*BSD News Article 93927


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!munnari.OZ.AU!news.mel.connect.com.au!news.syd.connect.com.au!phaedrus.kralizec.net.au!news.mel.aone.net.au!news.netspace.net.au!news.mira.net.au!news.vbc.net!vbcnet-west!knews.uk0.vbc.net!vbcnet-gb!azure.xara.net!xara.net!news-feed.inet.tele.dk!cpk-news-hub1.bbnplanet.com!news.bbnplanet.com!feed1.news.erols.com!howland.erols.net!rill.news.pipex.net!pipex!oleane!jussieu.fr!rain.fr!globalip.ch!imp.ch!SUNqbc.risq.net!news1.bellgloba
l.com!sympatico.ca!not-for-mail
From: gbuchanan@on.sympatico.ca (Gardner Buchanan)
Newsgroups: comp.unix.bsd.freebsd.misc
Subject: Re: Restricted Shell?
Date: 19 Apr 1997 15:39:36 GMT
Organization: Sympatico
Lines: 23
Message-ID: <5jaovo$hlj$1@news1.sympatico.ca>
References: <3344939f.9541354@news.hiwaay.net>
    <5j8i17$5mt@uriah.heep.sax.de>
NNTP-Posting-Host: 206.172.209.41
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Newsreader: knews 0.9.7
Xref: euryale.cc.adfa.oz.au comp.unix.bsd.freebsd.misc:39351


In article <5j8i17$5mt@uriah.heep.sax.de>,
	j@uriah.heep.sax.de (J Wunsch) writes:
> whuff@airnet.net (Walter Huff) wrote:
> 
>> I need to provide a user restricted access to a FreeBSD machine which
>> I administer.
> 
> 
> If you really need to give somebody restricted shell access, consider
> the (hard) work of setting up a chroot environment.  Still, he can
> abuse the network connections (if there are any), but it's way safer
> than what any restricted shell could offer you.
> 

I was doing this very thing not too long ago - I gave up since it was
not actually very important to be secure.  I was thinking that loopback 
mounts would've helped muchly though.

Are there any plans to add loopback mounts to FreeBSD?

============================================
Gardner Buchanan    <gbuchanan@sympatico.ca>
Ottawa, ON