ravthan / all-eyes

Automatically exported from code.google.com/p/all-eyes
0 stars 0 forks source link

Do not copy AllEyes executables in /bin of chroot-jail #33

Closed GoogleCodeExporter closed 8 years ago

GoogleCodeExporter commented 8 years ago
Create a separate directory such as /home/ae and copy everything in it.  
Execute the binaries from /home/ae.  It is not a good idea to execute binaries 
from /bin of chroot-jail,
ravi.

Original issue reported on code.google.com by ravt...@gmail.com on 26 Oct 2012 at 2:12

GoogleCodeExporter commented 8 years ago
Our service is exclusive under the chroot. All-Eyes executable and related 
configuration files are under the same permission protection. The /bin under 
chroot is protected by AppArmor. Therefor, it is actually more protective by 
installing All-Eyes' files under /bin under chroot.

Original comment by toddd...@gmail.com on 30 Oct 2012 at 1:58