The Savannah Compromise - what really happened?
Posted Jan 4, 2004 6:47 UTC (Sun) by
Ross (subscriber, #4065)
In reply to:
The Savannah Compromise - what really happened? by iabervon
Parent article:
The Savannah Compromise - what really happened?
Yes, exactly. But one must be careful that anything running outside the
chroot()ed area treats anything that is writable in the chroot()ed area as
untrusted. This means being very careful opening files and validating
inputs (it's a lot like handling /tmp correctly... i.e. almost impossible).
(
Log in to post comments)