|
|

楼主 |
发表于 2004-8-27 05:40:53
|
显示全部楼层
hello,难道没有人做过相类似的东西吗?看了chroot-bind9 how-to还不知道如何判断。只是这些:-)
http://cert.uni-stuttgart.de/arc ... 04/03/msg00241.html
use lsof
# lsof -p [pid number of bind process]
check:
- if the loaded libraries is in the chroot (by cheking the path and/or
the inode)
- if std in/out and err are connected inside the chroot to /dev/null
- there is only one socket to syslog (in the real world)
我的情况:
okdebian:~# ps auxw | grep syslogd
root 1360 0.0 0.4 1540 616 ? Ss 05:27 0:00 /sbin/syslogd -m 0 -a /var/lib/named/dev/log
okdebian:~# lsof -p 1360
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
syslogd 1360 root cwd DIR 3,6 536 2 /
syslogd 1360 root rtd DIR 3,6 536 2 /
syslogd 1360 root txt REG 3,6 27736 16034 /sbin/syslogd
syslogd 1360 root mem REG 3,6 90152 10532 /lib/ld-2.3.2.so
syslogd 1360 root mem REG 3,6 1243856 10536 /lib/libc-2.3.2.so
syslogd 1360 root mem REG 3,6 34520 11070 /lib/libnss_files-2.3.2.so
syslogd 1360 root 0u unix 0xc4559430 12935 /dev/log
syslogd 1360 root 1w REG 3,6 127895 1093 /var/log/auth.log
syslogd 1360 root 2w REG 3,6 201175 648 /var/log/syslog
syslogd 1360 root 3w REG 3,6 174896 16 /var/log/daemon.log
syslogd 1360 root 4w REG 3,6 146324 1091 /var/log/kern.log
syslogd 1360 root 5w REG 3,6 0 9343 /var/log/lpr.log
syslogd 1360 root 6w REG 3,6 0 12124 /var/log/mail.log
syslogd 1360 root 7w REG 3,6 87139 907 /var/log/user.log
syslogd 1360 root 8w REG 3,6 0 12127 /var/log/uucp.log
syslogd 1360 root 9w REG 3,6 0 12393 /var/log/mail.info
syslogd 1360 root 10w REG 3,6 0 12394 /var/log/mail.warn
syslogd 1360 root 11w REG 3,6 0 12395 /var/log/mail.err
syslogd 1360 root 12w REG 3,6 0 12396 /var/log/news/news.crit
syslogd 1360 root 13w REG 3,6 0 12403 /var/log/news/news.err
syslogd 1360 root 14w REG 3,6 0 12404 /var/log/news/news.notice
syslogd 1360 root 15w REG 3,6 7859 994 /var/log/debug
syslogd 1360 root 16w REG 3,6 239842 787 /var/log/messages
syslogd 1360 root 17u FIFO 3,6 12434 /dev/xconsole
syslogd 1360 root 18u unix 0xc51130e0 12937 /var/lib/named/dev/log |
|