logoalt Hacker News

justincormacktoday at 8:45 AM1 replyview on HN

Yes thats one thing Musl libc removes.


Replies

geocartoday at 12:06 PM

If the attacker can control newroot/etc/passwd they _still_ get getpwnam to return whatever userid they want. The solution is to not lookup --userspec=username:group inside the chrooted-space, but from outside.

Also, hi how's things? :)

show 1 reply