Stories
Slash Boxes
Comments

SoylentNews is people

Submission Preview

Link to Story

OpensshSftpChrootCodeExecution

Accepted submission by canopic jug at 2018-01-07 19:45:54
Security

The SFTP component in OpenSSH provides a chroot-feature for hardening. It is stated in the documentation that the chroot directory must not be writable by the user account, though specific files and subdirectories within it are allowed. Some people were questioning the read-only restriction. halfdog documents some analysis [halfdog.net] which is the result of discussions on openssh-dev mailing list. Here are some arguments about why these restrictinons still makes sense in 2018.


Original Submission