changes the root dir with chroot, and then calls exec to execute the command given as command line parameters. It is of course a... (8 Replies)
Discussion started by: john.english
8 Replies
6. UNIX for Advanced & Expert Users
I have a developer that needs ssh access to a server to get to a specific directory. I want to restrict them to that directory. I've tried to set their shell as rksh which does jail them but only if they are using ssh from another unix system. If they are using putty or winscp they can still... (2 Replies)
Discussion started by: toor13
2 Replies
7. Red Hat
Hi
I need a specific user to be able to sftp to a server and get files from a specific location. The location is not the users home dir, i don't want the user to be able to view anything else apart from the files in that area.
e.g ftp file are is - /logging/phplogs
e.g user home is... (1 Reply)
Discussion started by: duckeggs01
1 Replies
8. Cybersecurity
Hello people,
I'm creating a web game control panel, where people can manage their gameserver on a php made control panel.
But i have no idea how to create an jailed inviroment for the gameserver,
I've looked at possebilites for chroot, but i don't want the gameserver has any binaries of linux... (1 Reply)
Discussion started by: gm33
1 Replies
9. UNIX for Beginners Questions & Answers
The script works and creates a modified iso fine until I added the chrootbeg and chrootend functions and executed them. I'm sorry if I did something wrong this is my first post. I uploaded entire bash script for reference or in case you want to run it to debug it is called isoremast.txt.
... (5 Replies)
Discussion started by: paulhoffusa
5 Replies
LEARN ABOUT DEBIAN
updatejail
JAILER(8) System Manager's Manual JAILER(8)
NAME
updatejail - is a script for rebuilding a chrooted environment made with jailer
SYNOPSIS
updatejail <config.file> <jail identifier>
DESCRIPTION
updatejail is a script which wipes out a chroot environment and rebuilds it. By default it leaves the /dev/log device in the chroot, so you
do not need to restart system logger after updating a jail.
WARNING
Do not configure your daemon inside your jail, because updatejail script will wipe out all the data inside the jail. If you would like to
change any setting inside the jail, make the changes in the original location and then run updatejail . This makes it possible to place a
jail even to a ramdisk.
Options
<config.file>
The configuration file which contains the settings of the new chrooted environment. For further information see man 8 jailer.conf
<jail identifier>
The identifier which specifies which jail will be used. Identifiers need to be defined at jailer.conf . This identifier has to match
the directory name used in the Root location.
BUGS
updatejail will not parse the configuration file and determine the Root location by itself.
For updatejail to work the Root location for the jail identifier has to end with the name of the identifier itself. For example, if your
identifier is apache the Root location in jailer.conf has to be something like /chroots/apache.
SEE ALSO
updatejail(8) jailer.conf(5),
AUTHOR
This manual page was written by Peter Holtzl <peter.holtzl@balabit.hu>.
December 4, 2001 JAILER(8)