Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-27, 23:09:55

Author Topic: Allow customer to activate lxjailshell on their own  (Read 2474 times)

0 Members and 1 Guest are viewing this topic.

Offline Spacedust

  • Super Grand Master
  • ****
  • Posts: 4,050
  • Karma: +1/-0
    • View Profile
This should not harm us and it will reduce number of tickets to activate SSH.

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: Allow customer to activate lxjailshell on their own
« Reply #1 on: 2014-07-18, 21:39:36 »
This should not harm us and it will reduce number of tickets to activate SSH.

In my test lxjailshell is not a true chroot environment.  If you allowing vim or other editors they can break out easily.  I have been securing a server that i paid to have audited.  Perl was a nightmare.  Lxjailshell is better off than on!  You have to restrict it so much it makes it useless.  And a true jail requires the commands to be copied to the /home of the user.

I have abandoned apache and proxies.  I am moving forward with just hiawatha.  I have setup individual jails using the cgi-wrapper in hiawatha, at the cost of 50 mb per customer.  No real biggie.

Next is to change php session directory to /home/{user}/sessions - that was another security concern from my audit (shared hosting)

I can jailshell bash, but, again, all files must be copied to a users directory.

But, i am a security freak, and paranoid. ;)
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: Allow customer to activate lxjailshell on their own
« Reply #2 on: 2014-07-19, 00:58:17 »
Instead using 'copy', try using 'hardlink' or 'mount'.
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: Allow customer to activate lxjailshell on their own
« Reply #3 on: 2014-07-19, 04:34:19 »
Yes, considering hardlinks.  Just don't want anyone to be able to find a way to hack the file, as it would happen across the entire server if every client is hardlinked to say, perl.

But chattr +i and keeping it root:root with world execute, no write should handle that.  I had to chattr +i so on cleanup and fix scripts the ownership and permissions don't get changed.
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

 


Top 10 Social Networking:    Facebook    Twitter    LinkedIn    Pinterest    Google Plus    Tumblr    Instagram    VK    Flickr    Vine
Click Here

Page created in 0.066 seconds with 19 queries.

web stats analysis