[Apparmor-general] profile for proftpd and chrooted users

Christian Boltz apparmor at cboltz.de
Mon Jul 30 10:59:36 MDT 2007


Hello,

Am Montag, 30. Juli 2007 schrieb Dieter Bloms:
> does it make sense to write a profile for proftpd with chrooted users
> ? I asked because the users get a chroot directory and I have to
> allow access to / with lrw permissions.

That's bad :-(
It would be much better if there is a defined set of directories inside 
the chroot.

> So I think it doesn't make sense to write a profile, or are there any
> benefits for me, when I use a profile ?

It can only become better ;-)

BTW: You aren't the first one asking this question, so please also read 
my previous, somewhat longer, answer at 
http://forge.novell.com/pipermail/apparmor-general/2007-February/000269.html


Regards,

Christian Boltz
-- 
> > Dooooooooooooooooooch!!! ;-)
> N<?php do{echo "e";>!
cb at tux:~>  echo 'N<?php do{echo "e";>!' | php
Parse error:  parse error, unexpected '>' in - on line 1
[> Ratti und Christian Boltz in fontlinge-devel]



More information about the Apparmor-general mailing list