in reply to chroot() security in cgi script?

How do you know that the penetration happened through the web server/page? It probably didn't ...