Tuesday, October 11, 2016

security - vsftp: why is allow_writeable_chroot=YES a bad idea?

There are several thousand blog posts about vsftp and allow_writeable_chroot=YES



The common error message:




Fixing 500 OOPS: vsftpd: refusing to run with writable root inside chroot ()





I solved the problem on my server.



But one question remains:



Why is it advisable to use allow_writeable_chroot=NO?



Up to now I only found nebulous arguments like "For security reasons".



What are these "security reasons"?

No comments:

Post a Comment

linux - How to SSH to ec2 instance in VPC private subnet via NAT server

I have created a VPC in aws with a public subnet and a private subnet. The private subnet does not have direct access to external network. S...