Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Secure Shell
Can't run whoami(id -un) inside chroot jail using openssh native jail support Jul 23 2008 08:15PM
D M (dm mlist gmail com) (2 replies)
Re: Can't run whoami(id -un) inside chroot jail using openssh native jail support Jul 24 2008 11:14PM
Jon Kibler (Jon Kibler aset com) (1 replies)
Re: Can't run whoami(id -un) inside chroot jail using openssh native jail support Jul 24 2008 11:24PM
D M (dm mlist gmail com) (1 replies)
Re: Can't run whoami(id -un) inside chroot jail using openssh native jail support Jul 25 2008 05:48PM
Greg Wooledge (wooledg eeg ccf org) (1 replies)
Re: Can't run whoami(id -un) inside chroot jail using openssh native jail support Jul 28 2008 02:56PM
D M (dm mlist gmail com) (1 replies)
Re: Can't run whoami(id -un) inside chroot jail using openssh native jail support Jul 29 2008 08:12AM
Vladimir Levijev (vladimir levijev gmail com) (1 replies)
Re: Can't run whoami(id -un) inside chroot jail using openssh native jail support Jul 24 2008 07:41PM
Vladimir Levijev (vladimir levijev gmail com)
2008/7/23, D M <dm.mlist (at) gmail (dot) com [email concealed]>:

> OS: RHEL5.2
> Openssh: 5.0p1 and now 5.1
>
> I have successfully setup a chroot jail using openssh's new native
> jail support and almost everything appears to be working
> (ls,cd,cat,uname,etc,ect). However I can't run any commands that
> identify the user.. such as ld -un whoami logname. They all fail with
> this result:
>
> #whoami
> whoami: cannot find name for user ID 503
> #id
> uid=503 gid=504 groups=504
> #id -un
> id: cannot find name for user ID 503
> 503
> #logname
> 503
>
> i've made sure that /etc/passwd and even /etc/group are in the jail
> with the proper permissions but still I get the same result.. Any
> suggestions??

I wonder if you are missing NSS (/etc/nsswitch.conf) in your jailed
system? I would also check it with strace, like:

strace id -un

Although that would probably require setting up strace which might be
too expensive to set up in a jailed system.

Cheers,

VL

Regards,

VL

[ reply ]







 

Privacy Statement
Copyright 2008, SecurityFocus